It's a legitimate question, and the lazy answer — "to get you to create an account" — would be false. Two of our tools already work without sign-up: the UTM generator and the QR code generator. No form, no email address, nothing sent to a server.
Creating short links is the one place where the rule differs, and it's because of a mechanism worth understanding — whether you use our tool or someone else's.
What an open shortener becomes in a matter of weeks
An anonymous shortener is, structurally, an excellent phishing tool. Not by accident — by design.
A short link hides its destination. That's its function. Nobody can tell, reading xyz.ab/k3p9, whether it leads to a ticketing site or a fake bank page. Add that an anonymous link costs nothing, can be created in bulk, and is tied to nobody — and you've described the ideal tool for a fraudulent campaign.
This isn't speculation about your visitors' intentions. It's the observation that any open service eventually attracts exactly this, and that the actual operating method is bulk creation: thousands of throwaway links, used for a few hours.
Reputation plays out at the domain level, not the link level
Here's the point that decides everything, and that most people only understand once they've been through it.
Browser and messaging protection mechanisms don't rate links individually. They rate domains. Google maintains one such service, Safe Browsing, integrated into several browsers; Microsoft runs another, SmartScreen, built into its browser and operating system. Other reputation lists circulate among email providers.
When a domain tips into one of these lists, the warning doesn't appear in front of the offending link. It appears in front of every link on that domain. Including the ones you printed on ten thousand flyers. Including your client's bio link. Including the QR code on their storefront.
It's the most severe failure that can hit this kind of product, for two reasons:
- It breaks the core promise. A short link only has value if the link survives. A red warning screen in front of every destination is the end of the tool, not a service incident. The service status page wouldn't even say anything — technically, everything would still be responding.
- It can't be fixed with a deployment. Getting off a reputation list takes time, goes through external procedures, and comes with no calendar guarantee. In the meantime, your clients' links are showing a warning.
The second effect, quieter: email filtering
Before any flagging even happens, there's ordinary filtering. Email providers are wary of open shortener domains, because those are the same domains used for unsolicited campaigns.
Consequence for entirely legitimate use: a newsletter containing links shortened on a public domain has a higher chance of being classified as junk than one pointing to named addresses. The shared domain isn't just risky — it performs worse — and nobody will tell you, because nothing shows up in your send statistics.
This is the strongest argument for a branded domain: your reputation depends only on you, and it builds over time instead of being inherited from strangers.
Not all open shorteners are careless. The ones that last put safeguards in place, and it's useful to know which ones — it's the framework to apply to any of them:
| Safeguard | What it prevents |
|---|
| Short expiration for links created without an account | a fraudulent campaign lives by its duration |
| Shared domain only, never a branded domain | a client's name isn't used as cover |
| Destination check before creation | addresses already known to be malicious |
| Bot challenge | bulk creation, which is the actual operating method |
| Cap per address and per destination | abuse shows up by volume before it shows up by content |
| One-click reporting on the redirect | a domain that moderates gets reported less |
| Creation log, kept for a bounded period | enables response to a report |
And one human safeguard that no list replaces: someone needs to look at the reports. That's a real operating cost, and it doesn't go down as the service grows.
Where we stand, without glossing over it
Today, creating a short link with us requires an account. It's stated plainly on our link shortener page, which has no form — an uncomfortable choice for someone arriving from search, and one we own rather than hide behind a form that leads to a sign-up.
The question of a deliberately limited no-account tool — short lifespan, shared domain, verified destination, no statistics — is open with us. It's written out, with its advantages, its moderation cost, and the risk it leaves. It hasn't been decided, and we won't pretend here that it has been in either direction: that would mean announcing a decision that hasn't been made.
What won't change, however, is the reasoning: anything open must be open without exposing paying customers' links. A branded domain will never serve as cover for an anonymous user, because that's precisely what our clients are paying for.
What this means for an agency
The reasoning applies on your side too, if you manage links for multiple clients. A domain shared across all your clients means each one carries the others' risk: one bad campaign from one of them, and all clients' links show a warning on the same day, including those with nothing to do with it.
That's the least-cited argument for a per-client domain, and probably the strongest. The marketing agencies page describes the setup with separate workspaces, and white labeling covers what it changes for the end client: they see their own name on their links, not yours, and not a provider's.
What this means for you
Whether you use our tool or someone else's, three practical conclusions:
- Don't run important campaigns on a public shared domain. You inherit everyone else's reputation, with no control over it.
- Be wary of any service with no visible safeguards. No bot challenge, no reporting mechanism, no readable terms of service: the domain will eventually get flagged, and your links with it.
- On printed mediums, the question can't be fixed after the fact. A flyer or a QR code lives for months. The domain serving it should be yours.
Questions that come up
"The big public shorteners aren't blocked, though." They dedicate permanent resources to moderation and detection, and they have a history of reputation that protects them. A newer service has neither — which is exactly why the risk isn't the same for everyone.
"Is a short link bad for SEO, then?" That's a different question, and the answer is no — the article on short links and SEO explains what Google does with redirects. The risk this article is about is reputation, not indexation.
"What's the difference with a branded domain?" The domain belongs to you, only you create links on it, and its reputation is a reflection of your own sends. It's also what makes a link credible at the moment of the click: a readable slug under your name announces where you're going.
"Can I try without committing?" Yes, without creating an account: the demo workspace is open, with real data, and it shows what the tool does once links are created. The terms of service also specify what's prohibited on our domains.
"What about bots that click — does that skew the numbers?" That's a related but distinct topic: a bot click is detected and marked as such rather than counted, as explained in the lexicon entry on bots.
What the product collects, retains, and refuses to collect is detailed on security and GDPR. And to understand why a domain in your name changes everything, it's the short links and domains page.