1 · Configure the outgoing link

Your page links to a third-party site. Choose how the link opens and which protections are set, then open it. The destination is cross-origin and attacker-controlled. Everything is simulated — no real windows open.

How is the link opened?
rel attribute tokens
Environment
Generated link


    

2 · Two tabs — yours & the destination

After opening, the destination reports whether it received a usable window.opener. If it did, press its button to fire the reverse-tabnabbing navigation and watch your tab get silently replaced by a phishing page.

https://your-site.example/article

Your Article — "10 Tips for Faster Builds"

You are reading a trusted page you opened yourself. It contains an outgoing link to a partner site.

↳ the link you configured above lives here.

— (not opened)

Destination not opened yet

Press “Open the link” to launch the cross-origin destination tab.

3 · Why — the opener decision

The browser decides whether the destination gets a live window.opener from these inputs: