SMS Short Link Rules by Country: What the Law Wants
Your campaign passed legal review and still nothing got delivered. The rules that govern a text message and the rules that govern the link inside it are two different rulebooks, and only one of them is a statute.

Your campaign was legally fine and nobody saw it
You got consent, you added the opt out, legal signed it off. Then the send report came back: half undelivered in the US, almost nothing delivered in India. The only difference between the version that worked and the version that did not was the link. That is the second rulebook, the one nobody forwards to legal, because no legislature wrote it.
Two rulebooks, two kinds of failure
Most SMS law guides cover the first rulebook: consent, identification, opt out, records. Our guide to SMS marketing links lives there, and breaking those rules gets you complaints and fines. The second rulebook governs the link inside the message, and breaking it gets you silence. Messages are filtered, or the campaign is never approved. No fine, because no delivery.
What all of these rules are afraid of
Every regime below circles one fear: a text arrives, the recipient cannot tell who sent it, they tap an opaque link, money leaves. That is also why branded short links get clicked more. Deliverability and trust are the same signal read by two audiences. This page covers the shape of the link only, not consent to track the click, which sits in the pixel and consent guide. Every legal fact here was verified on 10 September 2026.
The rules, country by country
Read the second column as the instrument that touches the URL, not the one that governs consent. In most of these markets they are different documents.
| Market | Instrument that touches the link | What it demands of the link | If you ignore it | In force |
|---|---|---|---|---|
| India | TCCCPR 2018 plus the TRAI whitelisting direction, August 2024 | No URL shortener unless the short URL clearly indicates a relation with the sender, and the URL must be whitelisted on DLT | Access providers do not permit the traffic | 1 October 2024 |
| United States | CTIA Messaging Principles and Best Practices section 5.3.2, May 2023, plus 10DLC and toll free vetting | Links must not conceal the sender; a shortener should use a web address and IP addresses dedicated to the sender | Campaign rejected at registration, or carrier filtering | May 2023 edition |
| United Kingdom | PECR 2003 regulation 23 (regulation 22 for consent) | Do not disguise or conceal the sender identity, and give a valid opt out address | ICO enforcement | December 2003 |
| European Union | ePrivacy Directive 2002/58/EC Article 13(4), implemented nationally | Same ban on concealed sender identity and on a missing opt out address | National regulator enforcement | 2002, national dates vary |
| Canada | CASL plus the Electronic Commerce Protection Regulations (CRTC) section 2(2) | A link may carry the required sender information, but it must be clearly and prominently set out and free to reach | CRTC enforcement | July 2014 |
| Australia | Spam Act 2003 (Cth) section 17, plus the Telecommunications (SMS Sender ID Register) Industry Standard 2025 | The message must identify the sender, so identity cannot live only behind the redirect, and a branded sender ID must be registered | ACMA enforcement, and an unregistered sender ID is replaced with Unverified | April 2004; register from 1 July 2026 |
How to read it
Only India uses the words URL shortening service. The US row is the strongest constraint in practice and the weakest in legal force: CTIA writes should, not shall, and a campaign that ignores it still never launches. The other rows are identity rules that happen to catch opaque links, so the question is never is this shortener allowed but can the recipient tell who this is from. Note what none of these six instruments requires: a particular vendor, no redirects, no HTTP 302, or a fixed link lifetime. A rule quoted without an instrument, a section and a date is folklore. A rule that lives in a carrier policy rather than a statute is unciteable and still decides delivery, which is the next table's problem.
Where the carrier, not the legislature, bans the link
Six instruments is not six markets, and the harshest rules on the link are not instruments at all. Twilio's Saudi Arabia SMS guidelines state that shortened URLs are prohibited, and that URLs in the message content must first be allowlisted, with delivery failure the consequence of skipping that. There is no section to cite and no regulator to appeal to. That is stricter than India, which expressly contemplates a shortened URL that shows its relation to the sender, so treat a destination you cannot shorten as a supported case rather than an exception. We list only the market we verified against the operator side ourselves; vendor roundups name several more, and each one needs checking against your own aggregator before you trust it.
