Skip to content

SSL click tracking

A Secured Socket Layer (SSL) encrypts a URL with HTTPS instead of the less secure HTTP. Customers at Braze can set up their links and domains to apply SSL certificates. These certificates, similar to SPM and DKIM for email authentication, are insurances that links in your emails are sending your users to reputable locations, and not malicious websites. While not required, SSL certificates are quickly becoming the standard and are strongly recommended to ensure links and images display properly.

How do I get started?

  1. You must reach out to a COM or CSM to initiate a full Braze email setup.
  2. Braze will provide DNS records to add to your domain registry.
  3. Braze will verify if records have been added to your registry correctly.
  4. You will then select a CDN and obtain SSL certificates from a third-party provider.
  5. You will set up your CDN. Note that Braze will not be able to help troubleshoot CDN configuration. Reach out to your CDN provider for help.
  6. Lastly, reach out to your COM or CSM to get SSL turned on.

What is a CDN, and why do I need it?

A Content Delivery Network (CDN) is a platform of servers that help ensure quick load times of high-quality content across multiple mediums while also handling security certificates.

At Braze, to do click and open tracking, our delivery partners transform links using a branded subdomain, and the CDN applies the SSL certificate to those newly transformed links. Often, our delivery partners are required to present valid and trusted certificates to your email recipient’s browser for links and images to display correctly. Because Braze cannot request or manage such certificates, this must be set up on your end through a CDN.

In the following sections, we have outlined and linked out to relevant CDN partner resources to help make this process easy.

CDN resources

The following chart lists step-by-step guides written by Sendgrid and Sparkpost on how to configure certain CDNs. While your specific CDN may not be listed, you must make sure your CDN has the ability to apply SSL certificates.

Sendgrid Step-By-Step Guides Sparkpost Step-By-Step Guides
AWS Cloudfront
AWS Cloudfront
Google Cloud Platform
Microsoft Azure

CDN troubleshooting

While CDN configuration, certificates, and proxy issues should be handled with your selected CDN, we offer some basic troubleshooting tips to identify where your SSL click tracking setup may be failing.

Check for domain registry issues

A dig command can tell you whether you are pointing your link tracking at the CDN. This can be done through the terminal by running dig CNAME link_tracking_subdomain.

Once the command is run, under ANSWER SECTION it should list where your CNAME is pointed to. If it pointed to your chosen email service provider (Sendgrid or Sparkpost) and not your CDN, you must reconfigure your domain registry to point to your CDN.

Check for CDN issues

If your live email links start breaking during setup, this often means you’ve pointed your DNS toward your CDN without it being properly configured. This often comes up as a “Wrong Link” error.

Reach out to your CDN provider and review their documentation to help to troubleshoot your CDN configuration.

Check if SSL is enabled by Braze

If you have completed your SSL setup and are still seeing your links come up as HTTP and not HTTPS, reach out to your Braze COM or CSM and make sure SSL has been enabled by Braze. SSL can only be enabled by Braze once all aspects of your SSL setup have been completed.

New Stuff!