See the journey
behind a URL.

Follow DNS resolution, redirects, response behaviour, cache policy, and HTML resource references through a single trace, with proof at every hop.

Public HTTP/S targets only Reports expire after 14 days No login required Press / to focus
Advanced trace optionsDependency mapping, external reputation, and impersonation context Optional
Add security context optional

Context improves impersonation checks. Raw message context is not retained; the claimed organisation and matched signal categories appear in the report.

How this tool works

Diagnostic principles

01

Observed, not guessed

Every conclusion points back to captured DNS or HTTP evidence.

02

Clear boundaries

Edge timings are never presented as browser or end-user measurements.

03

Safe by default

Private targets, non-standard ports, and uncontrolled response bodies are blocked.

API and integrations

Trace and assess URLs from any workflow

Run complete request traces, map dependencies, assess suspicious links, and retrieve evidence-backed reports through REST or Streamable HTTP MCP.

  • Request trace
  • URL risk
  • Opt-in reputation
  • Report retrieval

Daily request limits apply, including repeat traces. If you reach a limit, the response tells you when to retry.

How RequestScope works

SAFE

Validate the target

Only public HTTP/HTTPS targets on standard ports are allowed. Credentials, IP literals, private addresses, and unsafe redirects are rejected.

DNS

Resolve and verify

Cloudflare and Google DNS-over-HTTPS responses are checked before every request. Displayed records remain DNS observations, not ownership claims.

HTTP

Follow the request path

The Worker follows bounded redirects manually and records edge-visible status, headers, TLS metadata, timing, and a limited response body. An optional profile requests the page as mobile Safari; every report records which identity was used.

PAGE

Extract page signals

Static HTML is inspected for forms, password fields, resources, and third-party services. RequestScope does not execute page JavaScript or submit forms.

MAP

Map optional evidence

When selected, CSP, bounded JavaScript, Certificate Transparency, and CNAME evidence are collected under one request budget. Bundle and takeover stages can be partial or skipped.

REP

Check reputation with consent

Google Web Risk and PhishTank check the original and final URL. Cloudflare's malware-filtering DNS checks their hostnames. Provider misses never mean safe.

RISK

Build the assessment

Deterministic findings are scored from captured evidence and provider matches. Reports remove query values and fragments before storage, retain selected redacted headers, and expire after 14 days.

RequestScope does not probe private networks, submit forms, bypass authentication, or test for exploitable vulnerabilities.

Open Cloudflare Radar?

Cloudflare retains URL Scanner reports and may make them public.

Do not continue with authenticated, private, password reset, or token-bearing URLs. Query values are sent exactly as typed.