India: the only regime that regulates the short URL by name
If you send commercial SMS into India you know the DLT platform, the registered sender header and the approved content template. In 2024 the link became a registered object too. TRAI issued a direction under the Telecom Commercial Communications Customer Preference Regulations, 2018 requiring URLs, APK links, OTT links and call back numbers to be whitelisted, and after a one month extension access providers had to stop passing traffic containing non whitelisted URLs, APKs and OTT links from 1 October 2024 (Newsonair, 30 August 2024). TRAI's press release 58 of 2024 gives the reason: fraud travels through malicious links in the variable parts of messages, and when headers and templates are misused it is hard to find the entity that pushed the traffic.
The shortener clause, word for word
The operative sentence, as reproduced by the platforms that implemented the mandate for their customers, reads: senders shall not use any URL shortening service or short URLs unless the shortened URL clearly indicates that it has a relation with the sender (WebEngage documentation of the TRAI mandate). Read it twice. It is not a ban on shorteners. It is a ban on anonymous shorteners, and a shortened URL that visibly belongs to you is expressly contemplated.
The documented shape is a path folder
The shape the Indian ecosystem settled on is a path folder carrying the registered header: the static part, domain plus folder, is what goes on the DLT whitelist, and the part after it varies per message. The implementers who built this for their customers publish the same pattern. msg91 documents https://m.9m.io/MSGIND/ and requires the sender ID at the end of the static path, Sprinklr documents https://spr.ly/SenderID/UniqueID and ships a path prefix setting for it, and WebEngage shows one whitelist entry per sender ID. So a business with headers ACMENX and ACMENY registers two entries, not one bare domain, and one short domain is not enough on its own.
Flyn cannot build that shape, and you should know it before you plan a campaign. A Flyn slug is a single path segment of letters, digits, hyphens and underscores, so go.example.in/ACMENX-spring is a link you can create and go.example.in/ACMENX/spring is not. For Indian traffic that leaves two honest options: use the shortener your aggregator supports for that market, which is where the path prefix feature lives today, or ask your aggregator in writing whether a whitelist entry covering your domain plus a header prefixed slug is accepted on their DLT setup before you commit a campaign to it. Do not let a vendor, us included, tell you the question does not matter.
Variable parts of a template are where whitelisting bites. If your system drops a freshly generated short URL into a placeholder at send time, that URL was never whitelisted. Build links from a registered domain and path convention before the campaign, not per recipient, and run them through the campaign URL QA checker.
The United States: the law governs consent, the carriers govern the link
No US statute or FCC rule says what a link inside a text message must look like. The TCPA and the FCC rules at 47 CFR 64.1200 govern whether you had permission to send, and are silent on URLs. So when a vendor tells you bit.ly is not allowed, they are quoting CTIA and their carrier connections, which are the documents that decide delivery.
CTIA section 5.3.2, the clause everyone paraphrases
The CTIA Messaging Principles and Best Practices, May 2023 has a short section headed Embedded Website Links. It says senders should ensure links embedded in a message do not conceal or obscure the message sender's identity, and then: where a web address shortener is used, message senders should use a shortener with a web address and IP addresses dedicated to the exclusive use of the message sender. It adds that addresses in messages, and any site they redirect to, should unambiguously identify the website owner and include contact information such as a postal mailing address.
CTIA writes should, not shall. It is the softest legal verb attached to the hardest commercial consequence: ignore it and your campaign is simply never approved.
Two details get lost in the paraphrase. It asks for a dedicated IP address, not only a dedicated domain, a bar most self serve shorteners cannot clear and should not claim to. And it reaches past the redirect: the page you land on is supposed to identify its owner and carry a postal address, so a bare landing page fails the clause even behind a perfect domain. For storefronts, see how ecommerce teams structure this.
Where it actually stops you: registration
Twilio publishes an error for it, 30525, toll free verification rejection, public URL shorteners not allowed, and its 10DLC troubleshooting guide tells customers a randomly shortened URL from a free service leads to rejection of the campaign by The Campaign Registry, and to use a dedicated branded short domain instead. A reviewer reads your sample message and looks at the host. A shared host is a rejection, and the fix is a domain change, not an appeal. The same mechanics elsewhere: why short links get flagged as spam.
