πŸ”—

Microsoft Safe Links Decoder

Reveal the original destination wrapped by Outlook and Microsoft 365 Safe Links

Security & Auth
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
Microsoft Safe Links
Original targets
Decoded targets appear here

About this tool

Reveal target URLs inside Microsoft Safe Links without requesting either the wrapper or destination. Paste one HTTP(S) wrapper per line; the decoder follows up to five nested url parameters and reports the target scheme, host and depth. Results are normalized by the browser URL parser. Decoding does not verify Microsoft signatures or assess destination safety.

Frequently Asked Questions

Which links does it recognize?

HTTP and HTTPS URLs on safelinks.protection.outlook.com or its subdomains, with exactly one nonempty url parameter. Other hosts, missing targets and duplicate target parameters are rejected.

Can it unwrap nested links?

Yes, up to five Safe Links layers. Extra percent encoding can be decoded until an absolute target is available; the decoder stops there so percent escapes belonging to that target are preserved.

Why may the displayed URL look different?

The browser URL parser normalizes host casing, default ports and other URL syntax. This is a readable destination, not a byte-for-byte reconstruction of the original email.

Does a decoded destination mean it is safe to open?

No. The page does not scan content, check reputation or validate Safe Links security parameters. It displays text and never opens the destination automatically.

Are batch links saved or sent elsewhere?

No. One link per line is parsed locally without saving a draft or fetching targets. Editing the input clears the previous results; use Decode again for the new input.

Keep browsing