How Cutt.ly (cutt.ly) Redirection Works
Cutt.ly is a widespread link shortening platform. Because it provides free aliases and analytics, spammers and phishing operators often wrap credential harvesting links in cutt.ly short URLs to evade spam filters.
IncogSay submits a headless edge probe request to cutt.ly, isolates the HTTP 301/302 Location header, and performs automated reputation and threat analysis on the destination hostname.
Security & Phishing Risks Associated with Short Links
Frequently Asked Questions
How can I check a cutt.ly link before clicking?
Paste the link into IncogSay's Redirect Checker above. We unpack the destination and scan for malware without opening the page.
Can cutt.ly links be previewed directly?
You can insert an @ symbol at the end of some cutt.ly links or use IncogSay's edge diagnostic tool for full security telemetry.
Why is cutt.ly frequently abused in spam?
Cutt.ly's free plan has no link volume limits and offers real-time analytics, making it attractive for spam operators who want to track click-through rates on mass phishing campaigns.
Does cutt.ly use 301 or 302 redirects?
Cutt.ly primarily uses HTTP 301 Moved Permanently for standard links and HTTP 302 Found for links with A/B testing or geo-targeting enabled.
Is there a way to see click stats for a cutt.ly link?
Cutt.ly shows public stats for links where the creator enabled public analytics. IncogSay's tracer is the most reliable method to see the actual destination without relying on the creator's settings.
Can I report a malicious cutt.ly link?
Yes — cutt.ly has an abuse report form at cutt.ly/abuse. IncogSay's tracer also reports resolved malicious domains to threat intelligence feeds automatically.