ToolAct

URL Expander

Unshorten short links to reveal the real URL, the full redirect chain and every status code

Paste a short link and click "Expand" to reveal the destination hidden behind it

What is URL Expansion?

URL expansion (also called unshortening) resolves shortened links such as t.cn, bit.ly or TinyURL back to the real destination. A short-link service works by storing a mapping from a short code to the original long URL: when someone visits the short link, it answers with an HTTP 3xx redirect that sends the browser to the real page. This tool requests the short link hop by hop on the server side, follows the Location header of every redirect, and reports the final URL together with the complete redirect chain, the number of hops, each hop's status code and the total time. It is handy for checking where an unfamiliar link actually leads before clicking it, verifying that a promotional link you configured resolves correctly, and debugging redirect setups. Two boundaries are worth knowing: only redirects carried by HTTP work — in-page Meta Refresh or JavaScript redirects are invisible to it; and the expanded URL is not a safety verdict — phishing links redirect perfectly normally, so the destination domain still deserves your own scrutiny.

How to Use

Steps

  1. Paste a short link into the input box, with or without the https:// prefix (e.g. t.cn/A6hXXX)
  2. Click the "Expand" button or press Enter
  3. Read the final URL, the number of redirects and the total time
  4. Open "Redirect chain" to see every intermediate URL with its status code
  5. Copy the final URL with one click, or open it in a new tab to verify

Good to Know

  • The server follows at most 10 redirects; a redirect loop stops at the limit, and every hop completed before the limit is still listed.
  • Only Location-header redirects count; in-page Meta Refresh and JavaScript redirects produce no HTTP status and cannot be expanded.
  • Links behind a login, region lock or bot check may return a 200 login/verification page — in that case the "Final URL" is simply that page.

Use Cases

Check where an unfamiliar short link leads before clickingShort links arriving in group chats, comment sections or DMs give no hint of their destination, and clicking one blind can land you on a phishing or ad page. Expand first, then decide: a normal article usually resolves in a single hop, while chains that stack several hops or route through unfamiliar tracking domains deserve extra suspicion.
Self-check promotional links before publishingBefore a campaign or a post goes live, expand the short links you generated and confirm the landing page is correct and that UTM parameters survive the whole chain intact — intermediate layers can silently drop or rewrite them. Remember that any 301 in the chain gets cached by browsers, so a later fix of the landing page will not reach everyone immediately; expanding first is cheaper than reworking after launch.
Reverse-engineer competitors' ad and campaign funnelsExpand the short links in a competitor's creatives and the whole delivery path becomes visible: which short-link provider they use, which tracking or redirect gateway sits in the middle, and which landing page and channel parameters the click finally lands on. It costs nothing and is the fastest first step in analysing a paid-acquisition funnel or an affiliate redirect structure.
Audit redirects on your own siteCheck whether HTTP→HTTPS, apex→www and old-path→new-path redirects resolve in a single hop. The chain view shows every status code: a 302 where a 301 belongs, or a one-hop job split into three, both slow down first visits and burn extra search-engine crawl budget for no benefit.
Archive long URLs so references outlive the shortenerShort-link services shut down or purge old codes — goo.gl stopped issuing new ones, and t.cn has changed policy more than once — so a short link stored in documentation, a paper or a bookmark bar puts your reference at a third party's mercy. Expand to the real URL before citing, and let the link's lifetime depend on your own domain instead.

Technical Principle

A short link is nothing more than a web service that answers with a redirect. The HTTP specification (RFC 9110, formerly RFC 7231) defines the 3xx family: 301 and 308 mean the resource moved permanently, 302, 303 and 307 are temporary. In every case the actual destination travels in the Location response header — the status code itself carries no address. A short-link service stores the short-code-to-long-URL mapping in a database, looks it up once per request, and its job is done the moment it returns a 3xx plus a Location header. That is why short links can be so short, and why expanding one is simply a matter of following the Location headers.

The expansion itself runs on the server side. The HTTP client is configured to never follow redirects automatically: for each request it inspects the status code — if it is a 3xx, the Location value (which may be a relative path, resolved against the current URL as RFC 7231 allows) is requested next; anything else means the final page has been reached. Every hop re-validates that the target is a public address, so a malicious short link cannot steer the expansion probe at an internal network (SSRF), and the chain is capped at 10 hops, beyond which it is declared a redirect loop and stopped. Each hop reads only the response headers and closes the connection without downloading the page body, so the total time is essentially the sum of the per-hop network round trips — typically a few hundred milliseconds.

The detection boundary matters just as much: Meta Refresh (<meta http-equiv="refresh">) and JavaScript redirects live inside the page content and generate no HTTP status at all, so a server that only reads headers cannot see them — these "invisible" redirects happen only once a browser actually renders the page. Finally, some short-link services vary their response by User-Agent or visitor region; this service probes with a generic browser UA so the chain you see approximates what a real visitor would experience.

