PrMail's link defanger checks the links in every email you open. It shows where shortened links really go, removes tracking codes and disables links to suspicious addresses. This guide explains what you'll see.
When it runs
The defanger runs when you open an email on the Low or Medium privacy level. On High, every link is already shown as plain text with its full address, and nothing is clickable. See Privacy Levels.
Shortened links are expanded
Links from URL shorteners hide where they lead. When a link uses a shortener PrMail knows, it follows the link (up to 5 redirects) to find the real destination, and the link then points straight there. The known shorteners are bit.ly, tinyurl.com, t.co, goo.gl, ow.ly, is.gd, buff.ly, dlvr.it, j.mp, rb.gy, soo.gd, short.io, cutt.ly, tiny.cc, shorturl.at, rebrand.ly, bl.ink, lnk.to and qr.ae.
- The lookup is made from our servers, not your device, so the shortening service doesn't see your IP address.
- Only those shorteners are looked up. PrMail never visits any other link in your emails to check it.
- Results are remembered for 24 hours, so opening the same email again is quicker.
- Some shorteners block automatic lookups, and a shortened link that leads to a private or internal address isn't followed. If a link can't be expanded, it's left as it was.
Tracking codes are removed
Marketing links often carry codes that tell the website which email and campaign you came from. PrMail removes these from links, including:
- Google Analytics:
utm_source,utm_medium,utm_campaign,utm_term,utm_content,utm_id - Ad click IDs:
fbclid(Facebook),gclidanddclid(Google),msclkid(Microsoft),twclid(X/Twitter),igshid(Instagram) - Email platforms:
mc_cidandmc_eid(Mailchimp),_hsenc,_hsmi,__hstcand__hsfp(HubSpot),mkt_tok(Marketo), plus Outreach, Vero and LinkedIn-styletrkcodes
The link still goes to the same page. The website just loses the information about where you came from.
What cleaned links look like
When a link has been expanded or had tracking removed, the real website's address appears in amber after the link text, for example Read more (goes to example.com). Hover over the link to see what was changed, such as "Shortened URL resolved" or "2 tracker(s) stripped". A bar above the email also says how many links were cleaned, with an About the link defanger link.
Suspicious links are disabled
PrMail flags a link as suspicious if it points to:
- A raw IP address instead of a website name.
- An address with lots of parts, such as
login.secure.verify.paypal.example-site.com, a common phishing trick. - A lookalike of a well-known brand, such as
paypa1,amaz0n,micros0ft,g00gle,app1e,faceb00korlinkedln.
A suspicious link is shown in red with [link disabled] in front of it, a dashed red underline and the real website in brackets, for example [link disabled] Click here [example-site.ru]. It can't be clicked. Hover over it to see the full address. The bar above the email says how many suspicious links were disabled.
If you really need to visit a flagged link, check the address carefully first. If the email claims to be from a company you use, go to their website yourself instead of following the link.
What it can't do
The defanger catches common tricks, not every one. A link that isn't flagged can still be harmful, so treat unexpected links with care, especially in emails with a Caution or Suspicious trust badge. See Sender Trust Badges.