URL Defanger & Refanger - Make Links, IPs and Emails Safe to Share
URL Defanger
Defang malicious links and indicators for reports, and refang them for analysis
Safe to Share
Turn http://evil.example.com into hxxp://evil[.]example[.]com so chat apps and email clients will not make it clickable.
Refang Too
Paste a report full of hxxp and [.] indicators and get the real URLs back, understanding the common variants like (.) and [dot].
Works on Whole Text
Finds URLs, emails, IP addresses and domains inside running text and leaves everything else exactly as it was.
Full Privacy
Your text is processed in your browser and never uploaded. The tool never visits any of the links.
Why Defang Indicators
Security teams share malicious URLs, domains, IP addresses and emails in tickets, reports and chats. If those are left as ordinary links, someone can click one by mistake, a mail gateway may block the message, or a chat app may fetch a preview from the malicious server. Defanging changes them just enough to stop that (hxxp instead of http, [.] instead of a dot) while keeping them readable.
The default replaces every dot in the host and turns http into hxxp; options let you replace only the last dot, defang the :// too, or skip domains and IPs without a scheme (bare domains can catch file names, so common file extensions are left alone). Defanging is safe to repeat, and refanging reverses it, but always analyse restored indicators in a safe environment.
Key Takeaways
- Idempotent: Running it twice changes nothing more; already defanged text is left alone.
- Variants understood: Refanging reads hxxp, hXXp, fxp, [.], (.), {.}, [dot], [at], [://] and more.
- Related tools: See also the Text Extractor for pulling URLs and IPs out of text.