The UK, the EU, Canada and Australia: do not hide behind the redirect
These four markets have no shortener clause, and people read that as permission. They all prohibit concealed sender identity in marketing messages, and a random code on a shared domain is a textbook way to conceal it. The difference is that the whole message is judged, so a clearly identified sender in the body can carry an opaque link; an unbranded body plus an opaque link is the failing combination.
United Kingdom: PECR regulation 23
PECR treats a text message as electronic mail, so the email marketing rules apply to SMS. Regulation 23 is headed use of electronic mail for direct marketing purposes where the identity or address of the sender is concealed, and it prohibits transmitting, or instigating the transmission of, direct marketing by electronic mail where the identity of the person on whose behalf it is sent has been disguised or concealed, or where no valid address has been given for a request that the messages cease. Regulation 22 is the consent half. Note what regulation 23 never mentions: domains, shorteners, redirects.
It does reach the destination, though, and this is the limb nobody quotes. Regulation 23 also bites where the electronic mail encourages recipients to visit websites which contravene regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002, which requires a commercial communication to be clearly identifiable as one and to clearly identify the person on whose behalf it is made. So a UK text pointing at a landing page that hides whose promotion it is can fail regulation 23 on the page, not on the message. The destination is part of the compliance surface, which is the same conclusion CTIA reaches from the opposite direction.
European Union: ePrivacy Article 13(4)
The same prohibition sits in Directive 2002/58/EC, Article 13(4). It is implemented by each member state rather than applying directly, so your real obligation is in national law, but the reading for a link is identical to the UK: identity, and a working way to make it stop.
Canada: the link is allowed to do the work
CASL anticipates that a short message cannot carry everything. The Electronic Commerce Protection Regulations (CRTC), section 2(2) provide that where it is not practicable to include the required information in the message, it may be posted on a web page readily accessible at no cost to the recipient by means of a link that is clearly and prominently set out in the message. Your short link becomes part of the compliance mechanism, with two conditions: prominent, and free to reach. A link behind a login, a paywall or a dead redirect does not satisfy it.
Australia: accurate sender information
The Spam Act 2003 (Cth) section 17 is headed commercial electronic messages must include accurate sender information, alongside section 16 on unsolicited messages and section 18 on a functional unsubscribe facility. The consequence follows from the word accurate: if the only place your identity appears is behind the redirect, the message has not identified you.
From 1 July 2026 Australia carries a second duty, and it is the newest rule on this page. The Telecommunications (SMS Sender ID Register) Industry Standard 2025 was registered on 8 October 2025 and commences in stages, with Part 3 apart from subsection 15(2), and Part 5, starting on 1 July 2026. From that date a message carrying a sender identification that is not on the ACMA register is disrupted, which the Standard defines as the sender identification being replaced with a new one reading Unverified. The obligations sit on carriers, carriage service providers and messaging providers rather than on you, the same structure as India's direction, so the failure again arrives as something done to your traffic rather than as a notice addressed to you.
Operationally: register the sender ID through your provider before an Australian send, under a name you can evidence. An entity with an Australian Business Number registers through a participating telecommunications provider, and the sender ID must have a clear and verifiable connection to its registered business name, company name, trade mark or domain name. An entity without an ABN, including an international sender, registers through a provider the ACMA has certified for that purpose, against a trade mark or its name on an official register in the country where it is based. The Standard says nothing about URLs, so it does not change what your link may look like. It changes something worse: once the header reads Unverified, the identity the link is supposed to confirm is gone before the recipient reaches the body.
What the link has to be, and what a redirect changes
Now the part legal summaries skip: what happens mechanically when the recipient taps, and which mechanics the rules above care about.
The domain is the signal, the path is the proof
A custom domain satisfies the dedicated host half of the CTIA clause and the relation to the sender half of the TRAI clause at a glance. The path carries your registered header in India. Flyn custom slugs accept letters, digits, hyphens and underscores, up to 100 characters, unique per domain, reserved system words refused, a random six character id by default. So go.example.in/ACMENX-spring is a slug you can create. What you cannot create is the /ACMENX/ path folder that the Indian ecosystem whitelists, because a Flyn slug is a single path segment. For India that is a hard limit rather than a detail to check later, and the India section above says what to do instead. Pick the host with the branded domain finder and set it up via connect a custom domain.
