Back to Blog

SMS Short Link Rules by Country: What the Law Wants

Your campaign passed legal review and still nothing got delivered. The rules that govern a text message and the rules that govern the link inside it are two different rulebooks, and only one of them is a statute.

Karan Bhakuni
Karan Bhakuni
Founder, Flyn
SecuritySep 10, 202617 min readUpdated Sep 10, 2026
SMS Short Link Rules by Country: What the Law Wants

Your campaign was legally fine and nobody saw it

You got consent, you added the opt out, legal signed it off. Then the send report came back: half undelivered in the US, almost nothing delivered in India. The only difference between the version that worked and the version that did not was the link. That is the second rulebook, the one nobody forwards to legal, because no legislature wrote it.

Two rulebooks, two kinds of failure

Most SMS law guides cover the first rulebook: consent, identification, opt out, records. Our guide to SMS marketing links lives there, and breaking those rules gets you complaints and fines. The second rulebook governs the link inside the message, and breaking it gets you silence. Messages are filtered, or the campaign is never approved. No fine, because no delivery.

Side by side comparison of the message rulebook written by legislatures and the link rulebook written by carriers, regulators and aggregatorsTap to enlarge
Consent rules decide whether you may send. Link rules decide whether the link survives the trip.

What all of these rules are afraid of

Every regime below circles one fear: a text arrives, the recipient cannot tell who sent it, they tap an opaque link, money leaves. That is also why branded short links get clicked more. Deliverability and trust are the same signal read by two audiences. This page covers the shape of the link only, not consent to track the click, which sits in the pixel and consent guide. Every legal fact here was verified on 10 September 2026.

The rules, country by country

Read the second column as the instrument that touches the URL, not the one that governs consent. In most of these markets they are different documents.

MarketInstrument that touches the linkWhat it demands of the linkIf you ignore itIn force
IndiaTCCCPR 2018 plus the TRAI whitelisting direction, August 2024No URL shortener unless the short URL clearly indicates a relation with the sender, and the URL must be whitelisted on DLTAccess providers do not permit the traffic1 October 2024
United StatesCTIA Messaging Principles and Best Practices section 5.3.2, May 2023, plus 10DLC and toll free vettingLinks must not conceal the sender; a shortener should use a web address and IP addresses dedicated to the senderCampaign rejected at registration, or carrier filteringMay 2023 edition
United KingdomPECR 2003 regulation 23 (regulation 22 for consent)Do not disguise or conceal the sender identity, and give a valid opt out addressICO enforcementDecember 2003
European UnionePrivacy Directive 2002/58/EC Article 13(4), implemented nationallySame ban on concealed sender identity and on a missing opt out addressNational regulator enforcement2002, national dates vary
CanadaCASL plus the Electronic Commerce Protection Regulations (CRTC) section 2(2)A link may carry the required sender information, but it must be clearly and prominently set out and free to reachCRTC enforcementJuly 2014
AustraliaSpam Act 2003 (Cth) section 17, plus the Telecommunications (SMS Sender ID Register) Industry Standard 2025The message must identify the sender, so identity cannot live only behind the redirect, and a branded sender ID must be registeredACMA enforcement, and an unregistered sender ID is replaced with UnverifiedApril 2004; register from 1 July 2026

How to read it

Only India uses the words URL shortening service. The US row is the strongest constraint in practice and the weakest in legal force: CTIA writes should, not shall, and a campaign that ignores it still never launches. The other rows are identity rules that happen to catch opaque links, so the question is never is this shortener allowed but can the recipient tell who this is from. Note what none of these six instruments requires: a particular vendor, no redirects, no HTTP 302, or a fixed link lifetime. A rule quoted without an instrument, a section and a date is folklore. A rule that lives in a carrier policy rather than a statute is unciteable and still decides delivery, which is the next table's problem.

Six instruments is not six markets, and the harshest rules on the link are not instruments at all. Twilio's Saudi Arabia SMS guidelines state that shortened URLs are prohibited, and that URLs in the message content must first be allowlisted, with delivery failure the consequence of skipping that. There is no section to cite and no regulator to appeal to. That is stricter than India, which expressly contemplates a shortened URL that shows its relation to the sender, so treat a destination you cannot shorten as a supported case rather than an exception. We list only the market we verified against the operator side ourselves; vendor roundups name several more, and each one needs checking against your own aggregator before you trust it.

