Decode and extract original URLs from safelink redirects and URL shorteners
Safelink Decoder
Decode and extract original URLs from safelink redirects and URL shorteners
Safelink URL Input
Decode SafeLinks
Paste a SafeLink URL above to instantly decode it and reveal the original destination. Supports Microsoft Outlook, Google, ProofPoint, and other security services.
What safelink wrapping does and why it appears in your inbox
Email security gateways — Microsoft Defender for Office 365, Proofpoint URL Defense, Mimecast, and others — rewrite every hyperlink in incoming messages before delivery. The original URL is percent-encoded and appended as a query parameter to a redirect URL hosted on the gateway's domain. When you click the link, the gateway checks the destination against threat intelligence in real time, then forwards you if the URL passes. The purpose is to block malicious links even when the threat was unknown at delivery time.
The side effect is that the link you see in the email bears no resemblance to the destination. For compliance reviews, security audits, and automated pipeline processing, you need the original URL — which is exactly what this decoder extracts without making any outbound request or sending the URL anywhere.
Supported wrapping formats
- Microsoft SafeLinks —
safelinks.protection.outlook.com/?url=with the destination in theurlquery parameter - Proofpoint URL Defense —
urldefense.com/v3/__format with the destination encoded after the double underscore - Mimecast —
protect-us.mimecast.com/s/or regional variants with the destination in the redirect path - Generic percent-encoded redirects — any URL containing a
url=,redirect=, ortarget=parameter with a percent-encoded destination
