Back to help
15

Trust, abuse, and prohibited content

clk.ms rejects links that point back to the service, malformed destinations, excessive-length URLs, and known spam or malicious destinations when detection is available. Public creation can be limited when one IP creates too many links, and abusive IP addresses can be blocked temporarily or permanently. Users may not create links to illegal content, spam, phishing, malware, or other harmful destinations. Confirmed abuse can lead to permanent account and IP blocking.

Passwords, email/OTP and access restrictions

All these settings are available when creating a link in the corresponding additional blocks and subsequently in the link card → «Settings». Save each modified form.

Link password

Specify a non-blank password of up to 256 characters. The password cannot consist only of spaces. Give it to the recipient in a separate, convenient way. When opened, the link will show the form; the correct password allows you to continue checking and clicking on the link. An incorrect password should not open the target URL.

To change, enter a new password and save. To remove protection, use the «Remove password» flag. The field does not show the previously saved password. Do not use your account password here.

Access via email and one-time code

Enable email/OTP and, if necessary, set allowed emails or domains. The visitor enters the address, receives a six-digit code and confirms it. The code is valid for 10 minutes; Up to five entry attempts are allowed. The number of code requests for one link is limited to ten per minute.

List examples: person@example.com, @example.com, *.example.com. Separate values ​​with commas, semicolons, or line breaks. The list is limited to 2048 characters. An empty list does not set domain restrictions: confirmation of the entered email is required, but not affiliation with a specific organization.

If there is no letter, check your email, Spam folder and allowed list. After requesting a new code, use the current email. Do not publish the code you receive: it is intended to confirm the recipient's access.

Allowed referrers

Referrer - browser information about the source of the click on the link. You can add a host name, origin, or a subdomain mask to the list: for example, partner.example, https://partner.example, *.trusted.example. The separators are the same as for the email list; maximum length is 2048 characters.

If the restriction is enabled, direct opening from the address bar, app, or QR may fail to pass the referrer and result in a denial. The source site or browser itself may also be hiding it. To check, follow the link from a truly authorized page. Referrer is not a reliable proof of identity; for specific people access, use a password or email/OTP.

Preview and warning

The preview page lets visitors review a link before continuing. The warning page asks for an additional confirmation. You can enable either mode alone or combine them with other restrictions. Continuing does not bypass the remaining access checks.

Use a new private window to test the entire access flow: the current session may already remember some confirmations. Use the simulator when it is sufficient, instead of increasing a click limit merely to run repeated tests. Password and OTP access still need to be checked with a real visit.

Troubleshooting

Situation — What to check Target URL not accepted — Scheme, completeness of the address, length and absence of a link to the service itself. Copy the exact error message. Own ID is busy — Use a different ID; check case and service names. The link doesn't work yet — UTC start time and actual current UTC. Link has ended — End date, counter and limit; Availability of a backup URL. All owner links are unavailable — Status of account freezing and service messages. The correct password does not immediately lead to the site — An OTP, warning or other check may remain. Go through the entire chain in a new session. OTP does not arrive — Email, allowed list, code period, request frequency, Spam folder and mail delivery. Referrer is prohibited — The actual source page and the browser's transmission to the referrer; direct opening may not transmit it. Unexpected target URL is selected — Priorities, inclusion, dates, UTC, empty conditions, weights and up-to-date status information. Compare the scenario in the simulator. One person always sees one A/B option — This is expected if the visitor's technical key is stable. Check different virtual numbers. The new address did not appear after the change — Form saving, active targeting rule, permanent redirect cache and openable short address. QR looks correct but doesn't scan — Contrast, white margins, overlapping blocks, print size, image quality and content mode. Old phone in printed vCard — Contacts are built into the QR itself. Generate and distribute new code. No conversions — Token, actual pixel execution/POST, API response, link state and download blocking. Webhook did not arrive — HTTPS, public handler availability, mode and threshold, inclusion, last delivery error. Fewer notifications than clicks — Interval between messages, exclusion of bots and channel availability. CSV partially imported — Result by line, encoding, separator, dates, 100 line limit and occupied identifiers. No function button — Login, owner access rights and feature availability for the account. Copying is prohibited by the browser — Select the short address and copy it manually or allow access to the clipboard for the site.

To contact support, please prepare a short address, time of the problem with the time zone, action, expected and actual result, error text, language and browser. Do not send passwords, one-time codes or API tokens. The support contact is located in the header of the site.

Complete user guide ยท Practical course

How to apply this section

Each topic explains a feature, the user decision behind it, and how to use it without making the link harder to manage. Read the checklist before changing a link that is already shared.

Before you publish or update

  • Start from the visitor experience: who opens the link, from where, on which device, and what should happen next.
  • Check that the destination is correct, opens quickly, and shows the expected page for the intended audience.
  • Choose only the controls that match the goal, such as expiration, password, referrer, QR design, UTM, routing, or analytics sharing.
  • Save a short note for important changes so future review, rollback, or teamwork stays clear.
  • Open the short link in a private browser session and, when relevant, test mobile, desktop, QR scan, and protected access paths.
  • Review analytics after sharing to confirm real visitors, source quality, device mix, and campaign performance.

Practical example

Example: create a test link for an internal page, add a clear slug, set a short expiration, enable preview if the destination is sensitive, scan the QR code from a phone, then check whether the visit appears in the link statistics.

Next step

After this topic is clear, combine it with one adjacent feature. For example, pair UTM with campaigns, QR with print layouts, targeting with fallback, or webhooks with conversion tracking.