India: the only regime that regulates the short URL by name

If you send commercial SMS into India you know the DLT platform, the registered sender header and the approved content template. In 2024 the link became a registered object too. TRAI issued a direction under the Telecom Commercial Communications Customer Preference Regulations, 2018 requiring URLs, APK links, OTT links and call back numbers to be whitelisted, and after a one month extension access providers had to stop passing traffic containing non whitelisted URLs, APKs and OTT links from 1 October 2024 (Newsonair, 30 August 2024). TRAI's press release 58 of 2024 gives the reason: fraud travels through malicious links in the variable parts of messages, and when headers and templates are misused it is hard to find the entity that pushed the traffic.

The shortener clause, word for word

The operative sentence, as reproduced by the platforms that implemented the mandate for their customers, reads: senders shall not use any URL shortening service or short URLs unless the shortened URL clearly indicates that it has a relation with the sender (WebEngage documentation of the TRAI mandate). Read it twice. It is not a ban on shorteners. It is a ban on anonymous shorteners, and a shortened URL that visibly belongs to you is expressly contemplated.

The documented shape is a path folder

The shape the Indian ecosystem settled on is a path folder carrying the registered header: the static part, domain plus folder, is what goes on the DLT whitelist, and the part after it varies per message. The implementers who built this for their customers publish the same pattern. msg91 documents https://m.9m.io/MSGIND/ and requires the sender ID at the end of the static path, Sprinklr documents https://spr.ly/SenderID/UniqueID and ships a path prefix setting for it, and WebEngage shows one whitelist entry per sender ID. So a business with headers ACMENX and ACMENY registers two entries, not one bare domain, and one short domain is not enough on its own.

Flyn cannot build that shape, and you should know it before you plan a campaign. A Flyn slug is a single path segment of letters, digits, hyphens and underscores, so go.example.in/ACMENX-spring is a link you can create and go.example.in/ACMENX/spring is not. For Indian traffic that leaves two honest options: use the shortener your aggregator supports for that market, which is where the path prefix feature lives today, or ask your aggregator in writing whether a whitelist entry covering your domain plus a header prefixed slug is accepted on their DLT setup before you commit a campaign to it. Do not let a vendor, us included, tell you the question does not matter.

Four gates an Indian SMS link passes: DLT registration, URL whitelisting, template registration, then the operator check, with a failing and a passing link exampleTap to enlarge
The four gates an Indian SMS link passes before delivery, and the shortener clause applied to a real URL.
Watch out

Variable parts of a template are where whitelisting bites. If your system drops a freshly generated short URL into a placeholder at send time, that URL was never whitelisted. Build links from a registered domain and path convention before the campaign, not per recipient, and run them through the campaign URL QA checker.

The UK, the EU, Canada and Australia: do not hide behind the redirect

These four markets have no shortener clause, and people read that as permission. They all prohibit concealed sender identity in marketing messages, and a random code on a shared domain is a textbook way to conceal it. The difference is that the whole message is judged, so a clearly identified sender in the body can carry an opaque link; an unbranded body plus an opaque link is the failing combination.

Matrix of the UK, EU, Canada and Australia showing the instrument that touches the link, whether identity may sit behind the link, and the condition attached, including the Australian sender ID registerTap to enlarge
The four markets with no shortener clause, how far each lets identity travel behind the redirect, and the Australian register.

United Kingdom: PECR regulation 23

PECR treats a text message as electronic mail, so the email marketing rules apply to SMS. Regulation 23 is headed use of electronic mail for direct marketing purposes where the identity or address of the sender is concealed, and it prohibits transmitting, or instigating the transmission of, direct marketing by electronic mail where the identity of the person on whose behalf it is sent has been disguised or concealed, or where no valid address has been given for a request that the messages cease. Regulation 22 is the consent half. Note what regulation 23 never mentions: domains, shorteners, redirects.

