Back to help
03

What happens when a link is opened

When a visitor opens a short link, clk.ms checks the link status in a clear order: whether the owner account is active, whether the link has started, whether it has expired, whether the click limit is still available, and whether password, email code, referrer, preview, or warning controls apply. If smart routing rules exist, the visitor can be sent to a destination selected by country, region, language, device, browser, time, date, random split, or fallback availability. If no rule matches, the default destination is used.

How short links work

A short link consists of a domain and a code, for example https://clk.ms/sale-2026. The destination is the address to which the service redirects a visitor. Changing an existing link’s destination lets you update a campaign page while keeping the short URL you have already published.

A link can have an expiry date, a start time, a click limit, a password, email verification, referrer restrictions, intermediate pages, UTM parameters and destination rules. These settings serve different purposes and can be used together.

A link without an expiry date has no scheduled end date. This does not mean an HTTP 301 redirect or a promise to store the link forever. Click limits, access restrictions and service rules still apply. Links may be deleted after three years without a click.

Identifier — the part of the address after /. In the interface, it is also referred to as "your identifier." Only Latin letters A–Z, a–z, numbers, hyphen, and underscore are allowed for a personal identifier; length — from 3 to 100 characters. For example, sale-2026 is allowed, but продажи-2026 and sale 2026 are not. Uppercase and lowercase Latin letters are distinguished. Reserved names, such as help, account, and api, cannot be taken.

Passwords, email/OTP and access restrictions

All these settings are available when creating a link in the corresponding additional blocks and subsequently in the link card → «Settings». Save each modified form.

Link password

Specify a non-blank password of up to 256 characters. The password cannot consist only of spaces. Give it to the recipient in a separate, convenient way. When opened, the link will show the form; the correct password allows you to continue checking and clicking on the link. An incorrect password should not open the target URL.

To change, enter a new password and save. To remove protection, use the «Remove password» flag. The field does not show the previously saved password. Do not use your account password here.

Access via email and one-time code

Enable email/OTP and, if necessary, set allowed emails or domains. The visitor enters the address, receives a six-digit code and confirms it. The code is valid for 10 minutes; Up to five entry attempts are allowed. The number of code requests for one link is limited to ten per minute.

List examples: person@example.com, @example.com, *.example.com. Separate values ​​with commas, semicolons, or line breaks. The list is limited to 2048 characters. An empty list does not set domain restrictions: confirmation of the entered email is required, but not affiliation with a specific organization.

If there is no letter, check your email, Spam folder and allowed list. After requesting a new code, use the current email. Do not publish the code you receive: it is intended to confirm the recipient's access.

Allowed referrers

Referrer - browser information about the source of the click on the link. You can add a host name, origin, or a subdomain mask to the list: for example, partner.example, https://partner.example, *.trusted.example. The separators are the same as for the email list; maximum length is 2048 characters.

If the restriction is enabled, direct opening from the address bar, app, or QR may fail to pass the referrer and result in a denial. The source site or browser itself may also be hiding it. To check, follow the link from a truly authorized page. Referrer is not a reliable proof of identity; for specific people access, use a password or email/OTP.

Preview and warning

The preview page lets visitors review a link before continuing. The warning page asks for an additional confirmation. You can enable either mode alone or combine them with other restrictions. Continuing does not bypass the remaining access checks.

Use a new private window to test the entire access flow: the current session may already remember some confirmations. Use the simulator when it is sufficient, instead of increasing a click limit merely to run repeated tests. Password and OTP access still need to be checked with a real visit.

Deletion, expiry and code reuse

The link stops regular clicking on the link when it expires or reaches the limit. If a fallback destination URL is configured after completion, it may open. Otherwise, the service shows an unavailable state; background procedures may subsequently delete the master entry.

Removing from “My Links” is a separate action. Check the selected line and confirmation. After removal, the usual click on the link and associated tools may no longer be available. Historical information is not a promise of full recovery through the interface.

The service also clears links that have not been used for three years. For a link without a single click on the link, the period is counted from creation, otherwise - from the last click on the link. Having a forever mode or fallback URL does not override this inactivity rule.

The released short identifier can be reused. Therefore, deleting an old link cannot be considered a way to permanently reserve its address. For a long-lasting printable QR, keep the active link and change its target URL instead of deleting and re-creating it.

Complete user guide ยท Practical course

How to apply this section

Each topic explains a feature, the user decision behind it, and how to use it without making the link harder to manage. Read the checklist before changing a link that is already shared.

Before you publish or update

  • Start from the visitor experience: who opens the link, from where, on which device, and what should happen next.
  • Check that the destination is correct, opens quickly, and shows the expected page for the intended audience.
  • Choose only the controls that match the goal, such as expiration, password, referrer, QR design, UTM, routing, or analytics sharing.
  • Save a short note for important changes so future review, rollback, or teamwork stays clear.
  • Open the short link in a private browser session and, when relevant, test mobile, desktop, QR scan, and protected access paths.
  • Review analytics after sharing to confirm real visitors, source quality, device mix, and campaign performance.

Practical example

Example: create a test link for an internal page, add a clear slug, set a short expiration, enable preview if the destination is sensitive, scan the QR code from a phone, then check whether the visit appears in the link statistics.

Next step

After this topic is clear, combine it with one adjacent feature. For example, pair UTM with campaigns, QR with print layouts, targeting with fallback, or webhooks with conversion tracking.