Link safety

Live, free

Short links you can check before you click.

Destinations are checked against known phishing and malware domains when a link is created. Anyone can add + to a zou.sh link to see where it goes first.

Anyone can report a link. No account needed.

How it works

How link safety works on zou.sh

  1. 1

    Checked at creation

    Each destination is compared with a blocklist of about 390,000 phishing and malware domains, refreshed every night from two open sources.

  2. 2

    Visible before the click

    Add + to a zou.sh link, as in zou.sh/careers+, to see the destination, creation date and clicks without visiting it.

  3. 3

    Reported, then disabled

    Anyone can report a link from its preview page. Abusive links are disabled and show a “This link was disabled” page.

Why it helps

What gets refused, and what anyone can check

  • Known bad domains refused

    About 390,000 phishing and malware domains from URLhaus (abuse.ch) and the Phishing.Database project, refreshed every night.

  • No hidden credentials

    URLs with a user name or password before the host, like user:pass@, are refused. That trick is a classic way to disguise a destination.

  • No private or local addresses

    Destinations on a private network or a local machine are refused. A public short link should only lead to the public web.

  • No short link chains

    A zou.sh link can’t point to another zou.sh link. Chains add hops and hide the real destination.

  • A preview for every link

    Every zou.sh link has a public + page with its destination, creation date and total clicks, so anyone can look before visiting.

  • Reports from anyone

    Each preview page has a “Report this link” form, and there is an abuse form too. Abusive links are disabled and answer with HTTP 410.

The blocklist

What “checked” means, and what it doesn’t

The blocklist catches domains already known for phishing or malware. No list is complete, and a site registered this morning may not be on one yet. That is why previews and reports matter too.

  • About 390,000 known phishing and malware domains
  • Sources: URLhaus (abuse.ch) and the Phishing.Database project
  • Refreshed every night
  • A match is refused with the error code unsafe_destination

Any shortener

Check links from other shorteners too

The free link expander shows where any short link leads, including bit.ly, tinyurl.com and t.co links. Developers get the same answer from the API, with every hop of the redirect chain and a safety verdict.

Open the link expander
  • Paste any short link into the link expander
  • API: GET /expand follows up to 10 redirects
  • It returns the chain, the final destination and a verdict
  • POST /reports flags a zou.sh link from code

Availability

Free today. More with an account.

Everything in the first column works right now, with no account. The second comes with accounts, now in early access.

Live Today, free, no account

  • A blocklist check on every new link
  • A + preview page for every zou.sh link
  • The “Report this link” form, with no account needed
  • The link expander for links from any shortener
  • GET /expand and POST /reports in the API
Shorten a link

Early access With an account

  • Roles and permissions in shared workspaces (Team)
  • An audit log (Team)
Join early access

FAQ

Questions, answered.

How can I tell if a short link is safe?

No check can promise that a link is safe. Add + to a zou.sh link, or paste any short link into the link expander, then read the destination’s domain carefully before you visit.

Which blocklists does Blinkhop use?

Two open sources: URLhaus, run by abuse.ch, and the Phishing.Database project. Together they list about 390,000 phishing and malware domains, and our copy is refreshed every night.

Why was my link refused as unsafe?

Its domain matches the phishing and malware blocklist, so it was refused with the error unsafe_destination. Why was my link refused? explains what to do if you think it’s a mistake.

What happens after I report a link?

Reports are reviewed, and abusive links are disabled. Visitors then see a “This link was disabled” page, served with HTTP 410. A report stores only the link code, your optional reason and the date.

Can I check where a bit.ly or tinyurl.com link goes?

Yes. Paste it into the link expander to see where it leads without opening it. We can only disable zou.sh links, so report others to the service that created them.

Is there a warning page before a zou.sh redirect?

No. Visitors go straight to the destination. Known bad domains are refused when a link is created instead, and reported links are disabled.

Related

Look before you click.

Add + to any zou.sh link, or paste any short link into the free link expander.