Safe Links & Wrapped URL Decoder
See where a wrapped e-mail link really goes — decoded in your browser, never opened.
Decoded in your browser as text. The link is never opened, so no click is recorded anywhere.
Show the text with real links
About the Safe Links & Wrapped URL Decoder
Company e-mail rarely shows you the link you were sent. Security gateways rewrite every address in a message so that a click passes through their checking service first: Microsoft Defender turns it into a long nam12.safelinks.protection.outlook.com address, Proofpoint into urldefense.com/v3/__…, Barracuda into linkprotect.cudasvc.com. Search engines and social networks do the same with their redirect pages. This decoder takes the original address back out of the wrapper, layer by layer, so you can see — and share — where the link really goes.
Everything happens in your browser: the link is decoded as text and never opened, so the wrapping service records no click. Paste one link, a whole message or its raw source, and every link in it is decoded; the text comes back with the real addresses in place of the wrapped ones. Each destination gets a quick check for phishing tricks, and one click hands it to the Suspicious Link Checker for the full report.
How to use it
- Copy the wrapped link without opening it: right-click it and choose Copy link (on a phone, press and hold the link). You can also copy a whole message, or its source — Gmail’s Show original, Outlook’s View message source.
- Paste it into the box. The real destination appears at once, with every layer of wrapping that was removed.
- Read the quick check under the destination. Check this link opens the full Suspicious Link Checker report; Copy link copies the real address.
- For a message, Copy text with real links gives you the whole text back with each wrapped link replaced by its destination (a link you had defanged comes back defanged).
Examples
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.example.com%2Finvoices%2F4471%3Flang%3Den&data=05%7C02%7Calex.morgan%40example.org%7C…&reserved=0
https://www.example.com/invoices/4471?lang=en
The destination is the url= part, percent-encoded. The data= part also holds an e-mail address — usually the one the message was delivered to.
https://urldefense.com/v3/__https://shop.example.net/track?order=7*1__;Kw!!Qx7dEk2PnR4!bW9ja1Rva2VuRm9yVGVzdA$
https://shop.example.net/track?order=7+1
Proofpoint replaces some characters with * and keeps them, base64-encoded, after __; — here Kw is the +.
A Safe Links address whose url= part is itself a Proofpoint link
Layer 1: Microsoft Defender Safe Links · Layer 2: Proofpoint URL Defense · destination https://portal.example.org/login
Messages that pass through two organisations’ gateways are wrapped by both. Every layer is removed in turn.
https://protect-eu.mimecast.com/s/Xk7pCgZ2rTq9vWbLsN4hy?domain=example.com
Cannot be decoded offline; the link names the domain example.com
Mimecast keeps the full address on its own servers: the link holds only a code.
Common uses
- Checking where a link in a work e-mail goes before you click it, when Outlook or your mail app shows only the wrapped address.
- Sharing a link from an e-mail in a chat, a ticket or a document without the security wrapper — and without the address of the mailbox it was delivered to.
- Triaging phishing reports: paste the message source and get every real destination, defanged for the report.
- Cleaning links copied from Google, Facebook, LinkedIn or Slack redirect pages.
Which wrappers it decodes
- Microsoft Defender for Office 365 Safe Links:
https://<region>.safelinks.protection.outlook.com/?url=…— the prefix Microsoft describes in its Safe Links overview — and the government-cloud and Teams variants. The destination is theurl=parameter. - Proofpoint URL Defense v1, v2 and v3 (
urldefense.proofpoint.com,urldefense.com), the three encodings that Proofpoint’s own decoder reads: v2 writes-for%and_for/; v3 keeps the address between__and__;with some characters replaced by*. - Barracuda Link Protection:
linkprotect.cudasvc.com/url?a=…, with the destination percent-encoded ina=. - Cisco Secure Email:
secure-web.cisco.com/<code>/<address>, as in Cisco’s examples. - More e-mail security and tracking: Symantec Click-time URL Protection, Trellix (FireEye), Sophos and Amazon SES click tracking.
