Destination validation
Submitted destinations must use public HTTP or HTTPS URLs. Explicit local, private, loopback, link-local, and reserved network destinations are rejected.
Trust and safety
UrlShorter combines destination restrictions, ownership checks, rate limits, and a documented abuse workflow. These controls reduce risk; they cannot guarantee that every external destination is safe or remains unchanged.
Security overview reviewed August 29, 2026
Submitted destinations must use public HTTP or HTTPS URLs. Explicit local, private, loopback, link-local, and reserved network destinations are rejected.
Signed-in sessions and signed guest claims identify who may manage a link or hosted page. Sensitive writes are checked again by the server rather than trusting browser state.
Creation and reporting workflows use rate limits. Turnstile and an external URL-reputation check can add screening when those providers are configured.
The dedicated abuse form creates a case ID. Administrators can review reports, quarantine a link during investigation, and revoke a confirmed harmful redirect.
Submit the UrlShorter link, category, and useful evidence through the abuse-reporting form. Do not open a suspected destination merely to collect more evidence. For general security or privacy questions, use the contact form and never send passwords, session tokens, or private keys.
Security claims on this page describe controls represented in the current application, not a guarantee against every misuse or external threat.