Blog

What AT&T, T-Mobile, and Verizon Actually Say About Link Trackers

Hannah Carlson

3 MIN READ

What AT&T, T-Mobile, and Verizon Actually Say About Link Trackers

Every major U.S. carrier polices shortened and tracked links, but not identically, and the gaps between their public codes of conduct are exactly where a compliant-looking program can still get filtered. T-Mobile publishes the most explicit language of the three. AT&T publishes similar language but enforces it more strictly in practice. Verizon publishes the least public detail, which makes treating it as more lenient the riskier assumption, not the safer one. Here's what each carrier's own policy actually says, and what a program built to clear all three looks like.

T-Mobile

If your business texts T-Mobile subscribers, the carrier's Code of Conduct directly determines whether your links get delivered. T-Mobile has published some of the clearest language in the industry on URL shorteners and link trackers, unlike carriers that lean on general, shared filtering infrastructure with little public detail, T-Mobile puts its expectations in writing.

What T-Mobile's Code of Conduct says

T-Mobile's Code of Conduct for Messaging discourages public URL shorteners outright: "the practice of using public URL shorteners in bulk messaging is highly discouraged, and messages containing them may be subject to blocking." That covers bit.ly, tinyurl.com, and similar shared domains, all of which route traffic through infrastructure shared by thousands of unrelated senders.

Two specific tactics draw extra scrutiny:

  • Shortener cycling. Using multiple public shorteners or domains for similar content is prohibited when done to evade filters or dilute reputation metrics.

  • Redirect chains. Links that bounce through more than one redirect are a red flag serious enough that the code of conduct warns it "may result in immediate suspension of services."

What T-Mobile recommends instead

T-Mobile's guidance: "each program should be associated with a single business's web domain." A full, unshortened domain is preferred, but "a branded short URL may be used to deliver custom links."

In practice, the difference between bit.ly/x7Y2z and links.yourbrand.com/x7Y2z isn't cosmetic. One is anonymous shared infrastructure; the other is a domain T-Mobile can associate specifically with your sending history and score accordingly.

What actually happens when a message gets blocked

"May be subject to blocking" can read as a minor inconvenience until you've seen it at scale. A blocked message doesn't bounce back with a clear error the way a failed email might. It can be silently dropped or delayed, showing up only as an unusually low delivery or click rate across an entire campaign, with no single message flagged as the cause.

That makes the problem easy to misattribute to weak creative or bad targeting, when the real cause is a link structure T-Mobile's filters were never going to let through.

Common mistakes that trigger T-Mobile's filters

  • Default inertia. Using whatever shortening domain a messaging platform defaults to, without realizing it's shared, multi-tenant infrastructure.

  • Redirect creep. Links passed through an analytics tool, then a CRM, then a landing page, each hop adding a redirect.

  • Inconsistency. Switching between shortening services over time as marketing tools change.

What compliant T-Mobile traffic looks like

  • One consistent domain across all campaigns

  • Links that resolve directly, no intermediate redirects

  • A domain that's either your full primary domain or a clearly branded subdomain (text.yourbrand.com)

AT&T

Of the major U.S. carriers, AT&T runs the tightest filtering on shortened and tracked links. AT&T is one of the largest carriers in the country, so a meaningful share of almost any text list includes AT&T subscribers, this isn't an edge case to design around later.

What AT&T's Code of Conduct states

AT&T's official Code of Conduct for Short Code and 10-Digit A2P SMS Messages states:

  • "The practice of using public URL shorteners in bulk messaging is highly discouraged, and messages containing them may be subject to blocking."

  • Multiple public shorteners used to evade filters or dilute reputation metrics are separately prohibited.

  • Any link's destination must "unambiguously identify the website owner," including a real postal address and published privacy policy.

In practice, AT&T goes further than "discouraged"

Businesses working directly with AT&T traffic consistently report that the carrier won't allow any traffic using a link-shortener structure, even a proprietary, single-tenant shortener a company built and controls exclusively.

Where T-Mobile's code of conduct carves out room for a "branded short URL," AT&T's enforcement in practice treats any shortened link format, branded or not, as a risk factor. The safest read: the format itself is what triggers scrutiny, not just the domain's reputation.

What to use instead

A full, direct, branded domain with no shortening layer at all, something like go.yourbrand.com/promo-fall. This also solves the redirect-chain problem: a direct link with no intermediate hop has nothing to redirect through.

A concrete before-and-after

Risky

"Flash sale ends tonight! Shop now: bit.ly/3xK9z2"

Compliant

"Flash sale ends tonight! Shop now: shop.yourbrand.com/flash"

Both fit comfortably within SMS character limits. Only the second is built to reliably clear AT&T's filters, and it's also the version more likely to convert once it does.