  • A 3xx status code (301/302/303/307/308) plus the Location response header is the entire redirect mechanism; the destination travels only in that header.
  • 301/308 permanent redirects are cached by browsers and search engines; 302/307 temporary redirects re-query the short-link service on every visit.
  • Hop-by-hop following: on every 3xx the address in Location is requested next, until a non-3xx arrives; a 10-hop cap guards against redirect loops.
  • Location may be a relative path (permitted by RFC 7231) and is resolved against the current hop's URL into an absolute address.
  • Each hop reads only response headers and closes the connection immediately, without downloading the page body — a typical expansion takes a few hundred milliseconds.
  • SSRF protection: every hop re-validates the target address and rejects private/loopback ranges, so a hostile short link cannot probe an internal network through the tool.
  • The same-origin policy stops a browser from reading arbitrary sites' response headers, which is why cross-site expansion must be proxied through a server.

Examples

Single-hop expansion: short link to article

Input: t.cn/A6h2XzK

→ https://t.cn/A6h2XzK                    302
→ https://example.com/blog/2026/launch-notes   200

Final URL: https://example.com/blog/2026/launch-notes
Redirects: 1 · Total time: 186 ms

Multi-layer chain: what a marketing link really does

Input: https://bit.ly/3xYzAbC

→ https://bit.ly/3xYzAbC                301
→ https://go.mkt-example.com/c/8812     302   (tracking gateway)
→ https://shop.example.com/sale?utm_source=newsletter&utm_campaign=summer   200

The landing page and its UTM parameters arrive fully intact on the last hop

SEO check: how short should a chain be?

Input: http://example.com

→ http://example.com/          301
→ https://www.example.com/     301
→ https://example.com/         200

Three hops to reach the final address: folding HTTP→HTTPS and www→apex
into a single 301 saves a round trip and a slice of crawl budget

Redirect loop: stopped at the hop limit

Input: https://short.example.com/a

→ https://short.example.com/a    302
→ https://short.example.com/b    302
→ https://short.example.com/a    302
… (stopped after the 10-hop limit)

Warning: too many redirects, possible redirect loop
All completed hops are still listed, so the loop point is easy to spot

FAQ

How does URL expansion work?

A short-link service answers each request with a 301/302/307/308 status code and the next address in the Location header — that is all a redirect is. The tool replays this handshake on the server: request the short link, and whenever a 3xx comes back, request the address in its Location header, repeating until a non-3xx status arrives. The URL of that last hop is the real destination. Each step reads headers only and never downloads the page body, which is why a typical expansion finishes in a few hundred milliseconds.

Why do some short links fail to expand?

Four causes cover most failures. The target page redirects via Meta Refresh or JavaScript, which produce no HTTP status, so the tool can only report that page's address. The link sits behind a login, a region restriction, or serves a bot-verification page to non-browser requests. The short-link service rate-limits heavy use or has shut down (goo.gl stopped issuing new short codes years ago). Or the input is not an http(s) link, or contains a typo.

Is the expanded link safe to visit?

Expansion makes a link transparent; it does not certify it as safe. Phishing and malicious links redirect exactly like normal ones. After expanding, check the destination domain carefully — look for lookalike spellings such as paypa1.com impersonating paypal.com, and be wary of chains that route through unfamiliar tracking domains. Inspecting the final URL before visiting is far safer than clicking blind, but it does not replace browser and antivirus protection.

What's the difference between 301 and 302 redirects?

301 and 308 are permanent: browsers cache the new address and search engines transfer indexing signals to it. 302 and 307 are temporary: every visit still goes through the short-link service first. For SEO, a long-lived redirect should be a 301, and the shorter the chain the better — every extra hop adds user-perceived latency and consumes another unit of search-engine crawl budget.

Can I see the intermediate hops?

Yes. The "Redirect chain" lists every hop in order with its status code, starting with the short link you entered. Marketing links often stack two or three layers — a short-link service, a tracking gateway, then the landing page with its UTM parameters — and this is the quickest way to see the whole path laid out.

Which short-link services are supported?

Anything that redirects over HTTP: t.cn, bit.ly, TinyURL, is.gd, s.id, corporate branded short domains and more — the tool is not tied to any provider. If a link is publicly reachable and its redirect relies on the Location header, you will get the real URL and the full chain. Links whose "redirect" is performed by an in-page script cannot be expanded.

What happens to my privacy when I expand a link?

The expansion request is issued by this site's server, so the destination website sees the server's egress IP, not yours; the short link you enter is used only for that lookup. Note the limits of that anonymity, though: it applies to the destination site's logs of the expansion probe. Once you actually open the expanded link in your browser, your own IP and device information are exposed as with any visit — so stay as cautious with sensitive links as you would be anyway.