URL shorteners — unmask disguised phishing links.
A bit.ly link doesn't reveal where it leads. MailGuard follows the redirect chain to the actual target URL and checks that against phishing feeds and RBLs — not the harmless-looking shortener link.
Why URL shorteners are dangerous
Attackers use services like bit.ly, t.co or tinyurl.com to disguise the real phishing URL. A classic filter only sees the short, innocuous link — the malicious target domain stays invisible. That's exactly the gap MailGuard closes.
How MailGuard resolves them
MailGuard follows the HTTP redirect chain to the final URL (or up to a configured maximum number of hops). What gets scored is the actual target URL — not the shortener. Resolution happens during the sandbox phase of the mail scan.
What happens to the resolved URL
- Checked against phishing feeds — the final URL is matched against the active phishing feeds
- Added to the sandbox report — the full redirect chain is traceable in the report
- IOC extraction — if the mail is reported as spam, the target domain is stored as a URL IOC and protects future mail (see Security Alerts)
Preinstalled and extendable
MailGuard knows the common shorteners out of the box — built-in entries can be disabled but not deleted; add your own services any time:
bit.ly · t.co · tinyurl.com · ow.ly · goo.gl · short.link · rb.gy · cutt.ly · rebrand.ly · tiny.cc · is.gd · buff.ly
Performance stays in your hands
Resolution happens synchronously during the mail scan. Very slow or unreachable shortener targets can increase sandbox runtime — so problematic shorteners can be disabled individually. You decide which services get resolved.
Expose phishing behind short links?
MailGuard follows the redirect chain to the real destination and checks the final URL — not the façade.
See pricing