Why AT&T's line is stricter than the rest

The network carries an enormous volume of A2P traffic, and shortened links are disproportionately represented in the phishing attempts its filters are built to catch. Rather than try to distinguish a legitimate proprietary shortener from a malicious one at the format level, a genuinely difficult filtering problem, AT&T's practical approach treats the format itself as the risk signal.

The feedback loop AT&T relies on

AT&T's filtering isn't purely automated. Subscribers can forward unwanted texts to 7726 (SPAM), and those reports shape how aggressively AT&T's systems treat similar messages going forward. A direct, fully branded domain gives recipients less reason to report your message in the first place.

What compliant AT&T traffic looks like

  • One full, direct domain across all campaigns

  • No shortening layer, proprietary or otherwise

  • A single hop, no intermediate redirects

  • A landing page that clearly identifies the business

This build tends to perform well across every carrier, not just AT&T, since a fully direct branded link satisfies the stricter standard and the more permissive ones at the same time.

Verizon

Verizon is less publicly prescriptive than AT&T or T-Mobile about link shorteners, but that doesn't mean its filtering is any more forgiving. It's easy to assume a carrier without a detailed public policy is more lenient by default. In practice, the opposite assumption is safer: less written guidance means less certainty about exactly where the line sits.

The framework Verizon operates under

Verizon is a CTIA member and applies A2P 10DLC standards in line with the CTIA's Messaging Principles, the same baseline AT&T and T-Mobile reference in their own codes of conduct. That requires any URL shortener to have "a web address and IP address(es) dedicated to the exclusive use of the Message Sender."

Verizon relies on the same shared, third-party filtering infrastructure used industry-wide to score A2P traffic in real time, so links on public, multi-tenant shortening domains face the same category of scrutiny as on any other major carrier.

What Verizon tells its own customers about suspicious links

Verizon's consumer guidance on smishing mirrors what its filtering systems are built to catch:

  • "A suspicious link" in a text is called out as "a huge warning sign."

  • Legitimate messages typically come from "a 10 digit number or a 5 to 6 digit short code."

  • Recipients are told not to click links or follow prompts from unfamiliar messages.

A link on a shared domain used by unrelated senders, some of them phishing operations, can't offer the identifiable sending identity Verizon's own guidance describes as the marker of a legitimate message.

What this means for marketers sending to Verizon subscribers

Without a carrier-specific carve-out like T-Mobile's "branded short URL," the safest approach mirrors the strictest standard across every carrier: a domain your business owns exclusively, used directly rather than through any shortening layer.

This also happens to be the format that performs best: branded, recognizable links see a 34–39% CTR lift over generic shortened ones (Messageflow, 2026).

What a Verizon-safe program looks like

  • A single domain your business owns and uses exclusively

  • Links that resolve directly, no redirect chains

  • A landing page that clearly identifies your business

Programs already built to satisfy AT&T's stricter enforcement will, in effect, already meet Verizon's bar too, one more reason a single, consistent domain strategy across all three carriers tends to be more reliable than a carrier-by-carrier patchwork.

Testing your program before a Verizon-heavy send

Because Verizon hasn't published a granular link policy, it's worth testing rather than assuming. Send a small batch to a controlled group of Verizon numbers and watch delivery and click data closely. A meaningful gap on Verizon traffic specifically is usually a sign a link or domain choice is triggering extra scrutiny.

Does this apply across 10DLC, short codes, and toll-free numbers?

Yes, across all three carriers. The link and domain guidance isn't specific to any one sending vehicle, it's a general content standard that applies to 10-digit long codes, short codes, and toll-free numbers alike. Choosing the right vehicle for your volume is a separate decision from getting your link strategy right. [moved here from the original T-Mobile post, since it's a general point rather than a T-Mobile-specific one]

Getting compliant across every carrier without an engineering project

Entri Activate is one integration to Connect, Sell, and Monitor domains.

  • Connect automates the DNS configuration into a one-click setup, so a branded, compliant domain can go live without a ticket to engineering.

  • Sell lets customers without a domain purchase one in-platform, so the whole process happens in one flow.

  • Monitor checks every customer domain you care about. Catch churn signals, broken pages, and deliverability issues before your customers do.

The Entri Unify call entri.showUnify(config) presents a centralized modal where the user chooses to buy a new domain or connect an existing one, then routes them through the right Entri flow automatically. When that flow completes, the domain goes from purchased or owned to fully functional inside your platform and your users can start sending sooner. Together, every customer gets an individualized, carrier-compliant sending identity without you building domain infrastructure from scratch, whether they're sending to AT&T, T-Mobile, Verizon, or all three.

LEARN MORE

One integration. Both flows. Higher activation and new revenue.

Bring your product. We’ll show you the unified Entri flow on your real activation step in 30 minutes.

LEARN MORE

One integration. Both flows. Higher activation and new revenue.

Bring your product. We’ll show you the unified Entri flow on your real activation step in 30 minutes.