Outlook Safe Links URL Decoder — Free
Runs 100% in your browser — your files never leave your device.
Microsoft Safe Links wraps a destination in a long protection.outlook.com URL that is difficult to inspect before opening. Paste the wrapped address to extract its url parameter, while rejecting lookalike hosts that are not genuine Outlook Safe Links domains.
How it works
- 1
Paste the Safe Links URL
- 2
Validate the Outlook host
- 3
Copy the original destination
About this tool
What safe links look like
Corporate mail scanners rewrite links into wrappers: the real destination hides inside a URL-encoded parameter on a scanner domain. The tool unwraps those — decode the wrapper URL and read the actual destination before you click.
Why unwrap before clicking
Phishing hides behind shorteners and wrappers; a rewritten link tells you nothing about where it goes. Decoding shows the true target so you can judge it — the difference between mail-service.example.com/scan?target=… and whatever that target really is.
Read the destination critically
After decoding, check the domain character by character — lookalikes swap rn for m, add hyphens, use unusual TLDs. When a "safe" link resolves somewhere unexpected, do not click the original either; report it to your mail admin.
Frequently asked questions
Is unwrapping a safe link risky?
No — decoding a URL is text processing; nothing is fetched and no one is notified. The risk only exists when you click through to the destination, which is exactly what the decode helps you judge first.
Why are wrapped links so long?
The wrapper carries the full original destination URL-encoded inside it, plus tracking parameters the scanner adds. The length is the hidden URL plus metadata.
Do all corporate mail systems wrap links the same way?
No — every vendor has its own wrapper format. The decoder handles the common parameter-based patterns; if a wrapper decodes to another wrapper, run it again.