SendCanyon

Deliverability

Links In Cold Email: What We Tested And What Gets Flagged

How many links can a cold email carry, and which ones get it flagged? We tested shorteners, redirects, IP links and blocklisted domains through a spam filter.

Sohaib Asghar8 min read

SendCanyon cover for Links In Cold Email: the template checker's spam filter rules for blocklisted links, a score of 8.7 against a threshold of 5.

Introduction

Your plain first email was getting replies. Then you added a calendar link, a case study and a short link to a demo video, and the replies stopped. A prospect who did answer forwarded a screenshot: your email, in their junk folder. Nothing in the copy changed, so it is natural to suspect the links. The question is which links, and why.

Search for advice on links in cold email and you will find precise-sounding numbers: every link past the third adds a fixed amount to your spam score, five links cut your inbox rate by some exact percentage. We could not find a primary source for any of them, so we tested instead. We took one short cold email, changed only its links, and scored each version with a spam filter and a full set of content checks.

The result was clear enough to change how you should think about links. The number of links barely registered with the filter. The domain behind each link, and whether the link was honest about where it went, decided almost everything.

A filter does not click anything. It extracts every URL in the message, then asks a few questions of each one:

  • Is the domain on a URI blocklist? Lists such as the Spamhaus Domain Block List and SURBL track domains seen in spam, phishing and malware. A filter looks up each link's domain against them at the moment it scores your message.
  • Does the link hide its destination? Shorteners, redirect parameters and bare IP addresses all stop the reader (and the filter) from seeing where a click lands.
  • Does the visible text match the address? Text that reads like one address while the link goes to another is the signature move of phishing.
  • Is it an ordinary web link at all? javascript: or data: links have no business in an email.

Google's sender guidelines put the principle in one line: "Web links in the message body should be visible and easy to understand. Recipients should know what to expect when they click a link." (Google's email sender guidelines)

The Test

The base email was a plain, personalised first touch from a fictional sender, [email protected], with an opt-out line and no other issues. With no link it scored 100 out of 100 and 0 on the spam filter, against a threshold of 5.0. We then swapped in each link setup below and checked again, changing nothing else.

Link setupContent scoreSpam filterWhat was flagged
No link1000Nothing
One https link on the sender's own domain1000Nothing
One bit.ly link850Link shortener (failed)
One link to http://203.0.113.24840Link to an IP address (failed); http link
Text example.com/deck, link through a redirect on another domain820Link text does not match the destination (failed); redirect
javascript: link850Unsafe link scheme (failed)
Seven links across five domains91, not ready0Too many links (failed); four outside domains
Click here text and an empty # link940Click here phrase; link with no destination
Links to the Spamhaus and SURBL test domains518.7Listed on URI blocklists: over the spam threshold

Every row except the last scored 0 on the spam filter. The content checks did the catching. The last row is the only one that a filter alone would have treated as spam, and it was not close.

Link Count Was Not What The Filter Scored

Seven links across the sender's domain and four others — a calendar booking page, a video, a review site and a blog platform — added zero spam filter points. So the claim that each extra link adds a fixed penalty did not hold on the filter we tested. Different filters weigh things differently, and we cannot speak for every one, but count alone was not a rule here.

The content checks still failed it, and we think that is right. Seven links in a message from a stranger reads as a newsletter, not a note, and that is a judgement about readers rather than filter rules. Each extra domain also adds another reputation you are borrowing: if any one of them is listed tomorrow, every message carrying it pays. Our checker passes up to three different links, warns from four to six, and fails seven or more; it also warns when links point to more than two domains besides your own.

The Domain Behind The Link Is What The Filter Scored

Spamhaus and SURBL both publish permanent test entries — dbltest.com and surbl-org-permanent-test-point.com — so administrators can confirm their lookups work. Putting both in an otherwise clean email took the spam filter from 0 to 8.7, well over the 5.0 threshold. The DBL listing alone was worth 2.5 points, and the SURBL test entry matched four of SURBL's lists for 6.2 between them.

