A URL expander shows you where a short link really goes before you open it. Paste a bit.ly, t.co, TinyURL, lnkd.in or any other short link into the free URL expander above, and our server follows every redirect for you, then shows the final destination, its domain, each hop’s HTTP status code, and any tracking parameters left on the end. Your browser never loads the page, so you can decide whether to click with the facts in front of you.
This page explains how short links work under the hood, what the expander can and can’t see, the built-in preview tricks each big shortener offers as of September 2026, how to read a redirect trace, and how to tell a harmless marketing link from a phishing lure.
What does a URL expander do?
A URL expander requests a short link, reads the redirect that comes back, and keeps following redirects until it reaches a page that stops redirecting. That last page is the real destination. Everything in between is the redirect chain.
A short link like bit.ly/3xYz is not a web page. It is a lookup key. When anything requests it, the shortener’s server looks up the key in its database and answers with a redirect: an HTTP status code in the 3xx range plus a Location header that contains the long URL. A browser follows that header automatically, which is why you normally never see the step. A link unshortener does the same request but stops to show you the answer instead of loading the page.
That is useful in more situations than you might expect:
- Safety. A short link hides its domain. Expanding it tells you whether
bit.ly/free-giftlands on a store you know or on a lookalike domain. - Bookmarking and citing. Short links break when the shortener shuts down or deletes a code. Saving or citing the full destination instead keeps the link independent of the shortener.
- Cleaning. Expanded URLs often carry
utm_orfbclidtags. Expanding first, then stripping the tags, gives you a link worth keeping. - Debugging your own links. Marketers and developers use a redirect trace to confirm that a campaign link, QR code or vanity domain points where it should, with the status codes they intended.
“Unshorten URL”, “expand short URL” and “link unshortener” all describe the same job. The difference between tools is how much of the chain they show and how honestly they describe what they couldn’t follow.
How does this free URL expander work?
This free URL expander sends each link to the Bookmend tools API, a small server we run, which follows the redirects with automatic following turned off so it can record every step. Your browser only talks to our server; it never contacts the shortener or the destination.
For each link, the server:
- Requests the short URL and records the status code and the
Locationheader it gets back. - Requests that location, and repeats, up to a fixed hop limit so a redirect loop can’t run forever.
- When a response stops redirecting, checks the HTML for a
<meta http-equiv="refresh">tag, which is a redirect written into the page rather than the headers, and records it as another hop if present. - Returns the list of hops and the final URL.
The page then analyses the result in your browser. It reads the final domain, looks for known tracking parameters, and compares the domain you started with to the one you ended on. You get a warning when something looks off, not a vague score.
Up to 20 links run per batch, five at a time. Duplicates and lines that aren’t links are dropped first, and bare links like t.co/abc get https:// added. If a request fails, the result says why in plain words (the domain doesn’t exist, the server timed out, the chain looped) and gives you a Retry button for that link alone. If you run many batches quickly you may hit the rate limit; the tool tells you to wait a minute rather than failing silently.
The server also refuses to request private or local network addresses such as localhost or 192.168.x.x. That protects the service from being used to probe internal networks, and it means a short link that points at one will show an error instead of a destination.
How do URL shorteners redirect?
Most URL shorteners redirect with an HTTP 301 or 302 status code; a few use 307 or 308, and some social platforms add a page that forwards with a meta refresh or JavaScript. Which one they pick changes how browsers cache the link and what an expander can see.
The HTTP specification, RFC 9110, defines the redirect codes, and MDN’s guide to HTTP redirections explains how browsers treat each one:
| Status | Name | Permanent? | What it means for a short link |
|---|---|---|---|
301 |
Moved Permanently | Yes | The short link always points to this destination. Browsers may cache it, so later visits can skip the shortener. |
302 |
Found | No | Temporary. The owner can change the target later. Common where shorteners let you edit a link or count every click. |
303 |
See Other | No | “Fetch this other page with GET.” Used by some services, notably for form-style redirects. |
307 |
Temporary Redirect | No | Like 302, but the request method must not change. |
308 |
Permanent Redirect | Yes | Like 301, but the request method must not change. |
200 + meta refresh |
OK, then a tag in the HTML | No | The server sends a normal page whose <meta http-equiv="refresh"> tag sends the browser on. The expander detects and records it. |
200 + JavaScript |
OK, then a script | No | The page runs code like location.href = …. A server-side expander cannot run it, so the chain appears to stop here. |
Why the redirect type matters
Permanent redirects are cacheable, which is why a 301 short link can keep working in your browser for a while even after the shortener changes it. Temporary redirects make the shortener see every click, which is how click statistics are counted. For a short link you plan to save for years, the code matters less than the shortener’s survival: if the service disappears, both kinds stop working.
