URL Unshortener • Social Media URL Wrapper

Twitter / X Shortener (t.co) Link Expander & Redirect Checker

Unshorten t.co links from Twitter/X. Reveal hidden destinations, audit redirect hops, and detect malicious social media links.

Quick Answer • How to Expand X (t.co) Links Safely

To unshorten a Twitter / X Shortener (t.co) URL without opening it in your browser, paste the short link into IncogSay's Redirect Tracer above. Our edge scanner sends an isolated HTTP HEAD request, captures all intermediate 301/302/307 redirect hops, and reveals the true destination URL while checking for phishing blacklists.

Unpack & Trace X (t.co) Redirect

Inspect HTTP status codes, intermediate tracking jumps, and final landing safety without triggering browser execution.

Sandbox Edge Isolation

How Twitter / X Shortener (t.co) Redirection Works

All external links shared on Twitter/X are automatically wrapped in a t.co short URL for analytics and security tracking. IncogSay unpacks t.co links to reveal the underlying article or website. While t.co performs some blacklist scanning, it does not catch all phishing URLs — particularly newly registered domains not yet reported.

Our engine sends a sanitized probe request to t.co and extracts the HTTP 301 or HTML meta-refresh destination URL in real time. Twitter/X uses both standard HTTP 301 headers and HTML meta-refresh redirects depending on the client. IncogSay handles both mechanisms, fully resolving the redirect chain and reporting the final landing page domain, SSL status, and registration age.

Security & Phishing Risks Associated with Short Links

Compromised Verified Accounts: Phishing links tweeted by hijacked verified accounts wrapped in t.co.
Crypto Scam Portals: Deceptive web3 wallet draining sites cloaked through t.co.
Newly Registered Domain Bypass: t.co blacklist checks are reactive; newly registered phishing domains may not be flagged for 24-72 hours after a campaign launches.
Impersonation of News Sources: Fake breaking-news articles shared through compromised journalist accounts, with t.co masking the fraudulent domain.

Frequently Asked Questions

Why does Twitter wrap all links in t.co?

Twitter wraps links in t.co to track clicks, count character limits, and scan against known malware blacklists.

Does t.co scan links for phishing?

Yes, but only against its existing blacklists. Newly registered phishing domains may pass t.co checks for the first 24-72 hours. IncogSay adds an additional layer by checking domain age and cross-referencing threat feeds.

Can I tell where a t.co link goes without clicking it?

Paste the t.co URL into IncogSay's Redirect Tracer above. We resolve the HTTP 301 or meta-refresh response to reveal the final destination domain without executing any scripts on the target page.

Why do t.co links sometimes use a meta-refresh instead of a 301?

Some Twitter/X clients use an HTML meta-refresh tag instead of an HTTP 301 header. This can bypass redirect-inspection tools that only follow HTTP headers. IncogSay handles both redirect types.

Are t.co links permanent?

No. If the original tweet is deleted, the t.co link becomes invalid and returns a 404. t.co links are tied to the tweet's existence, not a standalone redirect record.

Can a compromised verified account's t.co links be trusted?

No. Account compromise is common and attackers regularly post malicious links through verified accounts. Always trace the final destination before clicking, regardless of who shared it.