Decoy: Link Safety Inspector
Overview
Hover a link to see where it really goes. Decoy catches look-alike domains, homographs and trackers, and explains each one.
🔗 Links lie. hxxps://secure-аpple.com.login-verify.tk/ reads as Apple. It isn't. Every address on the web is either a decoy or it isn't — and right now you only find out which after you've typed your password. Decoy reads the link first. Rest your pointer on anything and a small card appears: a verdict, the destination taken apart, and the reason in plain English. Not "suspicious". This: "The 0 stands in for the letter o. Microsoft really lives at microsoft.com, not micros0ft-secure.top." ━━━━━━━━━━━━━━━━━━━━━━━━ ✨ WHAT IT DOES 🖱️ Hover verdict — Judged the moment your pointer lands. A decoy raises the card on its own; for anything else, rest and press D. 🔍 Look-alike detection — 224 bundled brands. Catches micros0ft, amaz0n, paypa1, secure-login-amazon, and Cyrillic а pretending to be a. 🚧 Confirm wall (optional) — A link that trips a rule doesn't navigate until you say so. Nothing is ever blocked — you always choose. 📋 Page audit — Alt+Shift+A lists every link on the page, worst first. 🎨 Link tints (optional) — Suspicious links get outlined in the page itself. 📥 Pasted URL flags (optional) — Paste a link anywhere and Decoy judges it on the spot. ✂️ Copy clean link — Right-click to strip utm_*, fbclid, gclid and friends. 🔧 Every rule switchable — Read them in plain words. Turn any off. ⭐ Your own watchlist — Teach it your bank, your SaaS, your internal tools. ━━━━━━━━━━━━━━━━━━━━━━━━ 🎣 WHY THIS EXISTS We read a URL like a sentence — the shape, the colour, the logo above it — and stop somewhere around the middle. That's exactly where a phishing link is built to be read: • a brand in a subdomain, where the real domain hides • l → 1, o → 0 — one character swapped • letters from another alphabet that render identically • pressure words: verify, suspended, unlock • a second address hidden in the path None obvious at a glance. All trivial to check. That gap is the whole product. ━━━━━━━━━━━━━━━━━━━━━━━━ 🔒 PRIVACY No servers. No accounts. No analytics. • Zero network requests by default — works with your connection unplugged • The verdict is computed in the tab, in about a millisecond • No telemetry, no crash reports, no "anonymous" IDs — there is no endpoint in this extension • Everything stays local in chrome.storage.local. Export it as one file, or delete it all with one button. One optional request, off by default: turn on Live destination preview and Decoy fetches the page you're pointing at — straight from your browser to that host, no cookies, no referrer. Only the title, description and favicon are kept. Off any time. ━━━━━━━━━━━━━━━━━━━━━━━━ ⚖️ HONEST ABOUT BEING A HEURISTIC A Clean verdict means nothing matched a rule — not that a site is safe. Decoy is a second pair of eyes, not a security product. It complements a password manager and MFA; it doesn't replace them. If a link passes every rule and still feels wrong, trust your gut. ━━━━━━━━━━━━━━━━━━━━━━━━ 💚 FREE. FOREVER. EVERYTHING INCLUDED. No accounts, no limits, no Pro nag, nothing disabled on purpose. Open source. MIT licensed. Zero dependencies. Built by Sneg HQ — https://sneg.dev
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedOctober 7, 2026
- Offered byVidoque
- Size16.85MiB
- LanguagesEnglish
- Developer
Email
extension@sneg.dev - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes