Multi-Hop Redirect Chain Tracer with SSRF Security

URL Expander

Unmask shortened URLs (bit.ly, tinyurl.com, t.co) to reveal final destination target URLs, trace multi-step redirect chains, inspect HTTP response codes, and detect security risks.

Load Preset Example:

Tracing redirection headers & verifying security...

Final HTTP Status

-

Total Redirects

0

Total Response Time

0 ms

Domain Transition

Same Domain

Real Destination Target URL200 OK

Redirect Sequence Steps
INITIAL DOMAIN
-
FINAL DOMAIN
-
CROSS-DOMAIN REDIRECTNo
HTTP → HTTPS UPGRADENo
WWW TRANSITIONNo
Evidence-Based Observations
Bulk URL Expansion Results (0 URLs Processed)
Short Input URLExpanded Final DestinationChainHTTP StatusAction
Recent Expansion History
No recent expanded links saved.

URL Expansion Architecture & Developer Specification

HTTP Redirect Status Codes

The expander traces 301 Moved Permanently, 302 Found, 303 See Other, 307 Temporary Redirect, and 308 Permanent Redirect status codes.

HTTP 307 and 308 strictly preserve the original request method and body headers during redirection.

Per-Step SSRF Security Protection

Before resolving each step in a redirect chain, resolved IP addresses are validated against private/loopback address blocks (127.0.0.1, 10.0.0.0/8, 192.168.0.0/16, 169.254.169.254) to prevent SSRF vulnerabilities.

Loop & Max Redirect Safeguards

Redirect loops (e.g. A → B → A) are tracked in a visited set and halted immediately. Redirections are capped at a 10-step maximum limit to prevent infinite network loops.

Relative Location Resolution

Relative Location headers (e.g. /new-page or ../page) and protocol-relative links (//example.com) are resolved against the current step URL according to standards-compliant URI resolution.