Custom tracking domains and why shared link domains hurt
Click tracking rewrites links through a redirect domain. If that domain is shared, its reputation becomes yours. Set up a branded one with HTTPS.

On this page(9 sections)
- How click tracking works
- Why shared link domains hurt
- Setting up a custom tracking domain
- 1. Choose a subdomain
- 2. Point it at the provider
- 3. Enable HTTPS
- 4. Verify
- Keep the link domain aligned with the sender
- Should transactional mail be tracked at all?
- Avoid URL shorteners
- Monitor the domain
- Checklist
- Key takeaways
Every tracked link in your email points somewhere other than where the reader will end up. If that intermediate domain belongs to your sending provider and is shared with thousands of other senders, its reputation is part of your message's reputation, whether you like it or not.
How click tracking works
When you enable click tracking, your sending system rewrites each link in the message. A link to https://example.com/pricing becomes something like:
https://click.provider-links.example/ls/click?upn=abc123...
When the recipient clicks, their browser hits the tracking domain, which records the click and redirects to the original URL. Open tracking works similarly, with a tiny image hosted on a tracking domain.
By default, many providers use their own shared domain for these links. That is convenient: no setup needed. It also means every customer of that provider sends links through the same hostname.
Why shared link domains hurt
Spam filters evaluate the domains in a message's links, not just the From domain. A link domain that appears in a lot of spam or phishing gets a poor reputation, and messages containing it are scored accordingly.
On a shared tracking domain:
- Other senders' behavior affects you. If another customer of the provider sends spam with tracked links, the shared domain's reputation suffers. Providers try to police this, but the domain carries traffic from everyone.
- Blocklists list domains. Domain blocklists, such as Spamhaus DBL and URIBL-style lists, list hostnames found in spam. A shared tracking domain that gets listed affects every message containing it.
- Mismatched domains look suspicious. A message from
example.comwhose every link points to an unrelated domain looks more like phishing than one whose links point tolinks.example.com. - Recipients notice. People who hover over links before clicking see an unfamiliar domain.
Setting up a custom tracking domain
Most sending providers support a branded tracking domain. The steps are similar everywhere.
1. Choose a subdomain
Use a subdomain of the domain you send from, dedicated to tracking:
links.example.com
click.mail.example.com
Keep it separate from your main website. The tracking subdomain serves redirects, and its reputation should be distinct from www.
2. Point it at the provider
Usually a CNAME record:
links.example.com. CNAME tracking.provider.example.
The provider then serves redirects on your hostname.
3. Enable HTTPS
This step is often missed. If the tracking domain serves plain HTTP redirects, links in your email start with http://. Some clients and security tools flag non-HTTPS links, and browsers increasingly warn on them. Providers handle HTTPS in different ways: some provision certificates automatically for your CNAME, while others require you to put a CDN or proxy in front. Follow your provider's instructions and confirm with a real click that the link starts with https:// and the certificate is valid for your hostname.
4. Verify
Send a test message and check:
# Confirm DNS
dig +short CNAME links.example.com
# Follow a tracked link and inspect the redirect chain
curl -sI "https://links.example.com/..." | grep -iE '^(HTTP|location)'
You should see a redirect, typically 301 or 302, to the original URL, served over HTTPS.
Keep the link domain aligned with the sender
The best practice is consistency: the From domain, DKIM signing domain and link domains all belong to the same organization. A message from news.example.com with links on links.example.com that resolve to example.com tells a coherent story.
If you use separate subdomains per mail stream, consider separate tracking subdomains too. Marketing links on links.news.example.com and transactional links on links.mail.example.com keep any link reputation problem contained to one stream.
Should transactional mail be tracked at all?
Tracking has costs in transactional mail:
- Security emails. Password reset and sign-in links pass through a redirect, which adds a hop, can confuse users who inspect links, and means tokens appear in the tracking provider's logs. Many teams disable tracking on security mail entirely.
- Link scanners. Corporate security gateways often follow links in incoming mail to check them. With tracking, those visits register as clicks, which inflates numbers. Worse, if a link performs an action on GET (confirming an email address, for instance), a scanner can trigger it. Design such links to require a deliberate user action on the landing page.
- Latency. Each redirect adds a little load time.
A reasonable policy: track marketing and engagement mail, and send security and critical transactional links directly to your own domain.
Avoid URL shorteners
Public URL shorteners are widely abused, and their domains appear in a great deal of spam. Messages containing them are often scored more harshly. Use your own domain for any short links you need.
Monitor the domain
- Check your tracking domain against major domain blocklists periodically.
- Watch for certificate expiry if you manage HTTPS yourself.
- Confirm after any DNS change that tracked links still resolve and redirect correctly.
A broken tracking domain is a particularly bad failure: every link in every email stops working at once.
Checklist
- Use a branded tracking subdomain instead of the provider's shared default.
- Point it with a CNAME and serve it over HTTPS with a valid certificate.
- Keep link, From and DKIM domains within the same organization.
- Consider separate tracking subdomains per mail stream.
- Disable tracking on security emails.
- Make sure GET requests on email links never perform actions on their own.
- Avoid public URL shorteners.
- Monitor blocklists and certificate expiry.
Key takeaways
- Click tracking rewrites links through a redirect domain whose reputation affects your messages.
- Shared tracking domains mix your reputation with every other sender using them.
- A branded tracking subdomain over HTTPS keeps link reputation under your control.
- Skip tracking on security emails, and assume link scanners will follow every URL.
- Monitor the tracking domain like any other critical piece of infrastructure.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


