Follow a shortened or suspicious link through every redirect — safely, server-side — and check each hop's domain against threat intelligence.
How it works
The trace runs server-side — your browser never touches the suspicious link. Only response headers are fetched; page bodies are discarded.
Each hop's domain is checked against Cloudflare's threat intelligence (the 1.1.1.2 filtered resolver): flagged means it's on a malware/phishing blocklist.
"Not flagged" is one signal, not proof of safety — new malicious domains appear constantly.
Up to 10 hops. Redirect loops and private-network targets stop the trace.
Meta-refresh and JavaScript redirects can't be seen from headers — the chain shows HTTP redirects only.
Nothing is stored. Traces run from Cloudflare's edge, not your device.