It does reach the destination, though, and this is the limb nobody quotes. Regulation 23 also bites where the electronic mail encourages recipients to visit websites which contravene regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002, which requires a commercial communication to be clearly identifiable as one and to clearly identify the person on whose behalf it is made. So a UK text pointing at a landing page that hides whose promotion it is can fail regulation 23 on the page, not on the message. The destination is part of the compliance surface, which is the same conclusion CTIA reaches from the opposite direction.

European Union: ePrivacy Article 13(4)

The same prohibition sits in Directive 2002/58/EC, Article 13(4). It is implemented by each member state rather than applying directly, so your real obligation is in national law, but the reading for a link is identical to the UK: identity, and a working way to make it stop.

CASL anticipates that a short message cannot carry everything. The Electronic Commerce Protection Regulations (CRTC), section 2(2) provide that where it is not practicable to include the required information in the message, it may be posted on a web page readily accessible at no cost to the recipient by means of a link that is clearly and prominently set out in the message. Your short link becomes part of the compliance mechanism, with two conditions: prominent, and free to reach. A link behind a login, a paywall or a dead redirect does not satisfy it.

Australia: accurate sender information

The Spam Act 2003 (Cth) section 17 is headed commercial electronic messages must include accurate sender information, alongside section 16 on unsolicited messages and section 18 on a functional unsubscribe facility. The consequence follows from the word accurate: if the only place your identity appears is behind the redirect, the message has not identified you.

From 1 July 2026 Australia carries a second duty, and it is the newest rule on this page. The Telecommunications (SMS Sender ID Register) Industry Standard 2025 was registered on 8 October 2025 and commences in stages, with Part 3 apart from subsection 15(2), and Part 5, starting on 1 July 2026. From that date a message carrying a sender identification that is not on the ACMA register is disrupted, which the Standard defines as the sender identification being replaced with a new one reading Unverified. The obligations sit on carriers, carriage service providers and messaging providers rather than on you, the same structure as India's direction, so the failure again arrives as something done to your traffic rather than as a notice addressed to you.

Operationally: register the sender ID through your provider before an Australian send, under a name you can evidence. An entity with an Australian Business Number registers through a participating telecommunications provider, and the sender ID must have a clear and verifiable connection to its registered business name, company name, trade mark or domain name. An entity without an ABN, including an international sender, registers through a provider the ACMA has certified for that purpose, against a trade mark or its name on an official register in the country where it is based. The Standard says nothing about URLs, so it does not change what your link may look like. It changes something worse: once the header reads Unverified, the identity the link is supposed to confirm is gone before the recipient reaches the body.

The pre send checklist

Run this before a single message leaves. Steps 1 to 4 are the ones that silently kill campaigns.

Decision tree asking whether the send reaches Indian handsets, US carriers, Australian sender IDs or other markets, with the registration step each answer requiresTap to enlarge
Which registration step applies depends on where the message lands, and one market takes no short link at all.
  1. Pick a dedicated host. One domain or subdomain used only for SMS links in that market.
  2. Decide the path convention now. For India, the registered sender header in the folder your aggregator whitelists; a readable brand word elsewhere. Write it down.
  3. Register where registration exists. Whitelist the URL on DLT for India; put the real short domain in your 10DLC or toll free samples, never a placeholder; register the branded sender ID on the ACMA register for Australia.
  4. Check whether the market allows a shortened URL at all. Saudi Arabia prohibits them and requires message URLs to be allowlisted first, so that branch sends the long link, allowlisted in advance.
  5. Check the destination identifies you. Company name, contact details and a postal address, reachable without a login.
  6. Name the sender in the body too. The UK, EU and Australian rules are satisfied by the message, not the domain.
  7. Give a working opt out. PECR regulation 23 and ePrivacy Article 13(4) both require it alongside identity.
  8. Confirm the redirect resolves over HTTPS to the exact destination with the URL expander.
  9. Send one test to a real handset per carrier and read it as a stranger would.
  10. Log what you registered and when: headers, templates, whitelisted URLs, campaign ids.
  11. Watch the first hour of clicks. Scanner hits with no human clicks usually means delivery failed, not that the offer failed.

