Check a tracking domain

How it works

the second reputation surface nobody checks
CNAMElink.acme.com → tracking hostPUBLISHED
PROVIDERrecognised sending toolMATCHED
HTTPScertificate never provisionedWARNING ON EVERY CLICK
ALIGNMENTsubdomain of the sending domainMATCHES FROM
TTL86400s — a day to change anythingHIGH
The CNAME resolving is not the finish line. If the tool never issued the certificate, every tracked link throws a security warning.
01

Follow the CNAME

Resolve the full chain and read the final target, including multi-hop setups.

02

Identify the tool

The target hostname names the sending platform it belongs to, or flags that it is unrecognised.

03

Check the certificate

Public Certificate Transparency logs confirm whether TLS was ever provisioned for this hostname.

04

Check alignment

Compare the link domain against the domain you send from, and flag tracking on a bare sending domain.

What a tracking domain is doing

When your sending tool tracks opens and clicks, it rewrites every link in the message to point at its own host, records the click, and redirects on to the real destination. That host is the tracking domain, and it appears in the body of every email you send.

Filters resolve and reputation-check the domains inside links, not just the domain in the From header. So the tracking domain is a second reputation surface — and on the default shared host it is one you neither control nor can see the history of.

Why the default is a problem

Every sending tool ships with a shared tracking domain used by its entire customer base. When any meaningful number of those senders behave badly, the domain gets listed on URL blocklists such as SURBL or Spamhaus DBL. Your mail then carries a listed link, and gets filtered on content grounds no matter how clean your own authentication is.

You cannot fix this, appeal it, or monitor it, because it is not your domain. The only real answer is a custom tracking domain on infrastructure you control.

The failure this tool exists to catch

Setting the CNAME is the easy half. The half people miss is that the sending tool then has to issue a TLS certificate for your hostname, and that step frequently does not complete — the CNAME went in before the tool was told to verify, or verification silently failed.

The result is a tracking domain that resolves perfectly and serves nothing over HTTPS. Every recipient who clicks gets a browser security warning. This is materially worse than leaving the default in place, and because you rarely click your own tracked links, it can run for weeks unnoticed while reply rates quietly sit at zero.

Same domain or a separate one?

There is genuine disagreement here and it is worth deciding deliberately rather than by accident.

Using a subdomain of the sending domain — link.sendingdomain.com — means the link domain matches the From domain, which reads as coherent to both filters and humans. The trade-off is shared fate: a listing on the tracking domain reflects on the domain you send from.

Using a separate domain isolates that risk, at the cost of the link pointing somewhere unrelated to the sender. On large fleets I generally use a subdomain per sending domain, because coherence is worth more than the isolation, and because rotating a burned sending domain retires its tracking subdomain along with it.

What is not defensible is tracking on the bare sending domain itself, which combines the downsides of both.

Frequently asked questions

Do I need a custom tracking domain at all?

If you are tracking clicks, yes. If you have turned tracking off entirely — which many cold email operators now do, since open tracking pixels are themselves a spam signal — then there is no tracking domain to worry about.

Should I turn off open tracking?

Open tracking adds an invisible image hosted on the tracking domain to every message, which is a well-known filter signal and produces unreliable data since Apple Mail Privacy Protection. Most experienced cold email operators disable open tracking and keep click tracking, or disable both.

My CNAME resolves but the check says HTTPS fails. What now?

Go back into your sending tool's tracking domain settings and re-run verification. The certificate is issued by the tool, not by you, and it usually completes within an hour of the CNAME becoming visible. Until it does, every tracked link warns.

Can this tell me if my tracking domain is blacklisted?

Not directly — URL blocklists refuse queries from public resolvers, so it cannot be checked reliably from a browser. Run the domain through the blacklist checker, which handles that lookup properly.

What TTL should the CNAME have?

300 seconds. You want to be able to move tracking quickly if the target host has problems, and a day-long TTL means a day of broken links before a fix takes effect.

How many tracking domains do I need?

One per sending domain is the clean pattern on a fleet. It keeps reputation isolated per domain, and when you retire a burned sending domain its tracking subdomain goes with it rather than carrying history into the next one.

Last reviewed

Related tools

What to run next

The checks that most often follow this one.

Domains & web

More in this category

Read more

Guides that go deeper

Services

When the tools tell you something is wrong

The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.

Get in touch

Start with a call

Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.

Thirty minutes, no pitch

We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
LicensingWorkspace below list price
Back to top