Not every URL gets a hop.
ONE HOP is a public portal, not a phishing, malware, scam, or cloaking service.
Allowed
Destinations must be public HTTP(S) URLs with a valid host. URLs are normalized and checked server-side before checkout and again before activation. DNS and reputation checks are used where available, and redirect parameters are checked for obvious attempts to reach a prohibited destination.
Rejected
We reject JavaScript, data, file, custom-scheme, localhost, private or internal network, credential-bearing, obfuscated, and raw IP destinations where they are not safe public endpoints. We also reject obvious phishing, malware, scams, deceptive login pages, malicious downloads, adult sexual content, illegal content, doxxing, harassment, and attempts to redirect into prohibited destinations.
After a hop starts
A destination can be disabled after activation if new information shows it is unsafe. Administrators can immediately fall back to a neutral platform-controlled destination. The public GO action is deliberate; ONE HOP never auto-redirects visitors on arrival, and the current destination is always shown before GO.
Report a destination
Report the exact URL and the reason at hello@onehop.lol. Do not send personal information, passwords, or payment details.