The rules the blocklisted links triggered
Spam filter score: 8.7 (threshold 5.0)

 points  rule
------  ------------------------------------------------
   2.5  Contains a spam URL listed in the Spamhaus DBL blocklist
   1.9  Contains an URL listed in the ABUSE SURBL blocklist
   1.7  Contains an URL listed in the CT SURBL blocklist
   1.3  Contains an URL listed in the CR SURBL blocklist
   1.3  Contains a URL listed in the MW SURBL blocklist

Nothing else about the email changed. Same copy, same sender, same subject. This is why a link domain you do not control is a liability: its listing status changes without you, and the next message you send inherits it. It is also why a shared link-tracking domain is worth thinking about. If your sending tool rewrites every link through a domain shared by many senders, that domain's reputation, good or bad, travels with your message.

Patterns That Fail Outright

Four link patterns failed the content checks on their own, each costing 15 points. None of them moved the spam filter in our test, which is exactly why they need a separate check: they are what recipients and phishing classifiers react to, whether or not a rule fires.

Link Shorteners

A public shortener such as bit.ly hides the destination, and its domain is shared with everyone who has ever shortened a link with it, spammers included. A shortened link in a cold email from a stranger is a reason not to click. Link to the full address on your own domain instead; if the address is long, use descriptive link text in an HTML email.

http://203.0.113.24/case-study tells the reader nothing about who they are about to visit, and legitimate businesses almost never link that way. The checker also decodes the disguised forms — decimal, hex and octal IP addresses — because those are only ever used to dodge a filter.

Link Text That Names Another Address

In our test, the link text read example.com/deck while the link actually pointed at a redirect on links.example.net. That is the pattern phishing is built on: show a trusted address, send the click somewhere else. Text that is the same domain with a different path is fine — example.com/case-study linking to https://example.com/case-studies/list-quality passed — because the reader still lands where they were told. Plain words such as the case study avoid the problem entirely.

The template checker report for an email whose link text shows example.com/deck while the link goes to another domain: 82 out of 100, with the link text check failed and a spam filter score of 0.
The spam filter scored this email 0. The link text check still failed it.

Script And Data Links

A javascript: link usually arrives by accident, copied from a web page's button. Mail clients block these, and filters treat them as an attack. The same goes for data: and file: links. Use an ordinary https:// address or remove the link.

Smaller Things Worth Fixing

  • Redirects to another domain. A link whose ?url= or similar parameter forwards to a different site hides the destination and borrows the redirector's reputation. Link straight to the final page.
  • Plain http://. A minor warning on its own, but there is no reason to send one in 2026.
  • Empty or # links. Usually left over from a template. They go nowhere, and they suggest the email was not proofread.
  • Click here. It is on our spam phrase list for a reason: generic link text on a link from a stranger tells the reader nothing. Name what they will get: the two-minute demo, the pricing page.

For a first touch, zero or one. With no link at all, there is nothing to look up, nothing to mismatch and nothing to list, and the call to action becomes a question the reader can answer with a reply, which is what you wanted anyway. When a link genuinely helps, such as a case study the reader would ask for, use one, on your own domain, over https, with honest text. A second link is fine when it earns its place. Beyond three, you are writing a newsletter.

Follow-ups are where a single link, such as a calendar page, does its best work: the reader has seen your name before, and the link answers a question you have already asked.

How SendCanyon Handles This

Paste your template into the free email template checker and it runs every link check above alongside the spam filter score, listing each rule a link triggered. If your sending tool rewrites links for click tracking, upload the .eml of a message it actually sent, so the checker sees the links your prospects will see rather than the ones you typed.

Inside SendCanyon, the link checks run as you write: the live deliverability score on each step in the sequence editor flags a shortener, an IP link, link text that names another address or a redirect the moment you paste it, and the full template checker adds the spam filter score for the step. Open and click tracking is a per-campaign switch on the Sending tab. With it on, links are rewritten through SendCanyon's tracking host so clicks can be counted; with it off, every link goes out exactly as you wrote it, which is the cleanest choice for a first touch judged by replies. The template checker guide explains each check and its weight, and our guide to testing a template for spam covers the rest of the pre-send routine.

The SendCanyon template checker with an HTML email whose second link shows example.com/deck but goes through a redirect on another domain: 82 out of 100, the link text check failed, and a spam filter score of 0.
The template checker inside SendCanyon catches the mismatched link even though the spam filter scored the email 0.

Keep reading

Run outbound from one place.

Connect your senders, build sequences, and keep replies moving.

Start freeExplore features