See it before you trust it
Drop an HTML file here, , or paste the markup below.
Nothing uploads. The markup renders in a sandboxed frame in your own browser.
Scripts are off until you say otherwise
An HTML file is the one format that is also a program. Opening one you did not write, by double clicking it, runs whatever is inside it with your browser and your network.
So the frame here is sandboxed with no script permission at all, and the referrer is
suppressed so the markup cannot see where you came from. The checkbox turns scripts on if
you need to test your own page, and the status bar changes from blocked to RUNNING so
there is never any doubt about which mode you are in.
What the status bar reports
Press Load a sample with a script in it and you get a line like this:
invoice-204.html · full document · title "Invoice 204" · 1 image (1 with no alt text)
· 1 script tag blocked · 1 form · loads from images.example.com
Each of those is worth knowing before you trust a file somebody sent you:
- Script tags, and whether they ran. A page that needs JavaScript to show its content will look empty here. That is the sandbox working, not a broken viewer.
- Forms, and where they submit. This is the one that matters. A form inside an HTML file somebody emailed you is how a card number or a password gets collected, and the viewer names the host it posts to.
- External hosts. Every domain the page would fetch a script, stylesheet, image or frame from. A plain document should fetch from nowhere.
- Images with no alt text, counted, because that is the most common accessibility fault in hand written HTML.
- Full document or fragment. A fragment with no doctype will render, but it is not a page you can host as it stands.
Viewing it and hosting it are different jobs
This page shows you the file. Putting it online as a working page at its own address is the other half, and it is the box at the bottom of this page.
That one has a condition attached: hosting a web page needs a free account with a confirmed
email address. Not a paywall, a deliberate one. An anonymous page host on a real domain
over HTTPS is exactly what a phishing kit wants, and an account makes an abusive upload
traceable. Everything hosted also carries a noindex header, so hosted pages never enter
search results.
What this will not do
It will not resolve relative paths. A file that references style.css or img/logo.png has
no folder around it here, so those will not load. Paste absolute URLs, or host the whole
thing as a zip.
It will not edit the markup, and it will not format or validate it against the spec.
It will not make an unsafe file safe. It blocks scripts and reports what it found; deciding whether to trust the file is still yours.
| Limit | Value |
|---|---|
| Characters read in this viewer | 400,000 |
| Hosting a page | needs a confirmed email |
| One uploaded file | 150MB |
| Free storage | 1GB |
