Guide

How it works

A quick guide to createlink.link — everything you need to get started.

What createlink.link is

It is a platform for personal short links: you create a separate link for every recipient, send them out — and see who opened the email, who clicked and how much it earned.

The key difference from ordinary shorteners: clicks are served not by our server but by yours. Your domain, your VPS with the agent, your Cloudflare account — the platform only orchestrates it and collects the stats. That way the reputation of your traffic belongs to you and never depends on neighbours in a shared service.

How it is set up — six links in the chain

From a Cloudflare token to a working funnel. Each link is configured once.

01

Cloudflare connected via API

Add the API token of your free Cloudflare account — the platform creates the zone, DNS records and HTTPS for every domain of yours.

There is no need to configure each domain by hand. Generate a token in your Cloudflare profile once and add it in the cabinet: from there the system creates the zone, points a proxied A record at your server IP and turns TLS on.

Zones are created in YOUR Cloudflare account, not ours — so your infrastructure never depends on other users of the platform. The token needs three permissions: Zone · Edit, DNS · Edit and Zone Settings · Edit.

What to do

Settings → the “Your Cloudflare” block: paste the token and run the check.

02

The agent on your own VPS

Your own clean VPS (we recommend Contabo) runs an isolated Docker agent that handles the clicks. Your server, your IP.

The agent is a small container: it takes the click, checks the visitor and sends them where intended, while the decision itself comes from the platform. Your infrastructure stays entirely separate from other users — your server, your IP address, your domains.

Today the agent is installed following our instruction (PDF, three languages) — a few commands you can paste even into your host's web console, with no SSH client. One-line automatic installation is in the works and will appear in the cabinet.

What to do

Settings → “Agent access key”: the ready-made config and the PDF instruction in three languages are right there.

03

Domain checks and rotation

Add your domains (three or more works best). The platform checks their reputation and rotates them for you during bulk link generation.

Every domain is checked against security registries — 8 DNSBL lists, Google Safe Browsing, VirusTotal and AbuseIPDB — and is then re-checked automatically every 6 hours. Ownership is confirmed with a DNS record.

Once confirmed, domains join the rotation: links from one batch are spread evenly across your domains, so neither the load nor the filters' attention piles up on a single name. If a domain ever gets blacklisted, the system removes its shield and takes it out of rotation on its own.

What to do

Settings → add the domain, confirm ownership with a DNS record and connect the shield.

04

One-time links: three clicks

Every link is personal and lives for exactly three clicks by real people. Bots are sent to a neutral page by the built-in Anti-Bot filter.

A link is created for one specific recipient. Scanners of mail services and messengers may hit it as often as they like — they get a neutral safe page, and those hits do not consume the clicks.

The link accepts three live clicks and then closes itself. The filter works on request signals — User-Agent and language headers — which cuts mass scanners well, but is not absolute protection.

What to do

Nothing to configure: the three-click limit and the Anti-Bot filter work from the start.

05

Bulk link generation

One target URL, and the system returns an array of personal links: up to 25,000 at a time, spread evenly across your domains, with CSV export.

A large mailing needs a separate address for every recipient. Put your target URL in the Links section — it is screened against threat databases (Google Safe Browsing, VirusTotal, PhishTank) right away, and only a clean result lets you set the amount. From there the platform generates the batch in seconds, distributing it across all your connected domains.

Up to 25,000 links are created per run; larger volumes go in several batches. The finished list is exported as a single-column CSV so you can load it straight into your mailing software.

What to do

Links → paste the destination and wait for the screening ticks, create the link, set how many personal codes you need and download the CSV.

06

Campaign analytics

A three-stage funnel: the email open, the click by a live person and the conversion — with affiliate revenue next to it via S2S postback.

The funnel shows three consecutive stages: the email open (via pixel), the click by a live person and the conversion from your affiliate network — all for the same period, so they can be compared with each other.

Separately you see countries on the map, browsers and device types, as well as humans versus bots. The network postback arrives on your own domain and ties the payout to a specific link — so revenue sits next to traffic in your stats.

What to do

Stats → pick a period. Revenue appears once you set our postback address in your affiliate network.

What happens when a recipient clicks

Four steps that take a fraction of a second

  1. 1

    The click goes to your domain and from there, through Cloudflare, to your VPS. The real server address is never exposed.

  2. 2

    The agent on your VPS looks at the request: a live person’s browser or automation. Bots get a neutral page — and that is where it ends for them.

  3. 3

    For a live person the agent asks the platform where this particular code should lead, and redirects. The code’s clicks are counted — three of them, then the link closes.

  4. 4

    The platform records the events: the email open (if the pixel was in the message), the click, and later the conversion from the network postback. Together they form the funnel with revenue.

What you get

The platform’s key features, in brief

Isolated self-hosted infrastructure

Clicks are served by your own server, never a shared one: your VPS, your IP address, your Cloudflare account. Your traffic never mixes with anyone else's, so the reputation of your domain and server depends on you alone.

Real-time Analytics

Every click is broken down by country, device, browser and traffic source. See where and when your target audience arrives, instantly.

S2S Postback synchronisation

End-to-end wiring with affiliate and CPA networks: the network reports the payout to your own domain, and the platform ties it to the exact link. Revenue sits next to traffic, so ROI is counted without exporting anything into spreadsheets.

