SafeLinks Decoder

Instant, 100% client-side URL cleaner for Defender Office 365 links.

🔒 100% Client-Side Engine 🚫 Zero Telemetry or Tracking 🌍 Global & Sovereign Cloud Support 📦 Double-Encoding Defense ⚡ Instant Real-Time Decoding 📖 100% Open Source (GPL v3) 🔒 100% Client-Side Engine 🚫 Zero Telemetry or Tracking 🌍 Global & Sovereign Cloud Support 📦 Double-Encoding Defense ⚡ Instant Real-Time Decoding 📖 100% Open Source (GPL v3)

1. SafeLink Input

0 chars Ctrl + Enter

2. Cleaned Destination URL

Awaiting Input
0 chars
🧩 Browser Add-on

Tired of pasting links manually?
Protect your inbox automatically.

Install the official SafeLinks Decoder browser extension to expand Microsoft Defender links automatically inside your browser without opening a website.

SecOps & Analyst FAQ

Learn how Microsoft Defender Safe Links work and why client-side decoding is critical for privacy.

Why decode SafeLinks client-side?

SafeLinks contain corporate recipient telemetry, tenant identifiers, and destination URLs. Sending these links to external third-party decoding web services exposes sensitive corporate communications and may alert attackers when analyzing phishing payloads. Our decoder runs 100% locally in your browser DOM.

Which SafeLink clouds are supported?

All global Microsoft Defender Office 365 clusters (such as nam01, emea01, eur03, aus01) as well as Sovereign and Government Clouds (.de, .cn, .us, office365.us) are fully supported.

Does it handle double-encoded links?

Yes! Security tools often double percent-encode parameters (e.g. %253A%252F%252F). The decoder recursively detects and normalizes nested URI percent encodings until the clean target URL is extracted.

Copied to clipboard!