Company
Report an abusive link
If a short link on this service leads to malware, a phishing page or spam, tell us and it will be removed. No account is needed and you do not have to say who you are.

Report a link#
Paste the short link — the xlyl.link/… address, not the destination. Anything you can add about where you encountered it helps, but is not required.
If you would rather send it by email, or the report needs attachments or explanation, write to contact [at] xlyl.link.
What counts as abuse#
These are removed whenever they are found, and the accounts behind them are closed. The full rules are in the terms of service.
- Malware. Anything that installs software a visitor did not ask for.
- Phishing. Pages impersonating a bank, a mail provider, a delivery company, a government service or any other organisation in order to harvest credentials or payment details.
- Spam. Links created in bulk for unsolicited messaging.
- Deception. A link presented as leading somewhere it does not.
- Illegal content, including any material involving the abuse of children, which is reported onward as well as removed.
What is not abuse: a destination you disagree with, a competitor's marketing, or a page you find distasteful but which is lawful and honest about what it is. A URL shortener is a redirect, and it is not the right place to adjudicate the open web.
What happens after you report#
A person looks at it#
Reports are reviewed by hand rather than acted on automatically, because automatic removal is trivially abusable as a way to take down a competitor. Review is usually within a day.
The link goes, and often more#
For clear malware or phishing, three things happen: the link is removed, the destination host is banned so the same target cannot simply be shortened again, and the account that created it is banned. For a borderline first offence, usually just the link is removed.
Why this matters to everyone else#
Short links share a domain's reputation. One phishing campaign is enough for browsers and mail filters to flag an entire shortener domain, at which point every honest link on it starts landing in spam folders or behind a warning page. Removing abuse quickly is what keeps the service usable — it is not a courtesy.
It is also the strongest argument for putting your own links on a domain you own: your reputation is then yours alone and does not depend on strangers.
If you have already clicked one#
- If you entered a password anywhere, change it now on that service, and anywhere you reused it. Turn on two-factor authentication while you are there.
- If you entered card details, contact your bank and tell them it was a phishing page.
- If a file downloaded, do not open it. Delete it and run a scan.
- Report the link here so the next person does not get that far.
Next time, you can check a link before following it: any link on this service shows its destination if you add a + to the end. Are short links safe? covers the other ways to check one, including links on services that offer no preview at all.
For operators and researchers#
If you run a mail filter, a security product or a blocklist and you are seeing a pattern rather than a single link, email instead of using the form — a list of links, a target host or a campaign signature is far more useful than one report at a time, and it can be acted on in bulk.
If you are running your own copy of this software, the same tools are in your admin console: ban a link, ban its destination host, ban the domain, or ban the account. About the project explains how self-hosting works.
Frequently asked questions
- How do I report a malicious short link?
- Paste the short link into the form on this page. You do not need an account, and you do not have to say who you are. If you have context — the email it arrived in, the page it was posted on — include it in the description, because it speeds up the decision.
- How quickly are reports acted on?
- Reports are reviewed by a person, usually within a day. Links that are plainly malware or phishing are removed as soon as they are seen; anything that needs judgement takes longer than that.
- What happens to the account behind an abusive link?
- For clear-cut abuse, the link is removed, the destination host is blocked so the same target cannot be re-shortened, and the account is banned. For a first, borderline case, usually just the link goes.
- I clicked a suspicious short link. What should I do?
- If you entered a password anywhere, change it now and enable two-factor authentication on that account. If you downloaded a file, do not open it. Then report the link so the next person does not reach it.
- Can I check a short link before clicking it?
- Yes. Add a plus sign to the end of any link on this service and it shows the destination instead of redirecting you. Other ways to check a link — hovering, fetching the headers, a link expander — are covered in our guide to whether short links are safe.