For bulk sends, generate links once from the registered domain with the bulk URL shortener or the shorten endpoint, and tag them with UTM parameters.

Enforcement reality: the penalty is usually an absence

Almost none of these failures arrive as a fine. They arrive as nothing happening, which is why they go undiagnosed for months.

Quadrant plotting legal force against the shape of failure, with the United States and Saudi Arabia in soft wording and undelivered traffic, India in binding wording and undelivered traffic, and the UK, EU, Canada and Australia in binding wording and regulator enforcementTap to enlarge
The US clause is the weakest wording of the six instruments and carries the hardest commercial outcome.

Blocked in India, rejected in the US

India's direction is addressed to access providers, not to you, so the failure looks like a delivery receipt problem or messages that never arrive, with nothing saying a URL caused it. Your aggregator is often the only party who can tell you which part of the template failed. In the US the clean outcome is a documented rejection at registration, before you spend money; the messy one is traffic that passes vetting and is filtered in the wild, where throughput falls with no error you can act on.

The gotcha that catches careful teams

Rotating the destination after approval. Editing where a link points is normal link management, but where the URL was whitelisted or submitted as a sample, a link that now leads somewhere unrelated to the approved campaign is exactly the pattern fraud detection hunts. Keep an approved link pointing at the approved kind of destination and mint a new link for a new offer; if a campaign must stop, link expiration is cleaner than repointing. In the UK, EU, Canada and Australia the same facts land differently: an opaque link on a host with no relationship to the named sender is evidence that identity was concealed.

One convention, and the fallback it cannot cover

There is no single link convention that clears every market, and that is the honest version of this page. The markets that regulate the shape of the link, India above all, can be satisfied by one convention you apply everywhere. The strictest markets do not regulate the shape at all: they ban shortening, and the only thing that clears a ban is not shortening. So build both, a convention plus a long link you can actually send, and decide which markets take which before the campaign calendar is full.

One host per market, one convention everywhere

Use a short subdomain of a domain you already own. Flyn allows three custom domains on a paid plan, which maps onto three markets. Keep the slug convention identical everywhere so reporting stays comparable, and put the brand or header token first so the link reads as yours in a notification preview. Naming tradeoffs: choosing a branded short domain and custom domains and trust.

Passcodes, and the character budget

Treat transactional and passcode messages as the strictest case, not the easiest: they are what fraud imitates, so an opaque host is the worst place to save characters. For payments into India a UPI payment link avoids a redirect entirely. A branded host costs characters and buys delivery, and that trade is not close, so trim the slug instead of the domain; the rest of the character budget and campaign tracking is a separate craft. Build the message with the SMS link generator, keep support replies on a tel link, and if you send from Klaviyo or Brevo, set the registered domain in the platform's link settings so nobody ships a default shortener by accident. Keep one page listing, per market, the host, the convention, what you whitelisted, the date and who approved it, because most of the pain here is that the person who registered the domain has left. Small teams can park it beside the campaign calendar, see the small business workflow.

The fallback, and when it is the only option

Keep the full destination in the campaign brief next to the short one, and keep it sendable: a clean path on your own domain, no tracking tail, nothing that depends on a redirect. Where Twilio's guidelines say shortened URLs are prohibited and message URLs must be allowlisted first, as in Saudi Arabia, that long link is the only version you can send, and the allowlisting happens before the send rather than after the first failure. The same fallback covers any aggregator whose policy is stricter than its market's law, which is most of them. On that branch you give up click attribution, because there is no redirect to measure; choose that in advance rather than discovering it when a market goes quiet.

This page is general information, not legal advice. Rules change, national implementations differ, and your aggregator's policy may be stricter than anything quoted here. Confirm your obligations with a qualified adviser and with your carrier or access provider before you send.

