SSL click tracking directs your branded links to open over HTTPS instead of HTTP. This means when recipients open links from your marketing emails, your email provider temporarily routes the click through its own servers before redirecting to the destination. Recipients are successfully brought to the intended webpage and will not receive any browser security warnings. This improves deliverability of emails, preventing them from landing in spam folders and builds trust with supporters.
SSL click tracking is only available after you complete link branding. The steps below walk through the entire process including configuring a CDN or proxy for your primary branded link domain, updating your CNAME record, and confirming HTTPS before you contact support to finish setup.
Prerequisites
Before you begin, ensure link branding is already set up and verified in Virtuous CRM+. If you have not completed link branding yet, click here to learn how to complete it.
If your account has more than one branded link domain configured, you must complete SSL click tracking setup for all of them. Virtuous Marketing is powered by SendGrid which enables SSL click tracking at the sub-account level. So each link domain must have its own SSL click tracking configuration.
Note: After link branding is verified, do not click the Verify button again. It is critical that you do not re-verify after completing Step 1, or you may break link branding and need to start the process over.
In addition to completing link branding, make sure you have:
- access to your DNS provider
- access to your CDN or proxy provider, such as Cloudflare, Fastly, KeyCDN, or CloudFront
Step 1: Set Up a CDN or Proxy for the Primary Branded Link URL
Once link branding is verified, the first step is to configure a CDN or reverse proxy to handle HTTPS traffic for your primary branded link URL and forward requests to sendgrid.net. Your CDN must have a valid SSL/TLS certificate for the primary branded link URL, and HTTPS must be active on that domain before SSL click tracking can be enabled.
SendGrid provides setup guides for common CDN providers:
Step 2: Update the Primary CNAME
Once your CDN or proxy is configured, update the CNAME for your primary branded link URL so it points to your CDN instead of sendgrid.net.
Only update the primary branded link CNAME. The secondary branded link CNAME must stay pointed to sendgrid.net at all times.
Step 3: Confirm HTTPS Is Working
After updating the primary CNAME, confirm that HTTPS is working on your primary branded link URL. If HTTPS is not active yet, your SSL certificate may still be provisioning or your CDN TLS settings may need attention.
To confirm HTTPS is set up, you can plug the primary CNAME into your browser with the https;// prefix.
- If it renders a security warning like "Your connection is not private" , "Potential Security Risk Ahead." ,or errors like NET::ERR_CERT_INVALID, ERR_CERT_DATE_INVALID, or SEC_ERROR_UNKNOWN_ISSUER, then the HTTPS setup is not working.
Note: An error like 404 is expected and does not indicate anything related to the security status
- If no security warnings or certificate errors appear on the page, click the padlock or tune icon in the address bar of your browser. Here, confirm that the certificate is valid and connection secure.
Some CDN providers handle certificates automatically, but setup varies by provider. For example, the helper notes that Cloudflare should have proxying enabled and SSL/TLS mode set to Full, while other providers may require you to confirm certificate coverage and forwarding settings.
Step 4: Contact Virtuous Support to Complete Setup
Once you’ve completed the previous steps, open a support ticket to let our team know you are ready to have SSL click tracking enabled. Make sure:
- Link branding is verified in Virtuous CRM+.
- The primary branded link URL points to your CDN or proxy, not directly to sendgrid.net.
- HTTPS works on the primary branded link URL.
- The secondary branded link URL still points to sendgrid.net.
Once those steps are complete, email support@virtuous.org to open a support ticket to let our team know you are ready to have SSL click tracking enabled.
Troubleshooting Common Issues
Link branding is not verified
If link branding is not verified, you must finish that first before working on SSL click tracking. If you point the primary CNAME record to a CDN too early, you can prevent verification from completing.
The primary branded link URL still points to SendGrid
If the primary branded link URL still points directly to sendgrid.net, a CDN or proxy has not been fully set up yet. Configure the CDN first, then update the primary CNAME.
The secondary branded link URL was changed
If the secondary branded link URL no longer points to sendgrid.net, update it back. Only the primary branded link URL should be changed during SSL click tracking setup.
DNS changes have not propagated yet
After adding or updating DNS records, propagation can take anywhere from a few minutes to 48 hours. If a recent change does not appear right away, wait and check again later.