Black Friday Our biggest deal of the year is coming soon Get notified →

Link Defanger

Updated 4 Oct 2026 3 min read

PrMail's link defanger checks the links in every email you open. It shows where shortened links really go, removes tracking codes and disables links to suspicious addresses. This guide explains what you'll see.

When it runs

The defanger runs when you open an email on the Low or Medium privacy level. On High, every link is already shown as plain text with its full address, and nothing is clickable. See Privacy Levels.

Shortened links are expanded

Links from URL shorteners hide where they lead. When a link uses a shortener PrMail knows, it follows the link (up to 5 redirects) to find the real destination, and the link then points straight there. The known shorteners are bit.ly, tinyurl.com, t.co, goo.gl, ow.ly, is.gd, buff.ly, dlvr.it, j.mp, rb.gy, soo.gd, short.io, cutt.ly, tiny.cc, shorturl.at, rebrand.ly, bl.ink, lnk.to and qr.ae.

  • The lookup is made from our servers, not your device, so the shortening service doesn't see your IP address.
  • Only those shorteners are looked up. PrMail never visits any other link in your emails to check it.
  • Results are remembered for 24 hours, so opening the same email again is quicker.
  • Some shorteners block automatic lookups, and a shortened link that leads to a private or internal address isn't followed. If a link can't be expanded, it's left as it was.

Tracking codes are removed

Marketing links often carry codes that tell the website which email and campaign you came from. PrMail removes these from links, including:

  • Google Analytics: utm_source, utm_medium, utm_campaign, utm_term, utm_content, utm_id
  • Ad click IDs: fbclid (Facebook), gclid and dclid (Google), msclkid (Microsoft), twclid (X/Twitter), igshid (Instagram)
  • Email platforms: mc_cid and mc_eid (Mailchimp), _hsenc, _hsmi, __hstc and __hsfp (HubSpot), mkt_tok (Marketo), plus Outreach, Vero and LinkedIn-style trk codes

The link still goes to the same page. The website just loses the information about where you came from.

What cleaned links look like

When a link has been expanded or had tracking removed, the real website's address appears in amber after the link text, for example Read more (goes to example.com). Hover over the link to see what was changed, such as "Shortened URL resolved" or "2 tracker(s) stripped". A bar above the email also says how many links were cleaned, with an About the link defanger link.

Suspicious links are disabled

PrMail flags a link as suspicious if it points to:

  • A raw IP address instead of a website name.
  • An address with lots of parts, such as login.secure.verify.paypal.example-site.com, a common phishing trick.
  • A lookalike of a well-known brand, such as paypa1, amaz0n, micros0ft, g00gle, app1e, faceb00k or linkedln.

A suspicious link is shown in red with [link disabled] in front of it, a dashed red underline and the real website in brackets, for example [link disabled] Click here [example-site.ru]. It can't be clicked. Hover over it to see the full address. The bar above the email says how many suspicious links were disabled.

If you really need to visit a flagged link, check the address carefully first. If the email claims to be from a company you use, go to their website yourself instead of following the link.

What it can't do

The defanger catches common tricks, not every one. A link that isn't flagged can still be harmful, so treat unexpected links with care, especially in emails with a Caution or Suspicious trust badge. See Sender Trust Badges.

Something out of date or unclear? Let us know.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support