Frequently Asked Questions

Is bit.ly allowed in SMS?
It depends on the market, and in the two biggest ones the practical answer is no. India's whitelisting direction says senders shall not use a URL shortening service unless the shortened URL clearly indicates a relation with the sender, which a random bit.ly code does not. In the United States no statute bans it, but CTIA asks senders to use a shortener dedicated to their exclusive use, and Twilio documents a toll free verification rejection specifically for public URL shorteners, so a sample message containing one is usually refused at registration. In Saudi Arabia the answer is no for every shortener, branded or not: Twilio's country guidelines say shortened URLs are prohibited and that URLs in the message content must first be allowlisted. Elsewhere no rule names shorteners, yet an opaque host supports a finding that the sender was concealed.
Do passcode and transactional messages need URL whitelisting in India?
Whitelisting under the TRAI direction applies to URLs, APK links, OTT links and call back numbers appearing in message content, and access providers had to stop permitting non whitelisted URLs from 1 October 2024. The direction is not written as a marketing only rule, so the safe operating assumption for any commercial SMS carrying a link, including transactional and passcode messages, is that the URL must be registered first. Your aggregator is the authority on what your templates need, because they hold the DLT relationship. Do not discover this on a passcode flow in production.
Does the Indian rule apply if my company is not in India?
The obligation runs to access providers, the Indian telecom operators, and it concerns the traffic they carry rather than where the brand is incorporated. Any sender reaching Indian handsets through Indian operators is inside the regime regardless of headquarters, because the operator is the party that must not permit a non whitelisted URL. You enter that regime through a principal entity registration on the DLT platform and through your aggregator. Being a foreign company does not exempt the link; it usually means your aggregator handles registration and passes the requirement to you.
What does CTIA mean by a shortener dedicated to my exclusive use?
Section 5.3.2 of the May 2023 Messaging Principles and Best Practices asks senders to use a shortener with a web address and IP addresses dedicated to the exclusive use of the message sender. The web address half is easy: a custom domain only you use. The IP address half is harder, because most hosted shortening services serve many customers from shared infrastructure, so treat it as a question for your provider. No shortener should tell you it makes you CTIA compliant, because the document says should throughout and compliance is judged on your whole programme.
Will a branded short domain on its own stop carrier filtering?
No. A branded host removes one of the strongest negative signals, a shared shortener, but filtering also weighs sender reputation, content, the consent record, the registration status of the campaign and the traffic pattern. A brand new domain has no reputation at all, which is why it pays to warm one host and keep it rather than rotating. The reverse holds too: a perfect domain attached to an unregistered 10DLC campaign still gets filtered. Fix the registration and the host together, and expect a few days before a fresh host settles.
Can I use one short domain for every country?
Technically yes, and many teams do. The reasons to split are blast radius and registration. If one market flags the host, every market on it suffers, and India's whitelisting is per URL pattern, so a single global host still needs an entry per sender header. A common middle ground is one host for India because of the header in path requirement, one for North America where carrier reputation binds, and one for everywhere else. Whatever you choose, write the convention down, because the failure mode is a later campaign quietly using a different host.
Does a QR code on a poster fall under these rules?
No. Every rule in this post is triggered by sending a commercial electronic message to a recipient, so a code printed on a poster, a menu or a package sits outside them. The destination still has to be honest about who owns it, and advertising and consumer protection rules still apply to what the landing page says, but there is no whitelisting, no carrier filter and no sender identification duty attached to a static print code. Text that same link to a list and both rulebooks apply again.
What about WhatsApp, RCS and other app channels?
They are governed by the platform's own policies rather than the SMS rulebook, and those policies are usually stricter about link behaviour than any regulator. WhatsApp Business messaging runs on approved templates with its own review, and RCS traffic is carried by the same carriers that filter SMS, so the dedicated host argument carries straight over. The identity duties in PECR, ePrivacy, CASL and the Spam Act are written around commercial electronic messages rather than a technology, so assume sender identification follows you onto app channels even where the shortener guidance does not.

Ready to try Flyn?

Free plan includes 25 links/month, full analytics, and access to all 30+ free tools above. No credit card required.

Already a member? Log in

Karan Bhakuni
Karan Bhakuni· Founder, Flyn

Karan Bhakuni is the founder of Flyn. He writes about branded links, click analytics, and the link-management tooling growth teams and creators actually need, drawn from building Flyn and reading a lot of user feedback.

Find these guides useful? Add Flyn as a preferred source so more of them show up in your Google results.