Skip to content

Custom tracking domains and why shared link domains hurt

Click tracking rewrites links through a redirect domain. If that domain is shared, its reputation becomes yours. Set up a branded one with HTTPS.

Koltrix Team4 min read
Yellow and green patch cables neatly connected to a panel
Photo by Albert Stoynov on Unsplash
On this page(9 sections)
  1. How click tracking works
  2. Why shared link domains hurt
  3. Setting up a custom tracking domain
  4. 1. Choose a subdomain
  5. 2. Point it at the provider
  6. 3. Enable HTTPS
  7. 4. Verify
  8. Keep the link domain aligned with the sender
  9. Should transactional mail be tracked at all?
  10. Avoid URL shorteners
  11. Monitor the domain
  12. Checklist
  13. Key takeaways

Every tracked link in your email points somewhere other than where the reader will end up. If that intermediate domain belongs to your sending provider and is shared with thousands of other senders, its reputation is part of your message's reputation, whether you like it or not.

How click tracking works

When you enable click tracking, your sending system rewrites each link in the message. A link to https://example.com/pricing becomes something like:

https://click.provider-links.example/ls/click?upn=abc123...

When the recipient clicks, their browser hits the tracking domain, which records the click and redirects to the original URL. Open tracking works similarly, with a tiny image hosted on a tracking domain.

By default, many providers use their own shared domain for these links. That is convenient: no setup needed. It also means every customer of that provider sends links through the same hostname.

Spam filters evaluate the domains in a message's links, not just the From domain. A link domain that appears in a lot of spam or phishing gets a poor reputation, and messages containing it are scored accordingly.

On a shared tracking domain:

  • Other senders' behavior affects you. If another customer of the provider sends spam with tracked links, the shared domain's reputation suffers. Providers try to police this, but the domain carries traffic from everyone.
  • Blocklists list domains. Domain blocklists, such as Spamhaus DBL and URIBL-style lists, list hostnames found in spam. A shared tracking domain that gets listed affects every message containing it.
  • Mismatched domains look suspicious. A message from example.com whose every link points to an unrelated domain looks more like phishing than one whose links point to links.example.com.
  • Recipients notice. People who hover over links before clicking see an unfamiliar domain.

Setting up a custom tracking domain

Most sending providers support a branded tracking domain. The steps are similar everywhere.

1. Choose a subdomain

Use a subdomain of the domain you send from, dedicated to tracking:

links.example.com
click.mail.example.com

Keep it separate from your main website. The tracking subdomain serves redirects, and its reputation should be distinct from www.

2. Point it at the provider

Usually a CNAME record:

links.example.com.  CNAME  tracking.provider.example.

The provider then serves redirects on your hostname.

3. Enable HTTPS

This step is often missed. If the tracking domain serves plain HTTP redirects, links in your email start with http://. Some clients and security tools flag non-HTTPS links, and browsers increasingly warn on them. Providers handle HTTPS in different ways: some provision certificates automatically for your CNAME, while others require you to put a CDN or proxy in front. Follow your provider's instructions and confirm with a real click that the link starts with https:// and the certificate is valid for your hostname.

4. Verify

Send a test message and check:

# Confirm DNS
dig +short CNAME links.example.com

# Follow a tracked link and inspect the redirect chain
curl -sI "https://links.example.com/..." | grep -iE '^(HTTP|location)'

You should see a redirect, typically 301 or 302, to the original URL, served over HTTPS.

The best practice is consistency: the From domain, DKIM signing domain and link domains all belong to the same organization. A message from news.example.com with links on links.example.com that resolve to example.com tells a coherent story.

If you use separate subdomains per mail stream, consider separate tracking subdomains too. Marketing links on links.news.example.com and transactional links on links.mail.example.com keep any link reputation problem contained to one stream.

Should transactional mail be tracked at all?

Tracking has costs in transactional mail:

  • Security emails. Password reset and sign-in links pass through a redirect, which adds a hop, can confuse users who inspect links, and means tokens appear in the tracking provider's logs. Many teams disable tracking on security mail entirely.
  • Link scanners. Corporate security gateways often follow links in incoming mail to check them. With tracking, those visits register as clicks, which inflates numbers. Worse, if a link performs an action on GET (confirming an email address, for instance), a scanner can trigger it. Design such links to require a deliberate user action on the landing page.
  • Latency. Each redirect adds a little load time.

A reasonable policy: track marketing and engagement mail, and send security and critical transactional links directly to your own domain.

Avoid URL shorteners

Public URL shorteners are widely abused, and their domains appear in a great deal of spam. Messages containing them are often scored more harshly. Use your own domain for any short links you need.

Monitor the domain

  • Check your tracking domain against major domain blocklists periodically.
  • Watch for certificate expiry if you manage HTTPS yourself.
  • Confirm after any DNS change that tracked links still resolve and redirect correctly.

A broken tracking domain is a particularly bad failure: every link in every email stops working at once.

Checklist

  • Use a branded tracking subdomain instead of the provider's shared default.
  • Point it with a CNAME and serve it over HTTPS with a valid certificate.
  • Keep link, From and DKIM domains within the same organization.
  • Consider separate tracking subdomains per mail stream.
  • Disable tracking on security emails.
  • Make sure GET requests on email links never perform actions on their own.
  • Avoid public URL shorteners.
  • Monitor blocklists and certificate expiry.

Key takeaways

  • Click tracking rewrites links through a redirect domain whose reputation affects your messages.
  • Shared tracking domains mix your reputation with every other sender using them.
  • A branded tracking subdomain over HTTPS keeps link reputation under your control.
  • Skip tracking on security emails, and assume link scanners will follow every URL.
  • Monitor the tracking domain like any other critical piece of infrastructure.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn
  • A single white envelope on a black background
    Deliverability

    The case against noreply@ addresses

    A noreply sender discards replies that signal engagement and frustrates customers. Route replies to a real inbox instead and set expectations clearly.

    4 min read

  • A row of six numbered mailboxes on a wooden rail in front of dense green plants
    Deliverability

    SPF, DKIM and DMARC in plain English

    Three DNS records decide whether your email arrives. What each one actually does, what to publish, and the four mistakes that cause most of the support tickets.

    4 min read