Defang and refang URLs
Defanging rewrites a dangerous link so it cannot be clicked by accident in an email, a ticket or a chat window. It is the standard way to pass a malicious address to a colleague, a registrar or an abuse desk. This converter runs entirely in your browser — nothing is sent anywhere.
How this works
- Defanging replaces every dot with [.] and rewrites http:// and https:// as hxxp:// and hxxps://, so no mail client or chat app turns the address into a live link.
- E-mail addresses get the same treatment: the @ becomes [@].
- Refanging reverses the change, including the common variants (.) and {.} and (at).
- The conversion happens in your browser. The text you paste never leaves your device and is never logged.
Don't want to chase this yourself?
Report the domain to Blackwall and our team handles the abuse reports to the registrar, the hosting provider and the browser blocklists, then tracks the case until the site is offline.
More tools: Abuse contact lookup · Site status check