What a URL expander can’t see
Be clear about the limits. A server-side expander sees what a first-time visitor with no cookies, from our server’s location, would get. It cannot see:
- JavaScript redirects. Pages that forward with a script look like a normal page to the expander.
- Personalised redirects. Some links send different visitors to different places based on country, language, device or login state. Mobile app links may send phones to an app store and computers to a website.
- What happens after you log in. A link to a document behind a login usually expands to the sign-in page.
- Changes after you check. A temporary redirect can be pointed somewhere else tomorrow.
When a chain ends on a page that still looks like a shortener, an ad network or a blank landing page, assume something happened in JavaScript that the tool couldn’t follow.
Where does this link go? Preview tricks for each shortener
Several big shorteners have their own preview feature that shows the destination without redirecting, handy when you have one link and don’t want a separate tool. The table below reflects how each service behaves as of September 2026.
| Short domain | Owner | Built-in preview | Notes |
|---|---|---|---|
bit.ly, j.mp |
Bitly | Add + to the end: bit.ly/abc+ |
Shows an info page with the destination. Bitly also runs a separate link-checker page. |
tinyurl.com |
TinyURL | Put preview. in front: preview.tinyurl.com/abc |
TinyURL also offers a cookie-based setting that turns previews on for every TinyURL you open. |
t.co |
X (Twitter) | None | Wraps every link posted on X. On the platform, the full URL often shows on hover or in the card. |
lnkd.in |
Interstitial on many links | Often shows “This link will take you to a page that’s not on LinkedIn” with the destination. | |
goo.gl |
None (no new links since 2019) | Inactive links stopped working August 25, 2025; actively used ones still redirect. | |
youtu.be |
YouTube | None needed | Always goes to youtube.com. The si parameter it adds is a share tracker. |
amzn.to, a.co |
Amazon | None | Usually goes to an Amazon product page, often with an affiliate tag parameter. |
Branded domains (nyti.ms, wapo.st, …) |
The brand | Varies | Usually run on a shortener platform under the brand’s own domain. Should land on the brand’s own site. |
Google’s own post on the goo.gl link shortening update explains the August 2025 change. If a goo.gl link now shows a warning page or an error, it was one of the inactive links that stopped working, and you’ll need the original long URL from somewhere else, such as the Wayback Machine.
How t.co and lnkd.in behave
t.co is X’s link wrapper. Every link posted on X is rewritten to a t.co address so the platform can check it against spam lists and count clicks. How t.co answers depends on who’s asking: some clients get a straightforward HTTP redirect, while browsers have historically received a page that forwards with a meta refresh and a script. The tool records either as a hop, so a typical t.co trace shows the t.co hop, then the real destination (which may itself be another short link, since people often post bit.ly links on X).
lnkd.in is LinkedIn’s equivalent. For many external links, LinkedIn shows an interstitial page that says the link will take you to a page that’s not on LinkedIn, along with the address. If LinkedIn serves that notice as a normal page, the expander will end the chain on the lnkd.in page. In that case the destination is written on the notice itself, and you can open the lnkd.in link in a browser to read it without continuing.
Branded short links
Many publishers and companies use their own short domain, for example nyti.ms for The New York Times. These are real short links run on a shortener platform under the brand’s domain, and they should land on the brand’s own site. That is why the tool warns you when a branded-looking short link lands on an unrelated domain: that’s exactly what a scammer would do with a domain that imitates a brand.
Is an expanded link safe? How to check short URL destinations
Expanding a short link tells you where it goes, not whether that place is safe. Use the destination as evidence, then check anything unfamiliar with a reputation service before you open it.
