Redirect Tracer

Paste a link to see every hop it takes before it lands — HTTP 301/302/307/308, meta refresh and JavaScript redirects — with status codes, headers, timings and TLS details for each step. Useful for checking short links, tracking URLs, SEO redirects and suspicious links without clicking them. The URL you submit is used only for this trace — nothing is stored.

Public http/https URLs on ports 80 and 443. https:// is added if you leave it off. Up to 15 hops.

What the colours mean

  • 2xx — success; the page was served.
  • 3xx / client-side — a redirect to the next hop.
  • 4xx / 5xx / failed — an error, or the request could not complete.

Redirect types

301 and 308 are permanent — search engines pass ranking to the target. 302, 303 and 307 are temporary. A meta refresh is an HTML tag telling the browser to load another page, and a JavaScript redirect changes window.location in a script. Long chains slow pages down and can dilute SEO, so aim for a single hop.

FAQ

Is it safe to trace a suspicious link?

Yes — the requests are made from a server, not your browser, and no page scripts are executed. You see where the link goes without visiting it. The trace does still make real requests, so one-time links (such as password-reset or unsubscribe links) may be used up.

How are JavaScript redirects detected?

By reading the page’s inline scripts for simple location assignments — the script is never run. A detected redirect is followed only on near-empty “bounce” pages; on normal pages it is reported as a note instead, because it is usually conditional (for example, a login check).

Why do I get a different result from my browser?

Some sites redirect based on country, device, cookies or language. The tracer starts with no cookies, carries any cookies set during the chain, and uses the user agent you pick — try “Safari (iPhone)” or “Googlebot” to see mobile or crawler redirects.

What can’t I trace?

Private, internal and reserved addresses (such as 192.168.x.x, 10.x.x.x or localhost), ports other than 80 and 443, and URLs with an embedded username or password are refused for safety. Traces are also rate-limited.