Why short domains get blocklisted, and how good shorteners prevent it
Here's a risk most people never consider when picking a shortener: it's a shared domain. If one bad actor uses it for phishing or malware and the domain gets flagged by Google Safe Browsing, every customer's links on that domain can stop working at once. Browsers show a red warning, and clicks die. Choosing a shortener that takes abuse seriously isn't optional; it's existential.
Why shorteners are targeted
Short links hide the destination, which is exactly what spammers and phishers want: a clean-looking link that leads somewhere nasty. So shorteners are constantly probed. A shortener that does nothing about it is a domain waiting to be blocklisted.
How a responsible shortener defends itself
The good ones layer several defences so bad links never get established:
- Checks at creation: a denylist of known-bad hosts and a reputation check before a link is even made.
- Safe Browsing lookups: destinations are checked against Google's malware/phishing database.
- Re-scanning: links are re-checked over time, because a destination can turn malicious after approval (the classic bait-and-switch).
- Warn and block pages: a suspicious destination shows an interstitial; a confirmed-bad one is blocked outright, not redirected.
- A report route + review queue: anyone can report a link, and the team acts on it; there's a published security contact.
- No indexing of redirects, so the domain isn't used to launder SEO.
What it means for you
When you choose where to put your links, you're trusting that domain's reputation. Pick a shortener that actively protects it, so a stranger's abuse never breaks your campaign. That protection is built into Urlicer from the redirect path up.
What Urlicer actually does
Every claim below is a mechanism, not a policy:
- Every link is queued for a reputation check the moment it is created — links made in the app, through the API, in bulk, or anonymously without an account. There is no path that creates a link the scanner never sees.
- The queue drains every thirty seconds against Google Safe Browsing.
- If that check cannot run, the link goes back in the queue rather than being recorded as clean. A quota problem or an outage at our end must never turn into "nobody objected".
- Existing links are re-checked on a rolling sweep, not just at creation. That is what catches the standard evasion: register something harmless, get it shortened, change the page afterwards.
- A blocked link cannot get a QR code from us. A printed code is permanent distribution, and we will not hand that to a destination we have judged harmful.
- Anonymous links cannot take a custom alias or a branded domain. Those are the brand-impersonation tools, and they require an account we can act against.
- We earn nothing from a redirect. No ad interstitials, no monetised redirects, no revenue that would make us slower to block a profitable abuser.
- The abuse contact is published, there is a report form on every warning page, and a flagged destination is named rather than silently followed.
None of this is visible when the product is working, which is the point. You will only ever notice it in the form of your links continuing to resolve.
Want links on a domain that's looked after? Shorten a link free. No signup, and every link gets a QR code and click analytics.