Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

URL Expander

Find out where a short link really goes — without clicking it.

Network Uses live data Free, no sign-up

Expand a short link

MySmartCoPilot’s server follows the redirects with HEAD requests and never downloads the pages, so nothing on them can run or track you. Defanged links (hxxps://bit[.]ly/…) work too.

Next steps

About the URL Expander

A short link from bit.ly, t.co, TinyURL, lnkd.in or any other shortener hides where it goes until you click it — which is exactly what phishing and scam messages rely on. The URL Expander follows the link from MySmartCoPilot’s server, hop by hop, and shows every redirect, the final address and its real domain, so you can decide before anything opens on your device.

Only the HTTP headers are requested (the HEAD method), so no page is downloaded and nothing on it can run, track you or record your visit as yours. The result points out what deserves a second look: look-alike letters from other alphabets, raw IP addresses, unencrypted hops, several shorteners wrapped inside each other, and tracking parameters you can strip off.

How to use it

  1. Paste the short link — or the whole SMS, e-mail or chat message that contains it; defanged links such as hxxps://bit[.]ly/… work too.
  2. Press Expand. If the text contains several links, choose the one you want.
  3. Read the headline (where it leads) and the warnings, then check each hop of the redirect chain.
  4. Copy the destination, or the version without tracking. Check it for phishing tricks or Where to report it hands the destination to the Suspicious Link Checker or the Abuse Contact Finder.

Examples

A YouTube short link
Input
https://youtu.be/dQw4w9WgXcQ
Result
1. HEAD youtu.be → 303 See Other
2. HEAD www.youtube.com/watch?v=dQw4w9WgXcQ&feature=youtu.be → 200 OK
Leads to youtube.com · after 1 redirect

youtu.be is YouTube’s own shortener, so the chain stays with one company.

A wrapped, look-alike phishing link
Input
https://t.co/… → https://bit.ly/… → http://203.0.113.50/go → https://xn--pypal-4ve.com/login
Result
Danger: “pаypal” mixes Latin and Cyrillic letters · downgrade from HTTPS to HTTP · an IP address instead of a name · 2 link shorteners in a row

xn--pypal-4ve.com is how computers write pаypal.com with a Cyrillic “а”. It looks like the real name but is a different domain.

Common uses

  • Checking a short link in an SMS or WhatsApp message (“your parcel is held…”) before tapping it.
  • Seeing the real destination of a QR code’s short link before visiting it.
  • Removing tracking parameters before sharing a link.
  • Finding out which domain to report when a phishing link hides behind a shortener.

How the expansion works

The HEAD method is “identical to GET except that the server MUST NOT send content” (RFC 9110 §9.3.2), and all general-purpose servers must support it (§9.1). For each hop, MySmartCoPilot reads the status code and the Location header of a redirect (301, 302, 303, 307 or 308, §15.4) or a Refresh header, then asks the next address. A server that refuses HEAD (405 Method Not Allowed, 501 Not Implemented, or an error a GET might not get) is asked once more with GET, and that response body is discarded unread.

Up to 10 redirects are followed per check (fewer when a chain passes through many different hosts, to stay within the free hosting limits); a longer chain can be continued up to 20, the limit browsers use. Loops — an address that comes back — are stopped at once, as RFC 9110 asks clients to do.

What the warnings mean

  • Look-alike letters: a name that mixes alphabets, or is written entirely in letters that look Latin, is flagged with the rules of Unicode’s UTS #39 Security Mechanisms (mixed scripts and “confusable” characters).
  • Internationalised names (Punycode, xn--…) are shown both ways, so you see what the browser would display and what the name really is.
  • IP address instead of a name: legitimate services almost always use domain names.
  • Unencrypted hop / downgrade: an http:// hop can be read or changed on the way; a step from https:// down to http:// is a strong warning sign.
  • Shorteners in a row: wrapping one short link in another hides the destination from filters.
  • Domain: the registrable domain comes from the Public Suffix List, so “login.paypal.com.secure-check.net” is reported as secure-check.net, and a site on github.io or pages.dev is marked as one that anyone can create.
  • Tracking parameters (utm_*, fbclid, gclid, msclkid …) only record where the click came from; the clean link leaves them out.

Why your browser could end up somewhere else

Shorteners and the sites behind them may answer differently depending on the device, the country, cookies or whether the visitor looks like a bot. MySmartCoPilot asks from Cloudflare’s network as MySmartCoPilotBot, without cookies. Redirects done by JavaScript or a meta refresh inside a page are not followed, because the page is never downloaded — when a chain ends with a page on the shortener itself (for example a preview or warning page), the result says so instead of guessing.

Limitations

  • Page content is never fetched, so JavaScript and meta-refresh redirects, preview pages and anything the page itself does are not followed or shown.
  • Sites can send people, bots and countries to different places; the destination shown is the one MySmartCoPilot’s server was sent to.
  • Only http:// and https:// on the standard ports are followed. Private, local and internal addresses are never contacted, and links that open an app (intent://, market://) are shown but not followed.
  • A clean destination does not prove a site is safe — new phishing sites look normal. Use the Suspicious Link Checker and your judgement as well.
  • Each check follows up to 10 redirects; the number of checks per hour is limited to stay within free hosting limits.

Privacy

The link you enter is sent to MySmartCoPilot’s server, which requests each address in the chain from Cloudflare’s network, so the sites see Cloudflare, not you. Short links can contain personal tokens: MySmartCoPilot does not store them, and its log records only the host name, status and time of each request — never the path or query string.

Frequently asked questions

Is it safe to expand a link here?

Expanding sends only header requests from MySmartCoPilot’s server; no page is downloaded, nothing runs in your browser, and the site sees Cloudflare’s address instead of yours. The site does learn that someone requested the link, which for a personal tracking link can count as a click.

Why does it say “answered with a page instead of a redirect”?

Some shorteners show their own page first — a preview, an ad or a warning for links they consider risky — and only that page names the destination. MySmartCoPilot never opens pages, so it reports that the destination is unknown rather than guessing.

What is the difference between this and the Redirect Checker?

The Redirect Checker is an SEO tool: it downloads the final page to find meta refreshes and JavaScript redirects and shows the headers search engines see. The URL Expander never downloads a page and focuses on safety: look-alike names, IP addresses, downgrades and shortener chains.

Why do some hops say “HEAD got 405, so it was asked again with GET”?

A few servers do not implement HEAD although HTTP requires it. MySmartCoPilot then repeats that one request with GET to read the redirect, cancels the download and discards the body without reading it.

Can I remove the tracking from a link?

Yes. When the destination contains known tracking parameters such as utm_source, fbclid or gclid, Copy without tracking copies the link without them. Other parameters stay, because they may be needed to open the right page.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.