Skip to content
UniKit

Safelink decoder

Unwrap Outlook SafeLinks, Google redirect, Facebook l.php and similar link shims to reveal the real destination URL, following nested and repeatedly encoded layers.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Real URL

What this tool does

  • Turn the long unreadable Outlook SafeLinks URL from an email back into the real domain, so you can decide whether it is worth clicking.
  • Unwrap Google search redirects and Facebook l.php links too, instead of trusting the outer domain just because it looks familiar.
  • Investigate phishing reports: once unwrapped, a destination that does not match the site the email claims to link to is a strong signal.
  • During security training or incident review, peel a multi-layer link apart layer by layer and paste the decode steps into the report.

Example

Input

https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fexample.com%2Fdocs%3Fid%3D42&data=05%7C01%7Cuser%40contoso.com%7Cabc&sdata=xyz&reserved=0

Output

https://example.com/docs?id=42

The wrapper is detected as Outlook SafeLinks and the decode depth is 1. The tool only reads the url parameter and percent-decodes it — example.com is never contacted.

Frequently asked questions

Does unwrapping a link visit the destination?

No. Unwrapping only restores the URL parameters; the page makes no network requests, so the target site never sees you. Whether to click the result afterwards is still your call based on the domain.

Which wrappers are supported?

Outlook SafeLinks (safelinks.protection.outlook.com), Outlook web mail deep links (outlook.office.com / outlook.office365.com), Google /url?q= redirects, Facebook l.php?u= redirects, and any generic redirect that carries a url, u, q, target, redirect or link parameter.

Why does the result show only one layer?

Up to five layers are unwrapped by default, and it only keeps going while the current URL really is another wrapper. A SafeLinks URL is a single layer, so the depth is 1; a link bouncing through several redirectors lists every intermediate URL.

It says "This is not a valid link" — why?

Usually because only part of the URL was copied (the parameters after url= are missing) or the mail client truncated it. You can also paste the scheme-less form na01.safelinks.protection.outlook.com/?url=… — the tool adds https:// for you.

Can it unwrap javascript: or ftp: links?

No — it answers "Only http/https links are supported". Those schemes have no business in an email or chat message; treat a javascript: link as suspicious content and move on.

Keywords:safelink安全链接解链outlook safelinks跳转链接url 解码phishingredirect

Related tools