- Redirect pages: Google (
google.com/url, AMP), YouTube, Facebook, Messenger, Instagram, Threads, LinkedIn, Slack, Steam, DuckDuckGo, Bing, Yahoo, VK and Reddit.
Wrappers inside wrappers are removed one after another, up to ten layers. A decoded address is accepted only when it is a complete link; otherwise the tool says which part was damaged.
Links that cannot be decoded offline
Some services keep the destination on their own servers and put only a code in the link: Mimecast URL Protect, link shorteners such as bit.ly or t.co, and newsletter click tracking (SendGrid, Mailchimp, Constant Contact). No tool can read the address out of such a link. The decoder names the service and, for Mimecast, the domain the link mentions in its domain= part.
To learn the full address you have to ask that service. The URL Expander can try that through MySmartCoPilot’s server — the service sees that request like a click.
Why a wrapped link can contain your e-mail address
Microsoft wraps links separately for every recipient of a message, and the data= part of a Safe Links address often contains the recipient’s e-mail address. Forward the wrapped link, or paste it into a chat or a ticket, and you share that address too. The decoder shows any e-mail address it finds in a wrapper, so you know — share the decoded link instead.
Is the decoded link safe?
Decoding shows where a link points, not what the page does. Under each destination a quick check looks for the tricks phishing links use — look-alike letters, text before an @, a brand in front of someone else’s domain, bare IP addresses — the same checks as the Suspicious Link Checker. A wrapper is not a safety stamp: the security service checks the address when it is clicked, and a link that looked harmless when the message arrived can lead somewhere else later. If you open the decoded address directly, that check at the time of the click does not happen — so open links from unexpected messages only after checking them, or not at all.
Limitations
- Wrappers that store the address on their servers (Mimecast, link shorteners, newsletter tracking) cannot be decoded without asking that service.
- Wrapper formats not listed above are not decoded; a link they carry in a parameter is still shown as a place the page may forward you to.
- The decoder reveals the destination; it does not open it, follow its redirects or look it up in blocklists.
- Links inside pictures, PDFs or QR codes must be copied as text first; the QR Code Safety Scanner reads QR codes.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is it safe to paste a wrapped link here?
Yes. The link is decoded as text in your browser; it is never opened, fetched or sent anywhere, so neither the wrapping service nor the destination site learns about it.
Can I paste the raw source of an e-mail?
Yes — Gmail’s Show original or Outlook’s View message source. Raw e-mail is often encoded: quoted-printable breaks long links over lines and writes = as =3D, and base64 turns a whole part into letters and digits. The decoder reads each part by its own headers, decodes the quoted-printable and base64 text parts, and leaves plain parts and attachments as they are, so a link such as ?page=10 in an unencoded part is never changed. Links you defanged before pasting (hxxps://, [.]) stay defanged in the text with real links.
Why does Outlook show a different address when I hover over a link?
Outlook shows the original address in the pop-up when you hover over a Safe Links link, but what you copy, forward or open in another app is the long wrapped address. This tool gives you the original in a form you can copy.
Does decoding a link get around my company’s protection?
Decoding only reveals the address. But if you then open the real address directly, the security service does not check it at the time of the click. For a message you did not expect, check the destination first — or do not open it at all and report the message to your IT team.
What is the data= part of a Safe Links address?
Information Safe Links adds for its own use. It often includes the recipient’s e-mail address, which is why the decoder points out any e-mail address it finds there before you share a wrapped link.
Why can’t it decode a Mimecast link?
A Mimecast URL Protect link contains only a code; the real address is stored on Mimecast’s servers. When the link names the destination’s domain in a domain= part, the decoder shows it; the URL Expander can try to follow the link through MySmartCoPilot’s server for the rest.
Can I turn link wrapping off?
Not yourself: your organisation’s administrators set it in the e-mail security service. Microsoft Defender, for example, has a “Do not rewrite the following URLs” list in each Safe Links policy for addresses that should not be wrapped.