What the redirect leaks, and what it stores
A Flyn short link is a 302 redirect that sends a Referrer-Policy of strict-origin-when-cross-origin, so the destination sees only your short link origin as the referrer on a cross origin hop, never the full short URL with its slug. The original referrer is recorded by Flyn and never reaches the destination unless you forward it in a parameter. A click stores country, city, device, operating system, browser, referrer, a hashed IP, any UTM values on the short URL, and a timestamp. There is no advertising identifier, and as of 10 September 2026 the redirect sets no cookie. Hits from known crawlers, preview fetchers, headless browsers, HTTP libraries, uptime monitors and blank user agents are screened by user agent before counting and reported separately on every plan, which matters because carrier scanners reach your link before any human. Background: 301 versus 302 and what happens to tracking parameters.
Where each requirement is configured
Mapping the five properties onto real settings, with the plan each one needs, so nobody promises a client something the account cannot do.
| What the rules ask for | What you set | Plan |
|---|---|---|
| A host dedicated to you | Custom domain, up to three | Pro, Lifetime or Team |
| A path that names the sender | Custom slug, up to 100 characters | Free |
| A fixed destination, no open redirect | Default behaviour of every link | Free |
| Separating scanner hits from people | Filtered bot count per link | Free |
| Proving where delivered clicks came from | Country and device breakdown | Pro, Lifetime or Team |
| Ending a campaign cleanly | Expiry date | Free |
| Capping a link after N clicks | Click limit with a fallback URL | Pro, Lifetime or Team |
The honest limits. Flyn is a link product, not a compliance product. It does not submit anything to DLT, register a 10DLC campaign, or give you a dedicated IP address, and calling any shortener TRAI compliant or carrier approved would be a claim nobody can make for you. What it does is build the shape the rules describe: your domain, your slug, a fixed destination, no open redirect for someone else to abuse.
Keep one short domain per market and never reuse an SMS host for anything else. The moment it also carries affiliate traffic or cold outreach, one abuse report can get the whole host filtered and every campaign dies with it. Vet the host with the short link safety checker and audit live links with the redirect checker.
The pre send checklist
Run this before a single message leaves. Steps 1 to 4 are the ones that silently kill campaigns.
- Pick a dedicated host. One domain or subdomain used only for SMS links in that market.
- Decide the path convention now. For India, the registered sender header in the folder your aggregator whitelists; a readable brand word elsewhere. Write it down.
- Register where registration exists. Whitelist the URL on DLT for India; put the real short domain in your 10DLC or toll free samples, never a placeholder; register the branded sender ID on the ACMA register for Australia.
- Check whether the market allows a shortened URL at all. Saudi Arabia prohibits them and requires message URLs to be allowlisted first, so that branch sends the long link, allowlisted in advance.
- Check the destination identifies you. Company name, contact details and a postal address, reachable without a login.
- Name the sender in the body too. The UK, EU and Australian rules are satisfied by the message, not the domain.
- Give a working opt out. PECR regulation 23 and ePrivacy Article 13(4) both require it alongside identity.
- Confirm the redirect resolves over HTTPS to the exact destination with the URL expander.
- Send one test to a real handset per carrier and read it as a stranger would.
- Log what you registered and when: headers, templates, whitelisted URLs, campaign ids.
- Watch the first hour of clicks. Scanner hits with no human clicks usually means delivery failed, not that the offer failed.
For bulk sends, generate links once from the registered domain with the bulk URL shortener or the shorten endpoint, and tag them with UTM parameters.
Enforcement reality: the penalty is usually an absence
Almost none of these failures arrive as a fine. They arrive as nothing happening, which is why they go undiagnosed for months.
Blocked in India, rejected in the US
India's direction is addressed to access providers, not to you, so the failure looks like a delivery receipt problem or messages that never arrive, with nothing saying a URL caused it. Your aggregator is often the only party who can tell you which part of the template failed. In the US the clean outcome is a documented rejection at registration, before you spend money; the messy one is traffic that passes vetting and is filtered in the wild, where throughput falls with no error you can act on.
