Custom Tracking Domains for Cold Email: Why You Need One (and Setup)
Here's a risk most senders don't know they're carrying: every open pixel and rewritten link in your emails points at your tool's shared tracking domain — a domain simultaneously used by every spammer on that platform. When their reputation tanks, yours goes with it. You didn't do anything wrong; you were just standing next to them.
How shared tracking burns clean senders
Spam filters evaluate every domain that appears in a message — sender, reply-to, and every link in the body. With default settings, your beautifully authenticated email contains links to track.sendingtool.com, and that domain's reputation is a group project with thousands of strangers. Shared tracking domains regularly end up on URI blacklists like SURBL — at which point every email containing them takes a placement hit, regardless of the sender's own flawless authentication.
Setup: five minutes per domain
Pick the subdomain
Convention: track.yourdomain.com (or link., go., t.) on each sending domain.
Add the CNAME
Point it at your tool's tracking target (each platform documents its hostname).
Verify in the tool
Add the custom domain in your sending platform and confirm SSL provisions.
Assign per inbox
Map each inbox to the tracking domain that matches its sending domain.
The bigger principle: control every domain in the message
Tracking domains are one instance of a rule that governs all of cold email infrastructure: never let a domain you don't control appear in your messages. Your from-domain, your links, your tracking, your unsubscribe URL — all should live on infrastructure whose reputation you own and monitor. It's the same logic as using secondary sending domains: isolate what you can't afford to lose from what you're putting at risk.
Open tracking versus click tracking
They are two different risks and it is worth separating them. Open tracking is a one-pixel image loaded from the tracking domain. Click tracking rewrites every link in the body so it goes through the tracking domain first and redirects to the real destination. A message with open tracking on and no links carries one foreign domain. A message with click tracking on carries the tracking domain in every single link the reader can see and hover over.
For cold email, opens are close to worthless as a metric anyway — Apple Mail Privacy Protection preloads the pixel, Gmail proxies it, corporate gateways fetch it before a human ever sees the message. I turn open tracking off on most fleets and keep click tracking only when the campaign genuinely needs to know who clicked. If you keep either one, it has to run on your own domain; the shared default is the problem, not tracking as such. The link scanner page explains what fetches the URL before the prospect does.
Root domain or a subdomain of the sending domain?
The tracking hostname should be a subdomain of the domain the message is sent from — track.getacme.com under getacme.com — not a subdomain of your main brand and not a separate domain bought for tracking. Filters score body links against the From domain. When the link's registrable domain matches the sender's, the message reads as one identity. When it does not, the message is carrying a third party, and it gets scored as one.
That means one tracking subdomain per sending domain, not one for the whole fleet. Twenty sending domains is twenty CNAMEs. It is tedious once and then it is done; the email DNS setup tool generates the tracking record alongside MX, SPF, DKIM and DMARC and can push all of them to Cloudflare in bulk from a CSV, which is how I do it for new pools.
HTTPS, redirects and the checks that catch a broken setup
The tracking subdomain must serve a valid certificate, because the link scanners that fetch it treat a certificate error the way a browser does. Every sending platform provisions this automatically once the CNAME resolves, but it can take an hour, and a campaign that starts in that hour sends links that fail TLS. Wait for the tool to show the domain as verified, then check it yourself.
Two things break later. The CNAME gets deleted when someone tidies a zone, which silently turns every tracked link into a dead host. And the platform changes its tracking target, which some do without much notice, so the CNAME points at something that no longer answers. The tracking domain checker resolves the CNAME, follows the redirect and confirms the certificate in one pass; the redirect checker shows the full hop chain if the destination is wrong. I run the first one across every sending domain monthly, because the failure mode is invisible from inside the sending tool.
Tools for this
Email DNS setupGenerate and apply email DNS records.Tracking domain checkerVerify a custom click domain end to end.Redirect checkerTrace a redirect chain to its final URL.Frequently asked questions
What is a custom tracking domain?
When your sending tool tracks opens and clicks, it rewrites links through a tracking host. By default that host is shared by every customer of the tool; a custom tracking domain replaces it with a subdomain of your own sending domain, so your links carry your reputation instead of a stranger's.
Do tracking domains need to match the sending domain?
Best practice is one tracking subdomain per sending domain (track.getacme.com for getacme.com). Matching keeps the domains in your email body aligned with your from-domain, which reads as coherent to filters and avoids cross-domain reputation bleed.
Should I turn off open tracking entirely for cold email?
Many high-deliverability senders now disable open tracking — the pixel adds a filterable fingerprint and open data is unreliable anyway. If you keep any tracking (especially click tracking), a custom domain is non-negotiable; if you disable all tracking, you sidestep the issue.
Does a custom tracking domain need its own SPF or DKIM?
No. The tracking subdomain never sends mail; it only serves a redirect and a pixel. It needs a CNAME to your platform's tracking host and a valid certificate, nothing else. Do not add an MX or SPF record to it — an SPF record on a subdomain that never sends is harmless, but an MX invites bounces to a host that cannot receive them.
Can I use one tracking domain for all my sending domains?
You can, and most tools let you, but it puts a foreign domain in every message from every other sending domain, which is a smaller version of the exact problem shared tracking causes. One tracking subdomain per sending domain is the setup that keeps each message inside a single identity. It is more CNAMEs, but it is one-time work.
Will a new tracking domain hurt deliverability while it has no reputation?
Not measurably. A subdomain inherits the standing of its parent for link-reputation purposes, and a sending domain that is already warmed carries that over. The transition to watch is the other direction: if you have been sending on the shared domain for months, moving to your own subdomain is the point where your links stop being judged by your platform's worst customer.