URL Parser
Split a URL into scheme, host, path, query and fragment.
Paste a URL on the left.
How it works
A URL is read left to right by people and by parsers, and the two do not always agree about where the host is. That disagreement is the mechanism behind a whole family of deceptive links, so this page separates the parts and names the ones that are easy to skim past.
Nothing is fetched
The URL is taken apart as a string. No DNS lookup, no request, no reputation check — so pasting a hostile URL here tells nobody you looked at it, and the host is reported exactly as written rather than as resolved.
What gets flagged, and what that means
Embedded credentials. A URL may carry user:password@ before the host. Everything
before the @ is userinfo, not the destination — so
https://accounts.bank.example@evil.test/ goes to evil.test. Any password is masked in
the output rather than echoed back.
A punycode host. A hostname beginning xn-- renders as non-Latin characters in an
address bar, so what a reader sees and what resolves are different strings. It is flagged, deliberately not
rendered: displaying the Unicode form would mean showing the exact deceptive string the encoding exists to hide.
A bare IP host, a non-default port, plain http, and leftover percent escapes. Each is ordinary in normal use. They are reported because they are the parts of a URL a reader skims, not because their presence proves anything — these are observations, not verdicts.
Repeated query keys
?a=1&a=2 is shown as two entries rather than merged. Which one a server honours varies by
framework, and the difference between them is exactly what parameter-pollution behaviour looks like.
Example
https://accounts.bank.example@203.0.113.9:8080/login?next=%2F%2Fevil.test parses to a host of
203.0.113.9, not accounts.bank.example — everything before the @ is
userinfo. Four observations follow: credentials, a bare IP, a non-default port, and escapes still in the query.
Frequently asked questions
Why does it insist on a scheme?
Because assuming one changes what the input means. example.test/a could be an https URL, a path, or a host with a path — a parser that picks for you has made a claim about the input rather than reading it.
What does the credentials warning mean?
A URL may carry user:password@ before the host. Everything before the @ is userinfo, not the destination, so https://accounts.bank.example@evil.test/ goes to evil.test. It is legitimate in some tooling and it is also the oldest trick for making a link read as something it is not. Any password is masked in the output rather than echoed back.
Are repeated query parameters merged?
No. ?a=1&a=2 is shown as two entries, because which one a server honours varies by framework — and the difference between them is exactly what parameter-pollution behaviour looks like.
Related tools
URL Decoder
Decode percent-encoded text, including repeatedly-encoded strings.
LocalURL Encoder
Percent-encode text for a URL path, query value or component.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalHTTP Status Code Lookup
What a status code means, which RFC defines it, and what to do next.
LocalJSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
LocalGit URL Parser
Break a git remote URL into protocol, host, owner and repository.
Local