Verification Beats a Link Shortener

A shortened link hides where it goes, which is exactly what a phishing link does. We put the list on a page we own instead — and the difference is not aesthetic, it is whether a customer can check you independently.

Ganda Tech Services 7 min read
Verification Beats a Link Shortener

Link shorteners and link-in-bio pages solve a real problem: you have several destinations and one place to put a link.

They also do something a business should think carefully about. They hide where the link goes, and they put your list of destinations on a domain you do not own.

Both of those are the defining characteristics of a phishing link.

The two problems, separately

Hiding the destination. A shortened link is opaque by design. The visitor cannot see where it goes until they have already gone. Every piece of security advice given to consumers for the last decade says to check a link before clicking it, and a shortener makes that impossible.

That advice is now widely followed. A shortened link in an email asking someone to confirm details is exactly the thing people have been trained to distrust — and the training is correct, which makes your legitimate link a casualty of a rule that is protecting them.

Renting the address. A link-in-bio page on a third-party domain has the same weakness as a business whose only web presence is an aggregator listing: you do not control whether it answers, what else appears on it, or what happens if the service changes its terms. Any accumulated recognition attaches to their domain.

There is a third issue that matters more over time. If a customer wants to verify that a message from you is genuine, a link to a third-party page does not help — they would have to trust the shortened link to reach the page that tells them what to trust.

What we did instead

A section on our own site listing every domain we operate: the ones with websites, the ones that only carry email, the brands they belong to. Our company number with a link to the national register so anyone can confirm the entity independently. The office address and phone number.

And one sentence that does most of the work: if a domain, address or number is not on this page, it is not us.

It lives at a stable address on a domain we own, and it is linked from the footer of every site in the group — so a customer who is unsure can reach it from any brand’s homepage without following a link in the message they are worried about.

★ Insight ───────────────────────────────────── That last property is the one that makes it work and the one a shortener structurally cannot have. A verification resource is only useful if it can be reached without trusting the thing under suspicion. A link in the suspicious email fails that test, however trustworthy the destination. The page has to be findable from somewhere the customer already trusts — which in practice means your own homepage, which means your own domain. ─────────────────────────────────────────────────

The entity argument

There is a second reason beyond trust, and it matters for how you are understood online.

Search engines and AI systems build a picture of an organisation from consistent signals across the web: the same name, the same address, the same domains, the same relationships. A business whose links all route through a third-party domain is feeding those systems a weaker signal than one whose links point at pages it owns.

Publishing an explicit list of your properties, on your own domain, with your registered identifiers alongside, is the clearest statement you can make about what your organisation consists of. That is useful to a customer checking you, and it is useful to every system trying to work out what you are.

When a shortener is genuinely fine

Not never, and it is worth being specific rather than absolutist.

Print and spoken contexts. A URL somebody has to read off a poster or type from a podcast needs to be short. That is a real constraint with no alternative.

Measuring campaigns. If you need per-link click data and your analytics cannot give it to you, a shortener is a reasonable tool.

Social profile links, where the platform allows one URL and you have five destinations — though the better version of that is one link, to a page on your own domain, that lists the five.

The distinction: a shortener is acceptable as a convenience for reaching content. It is not acceptable as the mechanism by which someone verifies you are you, and it is worst in email, which is where the impersonation actually happens.

Build the page

Four sections, an afternoon:

  1. Every domain that sends or receives mail in your name. Including the ones with no website — say so explicitly, because an unexplained dead domain looks worse than a disclosed one.
  2. Two or more details verifiable elsewhere. A company registration number with a link to the register is the strongest.
  3. What you will never do. Never change bank details by email, never invoice from outside the list. Specific commitments an impersonator cannot honour.
  4. Where the trusted phone number is. On this page. Not in the email they are querying.

Then link it from every footer, and keep it current — a verification page listing a domain you no longer use is confidently wrong about the one thing it exists to be right about.


Ganda Tech Services runs web, cloud, mobile and content operations for a group of Australian brands. The list of every domain that reaches us is public, and email security work is handled through Cloud Geeks.

Tags

Business TechnologyTrustCybersecurity