Skip to content

Defang / Refang — TypeScript source

Make URLs, IPs, and emails safe to paste by defanging indicators (https:// → hxxps[://], . → [.], @ → [@]) - and reverse refanged text back to its original form. Runs entirely in your browser, with a shareable link to your exact input and mode.

This is the TypeScript implementation — the same logic the interactive tool runs, in a shareable, citable form.

// Pure defang/refang - makes indicator text safe to paste (no clickable links)
// and reverses it. Zero deps - the unit-test surface for the Defang/Refang tool.

/**
 * Defang text so URLs, IPs, and emails are no longer clickable or auto-linked.
 *
 * Replaces `https://` and `http://` schemes with `hxxps[://]` / `hxxp[://]`,
 * then brackets EVERY dot as `[.]` and every at-sign as `[@]` - the standard
 * indicator-defanging convention used in threat-intel and phishing analysis.
 *
 * Scheme replacements run FIRST so the dots and colon inside the resulting
 * `[://]` marker are not themselves re-bracketed (which would corrupt the
 * scheme marker). Note: ALL dots are bracketed, not just the domain separator.
 */
export function defang(input: string): string {
  return input
    .replaceAll('https://', 'hxxps[://]')
    .replaceAll('http://', 'hxxp[://]')
    .replaceAll('.', '[.]')
    .replaceAll('@', '[@]');
}

/**
 * Reverse defanging - restore `hxxps[://]` / `hxxp[://]` to real schemes and
 * unbracket `[.]` / `[@]`. Exact inverse of {@link defang}: for typical URLs,
 * IPs, emails, and plain text, `refang(defang(x)) === x`.
 *
 * Scheme markers are restored before `[.]`/`[@]` are unbracketed, so a marker
 * like `hxxps[://]` is reassembled into `https://` rather than being split by
 * an earlier dot/at substitution.
 */
export function refang(input: string): string {
  return input
    .replaceAll('hxxps[://]', 'https://')
    .replaceAll('hxxp[://]', 'http://')
    .replaceAll('[.]', '.')
    .replaceAll('[@]', '@');
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →