ShortGo
FeaturesPricing BlogHelpLog in
All articles
Security4 min read

Link Security: Stop Phishing, Lock Links, Block Bots

Protect your short links and the people who click them: phishing scans, passwords, expiry dates, click limits, bot blocking and account security.

Short links are convenient precisely because they hide the long URL behind them. That same property is what makes people cautious: a visitor can’t see where a short link goes until they click it. If you share links professionally, security works both ways. You need to protect your audience from bad destinations, and you need to protect your own links, data and account from misuse.

This guide covers the practical side of both: how phishing abuse works, when to use passwords, expiry dates and click limits, what bot blocking really does, and how to keep your workspace locked down.

Attackers like anything that obscures a destination. A random short link can disguise a credential-harvesting page as a harmless shared document. That is why responsible link shorteners scan what people shorten and give visitors ways to check a link before opening it.

In ShortGo, new links are checked against Google Safe Browsing and the URLhaus malware list, plus heuristics that look for common phishing patterns. Unsafe links are blocked or flagged for moderation, and creation rate limits apply to both anonymous and signed-in users, so mass-producing malicious links is much harder.

Scanning is only half the story. Your audience also needs signals that a link is genuinely yours:

  • Use a branded domain. A link on go.yourbrand.com is far easier to trust than a random string on a generic domain. See our guide to custom domains and Cloudflare edge.
  • Use readable aliases. /spring-sale tells people what to expect; /x7Kq2 does not.
  • Teach the preview trick. Adding a “+” to the end of any ShortGo link (for example go.example/abc+) opens a safe preview page that shows the destination before the visitor goes there.
  • Set a custom social preview. A clear Open Graph title, description and image make shared links look intentional in chats and feeds.

Report what looks wrong

If you come across a ShortGo link that points to phishing, malware or other abusive content, use the public Report abuse form. Admins can ban offending links and users.

Not every link should be public forever. ShortGo gives you several controls you can combine on a single link.

Password protection

A password-protected link shows a prompt; only visitors who enter the right password reach the destination. It is a good fit for:

  • Pre-release material shared with press or partners
  • Internal documents sent to a small group
  • Paid content handed out after purchase

Share the password through a different channel than the link itself, for example the link by email and the password in a message, and change it if it leaks.

Expiration dates and click limits

An expiration date turns a link off at a specific time. A click limit stops it after a set number of clicks. Typical uses:

  1. Time-boxed promotions and early-bird offers
  2. Limited giveaways where only the first N people should get through
  3. Temporary download or registration links

Pair either option with an expired redirect URL. Instead of a dead end, visitors land somewhere useful, such as a “this offer has ended” page or your current promotions.

Bot blocking

Bot blocking stops known bots from following the link. This keeps scrapers and automated tools away from your destination. Importantly, link-preview crawlers from platforms like Slack, Facebook and X are still allowed through, so your links continue to unfurl with a proper preview when you share them.

Even without bot blocking turned on, ShortGo detects bots and crawlers from their user agent and excludes them from click totals by default, so your analytics stay focused on real people.

Choosing the right control

Situation Recommended setting
Sharing confidential files with a few people Password + expiration date
Flash sale ending Sunday night Expiration date + expired redirect
First 100 sign-ups only Click limit + expired redirect
Link being scraped or hammered by automation Bot blocking
Public campaign link Branded domain + clear alias + social preview

Securing your account and workspace

A secure link is only as safe as the account that controls it. Anyone who can sign in can change destinations, so treat your ShortGo login like any other business-critical account.

  • Turn on two-factor authentication. ShortGo supports TOTP authenticator apps. With 2FA enabled, a stolen password alone is not enough to get in.
  • Review your sessions. You can see where you are signed in and revoke sessions you don’t recognise, such as an old laptop or a shared computer.
  • Use a strong, unique password. ShortGo stores passwords with argon2id hashing and limits login attempts, but a reused password is still your weakest point.
  • Give people the least access they need. Use workspace roles deliberately: Owner, Admin, Editor (create and edit links and assets) and Viewer (read-only, analytics). A client who only needs reports should be a Viewer.
  • Check the audit log. Important actions are recorded, which helps you understand who changed what.

Developers: keep keys and webhooks safe

If you use the ShortGo API, treat API keys like passwords: store them in environment variables or a secrets manager, never in client-side code or public repositories, and rotate them when a team member leaves. For webhooks, always verify the X-ShortGo-Signature header. Each delivery is signed with HMAC-SHA256 over the timestamp and body, so you can reject forged requests. Inside ShortGo, third-party secrets are encrypted at rest with AES-GCM.

A quick security checklist

  • 2FA enabled for every workspace member
  • Roles reviewed; former teammates removed
  • Sensitive links protected with passwords and expiry
  • API keys stored safely; webhook signatures verified

Need help with any of these settings? The help center walks through each option step by step.

FAQ

Yes. Add a “+” to the end of the short link to open a preview page that shows the destination without redirecting.

No. Bot blocking still lets link-preview crawlers like those from Slack, Facebook and X through, so your links keep unfurling normally.

The link stops sending visitors to the destination. If you set an expired redirect URL, visitors are sent there instead of seeing a dead end.

Share this article
X LinkedIn Facebook

Put these ideas to work

Create branded links, QR codes and bio pages in seconds.

Start for free

We use essential cookies to run this site. Learn more