The tool flags the patterns most often seen in phishing and scam links:
| Warning in the tool | What it means | What to do |
|---|---|---|
| Public shortener, destination on another site | Normal for bit.ly, t.co, TinyURL. It’s a note, not an alarm. | Judge the destination domain itself. |
| Branded short link lands on a different site | The link looks like it belongs to one brand but goes elsewhere. | Treat as suspicious unless you know why. |
Punycode domain (xn--…) |
The domain uses non-Latin characters that can imitate a real name, for example a Cyrillic “а” in place of “a”. | Don’t enter passwords. Check the domain carefully. |
| Bare IP address | The link skips domain names entirely. Legitimate sites rarely do this. | Avoid unless you set it up yourself. |
Plain http:// |
The page isn’t encrypted. | Don’t enter personal or payment details. |
@ login part in the URL |
Text before @ in a URL is ignored by the browser and can disguise the real domain. |
Treat as a red flag. |
| Chain passes through 4+ sites | Typical of ad networks, affiliate hops and tracking redirects. | Usually not dangerous, but the final page is what counts. |
| Destination returns 4xx | The page is missing, blocked or broken. | The link is dead; see the fixes below. |
Free services to check the destination
- Google Safe Browsing site status checks a URL against the same lists Chrome, Firefox and Safari use to show red “Dangerous site” warnings.
- VirusTotal checks a URL against dozens of security vendors’ lists at once. Don’t paste links that contain private tokens, since submissions can be visible to security researchers.
A clean result from both is reassuring, not a guarantee. New phishing pages often go unlisted for hours or days. The strongest protection is still context: if a message pushes urgency (“your account will be closed today”) and the expanded domain isn’t the company’s real one, don’t open it.
Why a URL expander is safer than just clicking
Opening a link sends the destination your IP address, browser details and any cookies you have for that site. A malicious page can also try to exploit your browser the moment it loads. When you expand a short URL here, the only thing that contacts the destination is our server, and it doesn’t run the page’s scripts. On a phone, a long-press preview is not the same thing: Safari’s and Chrome’s link previews load the actual page to show it.
How do you read a redirect trace?
A redirect trace is the ordered list of every URL a link passed through, with the status code each one returned. Read it top to bottom: every 3xx line is a step, and the last line with a 2xx status is where you’d land.
Here’s what a typical trace from the tool looks like, written out as text:
1 301 permanent redirect https://bit.ly/3xYzExample
2 301 permanent redirect http://example.com/spring-sale
3 301 permanent redirect https://example.com/spring-sale
4 200 OK https://www.example.com/spring-sale?utm_source=newsletter&utm_campaign=spring
This tells you four things:
- Hop 1 is the shortener handing over the long URL.
- Hop 2 to 3 is the site upgrading plain
http://tohttps://. Harmless. - Hop 3 to 4 adds
www., another routine normalisation. - The final URL carries two
utm_tags. They only tell the site which newsletter sent you. The page is the same without them, so you can strip them with the free URL cleaner before saving or sharing the link.
Things that deserve a second look in a trace: a hop to an unrelated domain in the middle (often an ad or affiliate network), a chain that ends on a login page for a service you didn’t expect, a final status of 404 or 410 (the page is gone), or a 403 (the site blocked the request, which may just mean it dislikes automated visitors).
Redirect trace for your own links
If you manage short links, QR codes or campaign URLs, a redirect trace is a quick audit. Check that each link uses the status you intended, that there are no pointless extra hops (each one adds a round trip), and that the final URL has the tracking tags you meant to add, and no leftovers from an old campaign.
Other ways to expand a short URL
You can unshorten URLs without this tool: with a shortener’s preview feature, a command line, a browser extension or another website. Each is better in some situations.
| Method | Good for | Limits |
|---|---|---|
| This free tool | Up to 20 links at once, full chain with status codes, warnings, tracking-parameter check, CSV export | Can’t run JavaScript redirects; rate-limited |
Service previews (bit.ly/…+, preview.tinyurl.com/…) |
One link from a shortener that supports it | Only shows the first destination, not later hops; only works on that service |
curl on the command line |
Developers; exact headers | Needs a terminal; -I sends HEAD, which some servers answer differently than GET |
| Hovering on desktop | Seeing the link text you’d visit | Shows the short URL, not the destination |
| Phone long-press preview | Looking at the page | Loads the page, so it isn’t a safe preview |
| Link-expanding browser extensions | Expanding links automatically as you browse | Needs broad permission to read the pages you visit; check who makes it |
| Other link unshortener websites | A second opinion | Quality varies; some show ads or don’t list every hop |
Expand short URL links with curl
On macOS, Linux and Windows 10 or later (which include curl), this prints every redirect status and location without downloading page bodies:
curl -sIL https://bit.ly/3xYzExample | grep -iE "^(HTTP|location)"
To print only the final URL:
curl -sL -o /dev/null -w "%{url_effective}\n" https://bit.ly/3xYzExample
On Windows, use NUL instead of /dev/null. Like any server-side method, curl won’t follow JavaScript redirects.
