links sent via square marketing emails are flagged as not private

When we send marketing emails via Square, the links we include are transformed with Square tracking after we tell Square to send.:

i.e.:  www.sabatinis.com/bottleshop 

becomes

https://zpzl839y.r.us-west-2.awstrack.me/L0/https:%2F%2Fsqclick.com%2Foutreach%2Ft%2FjfYvbkhNvVuo%2F...

 

The issue is Safari and Chrome flag these transformed links as

"Your connection is not private
Attackers might be trying to steal your information from zpzl839y.r.us-west-2.awstrack.me (for example, passwords, messages, or credit cards). "

It is possible that spam filters and other malware prevention tools may flag these emails.  Not the experience we want for our customers.

1,753 Views
Message 1 of 11
Report
10 REPLIES 10

I am experiencing the same issue. I have chatted with support and they had no real solutions for me. We spend hours each week creating email marketing campaigns and it is frustrating that the links are not working for our customers. Does anyone have a solution?

 

1,731 Views
Message 2 of 11
Report

We are having the exact same issue as well. 

1,699 Views
Message 3 of 11
Report
Square Champion

@timelord 

I saw the issue you're having with the 'Connection not private' warnings on your Square marketing links.

What’s happening is that Square is wrapping your links in a tracking URL ($awstrack.me$), and browsers like Safari and Chrome are flagging it because of a security certificate mismatch or a 'reputation' issue with that specific tracking domain.

Normally there should be an option to turn of tracking but I do not see that, I would try to avoid 'Hidden' Links: Instead of hyperlinking text like 'Click Here,' try writing out the full URL or using a clear button. Sometimes that helps bypass the filter. The button approach might be better visually as well

1,712 Views
Message 4 of 11
Report

Have tried hyperlinks, buttons, embedded items...all links are getting this same error. 

1,699 Views
Message 5 of 11
Report

I have tried using buttons and the same error happens. 

1,682 Views
Message 6 of 11
Report

I had not gotten this before, but with my most recent email my anti-virus is flagging all my links in the email. Is there no way to just turn off the tracking urls created by square? I don't want customers thinking we are sending them infected emails This is one of the links created:  https://zpzl839y.r.us-west-2.awstrack.me/L0/https:%2F%2Fsqclick.com%2Foutreach%2Ft%2FA6qxH7N6rTQA%2F...

1,622 Views
Message 7 of 11
Report
Alumni

Hi all @timelord @RedHill @throughtheriver @Loamibathandbod @mitin 👋

Thank you for reaching out about this question regarding your Square Marketing Email links. I've escalated this directly to the Square Marketing engineers, so they can take a look, and provide more details.

I'll reach back out to you here once I gather more info!

Violet
Community Moderator, Square
Sign in and click Mark as Best Answer if my reply answers your question.



1,477 Views
Message 8 of 11
Report

Any updates?  This is still occurring, and our customers are either not getting the emails due to their spam filters or are concerned that when they click a link in our email, their malware defenses are flagging it.  Can we an option to not have Square wrap our links with this tracking?  At this point, this negates the email marketing feature's value we are paying for.

966 Views
Message 9 of 11
Report
Square Champion

Hi @timelord 

This issue is strictly on the square side, not on your platform or website, Its something Square would need to fix

What’s actually causing the warning

1. Square rewrites links through tracking + redirect domains

Square Marketing uses:

  • AWS tracking domains (*.awstrack.me)

  • Their own redirect layer (sqclick.com)

Safari and Chrome don’t just check SSL anymore — they check:

  • Redirect chains

  • Domain reputation

  • Known tracking infrastructure

  • Link obfuscation patterns

Long redirect chains + URL encoding = phishing-like pattern
Browsers flag it even if SSL is technically valid.


2. Why it shows “Your connection is not private”

That warning can mean:

  • Invalid or mismatched certificate OR

  • Browser distrust of the redirect domain OR

  • Tracking domain recently flagged or reputation-degraded

Square’s tracking domain is being flagged, not your website.

@_Violet This should be escalated within Square, I am sure its affecting many people, at the minimum it should allow the customers no disable tracking withing their configuration to avoid such flags

 

893 Views
Message 10 of 11
Report
Alumni

Hi all @timelord @RedHill @throughtheriver @Loamibathandbod @mitin - I appreciate your patience here.

When I replied on 1/29, I mentioned that I escalated this directly to the Square Marketing Engineers. They've let me know that they have stabilized the issue and are investigating the root cause.

@timelord I see this doesn't seem to be the case for you though 😞 I've just reached out to them again to let them know. I'll follow up with you all again, once I have another update to share.

Again, I thoroughly appreciate your patience 🙏

Violet
Community Moderator, Square
Sign in and click Mark as Best Answer if my reply answers your question.



750 Views
Message 11 of 11
Report