The gotcha that catches careful teams
Rotating the destination after approval. Editing where a link points is normal link management, but where the URL was whitelisted or submitted as a sample, a link that now leads somewhere unrelated to the approved campaign is exactly the pattern fraud detection hunts. Keep an approved link pointing at the approved kind of destination and mint a new link for a new offer; if a campaign must stop, link expiration is cleaner than repointing. In the UK, EU, Canada and Australia the same facts land differently: an opaque link on a host with no relationship to the named sender is evidence that identity was concealed.
One convention, and the fallback it cannot cover
There is no single link convention that clears every market, and that is the honest version of this page. The markets that regulate the shape of the link, India above all, can be satisfied by one convention you apply everywhere. The strictest markets do not regulate the shape at all: they ban shortening, and the only thing that clears a ban is not shortening. So build both, a convention plus a long link you can actually send, and decide which markets take which before the campaign calendar is full.
One host per market, one convention everywhere
Use a short subdomain of a domain you already own. Flyn allows three custom domains on a paid plan, which maps onto three markets. Keep the slug convention identical everywhere so reporting stays comparable, and put the brand or header token first so the link reads as yours in a notification preview. Naming tradeoffs: choosing a branded short domain and custom domains and trust.
Passcodes, and the character budget
Treat transactional and passcode messages as the strictest case, not the easiest: they are what fraud imitates, so an opaque host is the worst place to save characters. For payments into India a UPI payment link avoids a redirect entirely. A branded host costs characters and buys delivery, and that trade is not close, so trim the slug instead of the domain; the rest of the character budget and campaign tracking is a separate craft. Build the message with the SMS link generator, keep support replies on a tel link, and if you send from Klaviyo or Brevo, set the registered domain in the platform's link settings so nobody ships a default shortener by accident. Keep one page listing, per market, the host, the convention, what you whitelisted, the date and who approved it, because most of the pain here is that the person who registered the domain has left. Small teams can park it beside the campaign calendar, see the small business workflow.
The fallback, and when it is the only option
Keep the full destination in the campaign brief next to the short one, and keep it sendable: a clean path on your own domain, no tracking tail, nothing that depends on a redirect. Where Twilio's guidelines say shortened URLs are prohibited and message URLs must be allowlisted first, as in Saudi Arabia, that long link is the only version you can send, and the allowlisting happens before the send rather than after the first failure. The same fallback covers any aggregator whose policy is stricter than its market's law, which is most of them. On that branch you give up click attribution, because there is no redirect to measure; choose that in advance rather than discovering it when a market goes quiet.
This page is general information, not legal advice. Rules change, national implementations differ, and your aggregator's policy may be stricter than anything quoted here. Confirm your obligations with a qualified adviser and with your carrier or access provider before you send.
Frequently Asked Questions
Is bit.ly allowed in SMS?
Do passcode and transactional messages need URL whitelisting in India?
Does the Indian rule apply if my company is not in India?
What does CTIA mean by a shortener dedicated to my exclusive use?
Will a branded short domain on its own stop carrier filtering?
Can I use one short domain for every country?
Does a QR code on a poster fall under these rules?
What about WhatsApp, RCS and other app channels?
Free tools for this
Three Flyn tools that pair well with the strategy in this article, all free, no signup needed.
Security Headers Checker
Audit HTTP security headers.
Redirect Checker
Trace 301/302 redirect chains.
URL Cleaner
Strip tracking params from any URL.
Keep reading
Three related deep-dives from the Flyn blog.
Retargeting Pixels and Consent: GDPR & CCPA
12 min read

Are Short Links Safe? How to Check Before You Click
13 min read
Does a Short Link Click Need Cookie Consent? Law by Law
31 min read
Ready to try Flyn?
Free plan includes 25 links/month, full analytics, and access to all 30+ free tools above. No credit card required.
Already a member? Log in

Karan Bhakuni is the founder of Flyn. He writes about branded links, click analytics, and the link-management tooling growth teams and creators actually need, drawn from building Flyn and reading a lot of user feedback.
Find these guides useful? Add Flyn as a preferred source so more of them show up in your Google results.