(التوثيق بالإنجليزية)
What it does
Defang makes URLs, IP addresses, and email addresses safe to paste into reports, tickets, chat, or threat-intel feeds by removing the parts that browsers auto-link or mail clients turn into mailto: triggers. It rewrites the https:// and http:// schemes to hxxps[://] / hxxp[://], then brackets every dot as [.] and every @ as [@] - the standard indicator-defanging convention used by SOC analysts and phishing researchers. Refang is the exact reverse: it restores real schemes and unbrackets [.] / [@].
How to use it
- Pick Defang or Refang with the toggle.
- Paste your text into Input.
- The transformed result appears live under Defanged / Refanged.
- Copy the output, or share a link to your exact input and mode.
Examples
Defang an HTTPS URL:
https://example.com/login → hxxps[://]example[.]com/login
Defang an email and an IP:
admin@10.0.0.5 → admin[@]10[.]0[.]0[.]5
Refang a defanged indicator:
hxxp[://]phish[.]example[.]org → http://phish.example.org
Good to know
- Private: all processing is 100% client-side - nothing is sent anywhere.
- All dots are bracketed (not just the domain separator), matching the common analyst convention. This is intentional.
- Round-trip safe: for typical URLs, IPs, emails, and plain text,
refang(defang(x))returns the original. - Already-defanged text passed back through Defang is left as-is (idempotent on indicators).
- Related tools: URL Encoder,
Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
.