Domain Reputation Checks

Every domain is checked automatically against dozens of phishing databases (Google Safe Browsing, VirusTotal, DNSBL). Compromised addresses are detected by the system on their own.

Cloudflare Shield Protection

Your server stays safely hidden behind Cloudflare. The real IP address is never exposed, and traffic goes through protected proxies with free SSL encryption on every domain.

Smart Anti-Bot Filter

A built-in system for safe traffic routing. Automated bots, parsers and monitoring systems are quietly sent to a fallback page, while real users get instant access to your content.

Destination screening

Every destination URL is screened against threat databases — Google Safe Browsing, VirusTotal and PhishTank — when the link is created and weekly after that. The reason is simple: your links run on YOUR domain, so phishing or malware on the offer side hits your reputation and your email deliverability first. A destination flagged as dangerous gets no links.

Topic by topic

Longer write-ups on individual parts of the system

Creating a short link

Paste a long URL into the create field and get a short link. It is easy to share in messengers, social media and email campaigns.

Your own domains

Connect your own domain so links are branded (e.g. link.yoursite.com). Manage all your domains from a single panel.

The agent on your VPS

A small Docker container on your own server handles the clicks. You install it from the instruction, and the cabinet picks up its IP and status by itself.

Click analytics

The stats section shows click counts, countries, devices, browsers and traffic sources — in real time.

Protection & checks

Automatic domain spam/reputation checks and bot-traffic protection keep your links clean.

Email campaigns & unique links

Generate unique links for bulk mailings to precisely track each recipient's clicks.

Need help?

If you have a question, contact support right from your dashboard. We are here and constantly improving the service.

Questions

Frequently asked questions

What people ask before connecting

Connecting a VPS

What are the technical requirements for the VPS?

A clean server with Ubuntu 22.04 or 24.04 LTS. The agent is a small container that takes a click and answers with a redirect, so a provider's entry-level plan is plenty: 1–2 vCPU and 2 GB RAM cover ordinary mailings with room to spare. We have not load-tested extreme volumes, so if you plan millions of clicks a day, size the server generously.

Which hosting provider do you recommend?

Contabo: solid servers at a low price and, most importantly, clean IP addresses — which directly affects deliverability. Check the IP against blacklists right after you buy it: if a previous owner tainted it, replacing the server while it is new is the easy fix.

Do you need the password to my VPS?

No. We never ask for it and never store it — access to your server stays with you alone. You install the agent yourself following our instruction (PDF in three languages): a few commands you can paste even into your host's web console, with no SSH client. One-line automatic installation is already in the works and will appear in the cabinet.

Is my server IP checked?

Yes. The check runs against 8 DNSBL lists, Google Safe Browsing, VirusTotal and AbuseIPDB. Today you start it with a button in Settings (an automatic run right after the agent appears is in the works). If the IP is already listed, replacing the server at your provider is easier than restoring its reputation.

Cloudflare and API

Why connect Cloudflare over the API?

So you do not do by hand what takes hours: the platform creates the zone itself, points a proxied DNS record at your agent's IP and turns TLS on. The real server address stays hidden. The zone is created in your own Cloudflare account — you stay in control of it.

Which permissions does the Cloudflare API token need?

Three: Zone · Zone · Edit (create the zone), Zone · DNS · Edit (point the domain at the agent IP) and Zone · Zone Settings · Edit (enable TLS). ⚠️ The ready-made "Edit zone DNS" template is NOT enough: without Zone Settings · Edit, Cloudflare returns error 9109 and the domain serves 521 instead of the page. Under Zone Resources pick Include → All zones from an account. Account · Account Settings · Read is optional — it only lets the cabinet show your account name. We do not ask for access to billing or personal data in Cloudflare.

Is the free Cloudflare plan enough?

Yes, the free plan is enough — there is no need to buy paid Cloudflare subscriptions. Just note that a free account holds about 50 zones: for our scenario (volume in links, not in domains) that is not a constraint.

How the system works

How does the three-click limit work?

A link is created for one specific recipient and accepts three clicks from live people, after which it closes itself. Scanners of mail services and messengers may hit it as often as they like — they get a neutral safe page, and those hits do not consume the clicks. The filter works on request signals (User-Agent, language headers): it cuts mass scanners well, but it is not absolute protection.

How many domains should I connect for large volumes?

Three or more is our recommendation. During bulk generation the platform spreads the batch evenly across all your domains, so neither the load nor the mail filters' attention piles up on a single name. If a domain ever gets blacklisted, the system removes its shield and takes it out of rotation on its own, while the rest keep working.

Is postback from CPA networks supported?

Yes, S2S postback is built in. We stamp your link code into the sub1 parameter on the offer URL, and the network reports the payout to a postback address on your own domain — the platform ties the payout to the exact link and shows revenue next to traffic. We do not ingest ClickIDs from ad systems into the tracker: the platform is built for mailings, not media buying.

Do you screen the destination links I add?

Yes, and without a clean result no link is created. Every destination is checked against domain blocklists (Spamhaus DBL, SURBL) and against Google Safe Browsing, VirusTotal and PhishTank — when you create the link and weekly after that, because affiliate landing pages change without notice. This is not about policing your work: your links run on YOUR domain, so phishing or malware on the offer side hits your reputation and email deliverability first. We never upload the address anywhere — we only read what the databases already know about it.

Ready to start?

Signing up is free, and so are the first 100 links. No card required.

Create an account