When another tool is the better choice
If you need to open a long list of already-expanded links to review them, the free bulk URL opener opens them in batches. If you have hundreds of saved links and want to know which ones are dead rather than where they go, the bookmark dead link checker is built for that. And if you only have one bit.ly link, the plus-sign trick is the quickest route.
Troubleshooting: when a short link won’t expand
Most failures come down to a dead shortener code, a destination that blocks automated requests, or a redirect the tool can’t follow. The error in each result tells you which.
| What you see | Likely cause | Fix |
|---|---|---|
| “That domain doesn’t exist” | Typo in the short domain, or the shortener shut down | Check the spelling; search for the original long URL or try the Wayback Machine |
| 404 on the first hop | The short code was deleted, disabled for abuse or mistyped | Codes are case-sensitive: bit.ly/AbC and bit.ly/abc are different links |
| 404 or 410 on the last hop | The shortener works, but the destination page is gone | Look for an archived copy; the page itself is dead |
| 403 or 429 on the last hop | The site blocks or rate-limits automated requests | The page may be fine in a browser; check the domain first, then open with care |
| Chain ends on a shortener or blank page | JavaScript redirect, bot protection or an app deep link | Use the service’s preview feature or open it in a private window after checking the domain |
| “Redirects in a loop” | Two URLs point at each other, or a login redirect cycles | Usually a broken link; the owner has to fix it |
| “Timed out” | The destination server is slow or down | Retry that link in a minute |
| “Private or local network” | The link points at localhost or an internal IP |
Expected. The tool never requests internal addresses |
| “Too many requests” | You hit the per-visitor rate limit | Wait a minute and press Retry |
| Final URL differs from your browser | Country, device, cookies or login change the redirect | Normal for some sites; the tool shows the logged-out, no-cookie result |
Why short links in your bookmarks break
Short links break more often than the pages they point to, because each one depends on two things staying alive: the shortener and the destination. If either disappears, the bookmark stops working.
Shorteners do shut down or prune links. Google stopped creating goo.gl links in 2019 and turned off the inactive ones in August 2025. Smaller shorteners have closed without warning, and free plans on some services expire or disable links. When that happens, every bookmark, document and printed QR code using those links fails at once, and there’s no way to ask a dead shortener where a code used to go. This is one flavour of what Wikipedia describes as link rot, and short links make it worse by adding a second point of failure.
Two habits help:
- Save the expanded URL, not the short one. Run short links through the expander above before you bookmark or cite them, and strip the tracking tags with the URL cleaner. The full URL survives the shortener.
- Check old bookmarks periodically. A free bookmark health check shows the shape of your library from an export, and our guide to finding and fixing broken bookmarks in Chrome walks through repairing what’s already broken.
Is this link unshortener free and private?
Yes, the link unshortener on this page is free, with no signup, no account and no limit beyond a per-visitor rate limit that keeps the service available for everyone. There are no ads and no paid upgrade for this tool.
On privacy, here’s exactly what happens. The links you paste are sent to the Bookmend tools API so it can request them; that’s the only way to read a redirect without your browser visiting the page. The destination and every site in the chain see a request from our server, identified as Bookmend’s tools bot, not from you. Results may be cached briefly so the same link isn’t requested repeatedly. Nothing you paste is linked to an account, because there isn’t one.
Don’t paste links you wouldn’t want requested at all, such as one-time password-reset links or single-use invitation links. Requesting those, by any tool, can use them up.
Where Bookmend fits
Bookmend isn’t a URL expander. It’s an AI-native bookmark manager for Chrome and the web, and it helps with what happens after you’ve found where a short link goes: keeping the page if it’s worth keeping.
When you save a page with the Chrome extension or the web app, Bookmend reads it, writes a short summary and suggests tags, a note and an existing collection, which you can accept, edit or ignore. It also keeps the readable text of each saved page, so the content stays available even if the site changes. Later you can ask your library a question in plain language and get an answer drawn from your saved pages, with numbered citations back to each bookmark. Saving the expanded destination rather than the short link also means the bookmark no longer depends on the shortener staying online. On Premium (free for new accounts during early access), link health checks saved links in the background at most once a day, flags dead ones and offers the Wayback Machine snapshot closest to when the page last worked. The free plan covers saving, collections, tags, search and import and export, and you can bring in an existing bookmarks.html export from any browser. It runs in Chrome, Brave, Edge, Arc and Opera, plus the web app.
If you’ve been saving short links for years, some of them may already point nowhere. See how Bookmend works or the full feature list.
Written by Nafiul Hasan, Founder, Bookmend. Last updated.