One link, multiple destinations
A short link or marketing URL can redirect to another destination. HTTP redirects use response status codes and Location headers. Browser-side redirects can also use HTML refresh directives or JavaScript and may not be visible in an HTTP-only collection.
The final destination can depend on location, user agent, cookies, time or whether the visitor appears automated. A single observation does not prove that every recipient saw the same page. Do not assume a reputable first-hop domain makes the final destination trustworthy.
Controlled collection
Redirect traversal should happen in an isolated environment with network controls and clear authorization. Record the original URL, each hop, response codes, collection time and request context. Avoid exposing credentials or confidential tokens to an external service.
A safe fetcher needs controls against server-side request forgery, including blocking private and reserved addresses, rechecking each redirect and accounting for DNS rebinding. URL Forensics’ public DNS report does not visit websites or traverse redirects.
Reporting a chain
Distinguish observed redirects from inferred links. Retain original response artifacts where lawful and relevant. Explain collection limitations, particularly when browser-dependent behavior was not reproduced.
- Record each hop rather than just the last URL.
- Preserve Location values and status codes.
- Document user agent, time and collection environment.
- Recheck destination changes without assuming a stable chain.
