Torito

URL & Unicode Security Inspector

Reveal the actual URL destination and the characters behind a suspicious name. Every result is inert text; no link is visited or checked remotely.

About URL & Unicode inspectorFeatures & how to use

Inspect URL destinations, Punycode, Unicode confusables, hidden characters and percent-encoding layers locally. Suspicious URLs are never opened.

What it can do

  • Separate hostname, userinfo, port, path, repeated query parameters and fragment.
  • Decode Punycode labels and inspect Unicode 17.0.0 confusable mappings, code points and scripts.
  • Reveal invisible or bidirectional controls and inspect up to five percent-decoding layers.
  • Confusable skeletons and multiscript names are inspection aids, not maliciousness verdicts.

How to use it

  1. Choose URL / domain or Unicode text and paste the value to inspect, or load the example.
  2. Select Inspect and review the actual ASCII hostname before considering userinfo or decoded layers.
  3. Expand character and encoding details. Decoding a whole URL can change its meaning; the destination uses the original input.