PP

Proofpoint URL Decoder

Reveal original destinations wrapped by Proofpoint URL Defense v2 and v3

Security & Auth
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
Proofpoint URL Defense

Decoding only reveals the destination; it does not visit, scan, or certify the target.

Decoded destinations

The v2/v3 version, target host, and original URL will appear here.

About this tool

Inspect common Proofpoint URL Defense /v2/url and /v3/__ wrappers locally. The decoder handles v2 substitutions and supported v3 replacement data, then shows the destination as URL text without opening it. Unsupported structure or malformed encoding is reported. It neither verifies Proofpoint signatures nor evaluates website safety.

Scenario Recipes

01

Review a protected email link before opening it

Goal: Expose the destination host without triggering a web request

  1. Paste the complete URL Defense link from the message.
  2. Decode it and review both the original URL and host.
  3. Use an approved security scanner if the destination remains suspicious.

Result: A visible destination suitable for a separate security decision.

Frequently Asked Questions

Which formats and hosts are recognized?

HTTP(S) links on urldefense.proofpoint.com, urldefense.com or their subdomains, using /v2/url or /v3/__ paths. V2 needs one nonempty u parameter; v3 needs its payload delimiters and replacement data when markers are present.

What does decoding verify?

Only the supported wrapper structure and whether its reconstructed target can be parsed as an absolute URL. It does not authenticate wrapper signatures, fetch the target or provide malware and phishing analysis.

Why can a customized link fail?

Products can emit variants outside this subset. Truncated replacement data, malformed UTF-8 or percent encoding, unsupported paths and duplicate v2 target parameters return errors. Preserve the complete original link for investigation.

Can I process several links without leaving a draft?

Yes. Paste one wrapper per line. Parsing stays in memory, makes no target requests and saves no local draft. Editing input clears old destinations so they cannot be mistaken for new results.

Keep browsing