Policy
Abuse and Takedown Policy
zip1.io is a free URL shortener, and free shorteners attract phishing. This page states exactly what we remove, how to tell us about a link, and how long we take. Report anything at zip1.io/report — no account, no sign-in.
- 2 business days
- No account needed
- Deleted, not blocked
- Swept monthly
How to report a link
Use the report form. It needs the short link and a reason; everything else is optional. The report goes straight to an on-call channel, not to a mailbox.
A report is faster to action if it includes:
- The zip1.io short link — the full URL or just the code after the slash.
- What the destination does, if you have seen it. "Fake Microsoft 365 login" beats "phishing".
- Anything third-party that already classifies it — a Google Safe Browsing verdict, a VirusTotal link, your own blocklist entry.
We do not need your name or your reason for looking. Reports are read the same way whether they come from a victim, a security vendor, a hosting provider or a competitor.
Blocklist operators, hosting and registrar abuse teams, and law enforcement: the report form is the fastest path for a specific link. For anything broader — a pattern across many links, or a request that needs a written reply — use the contact form. Machine-readable contact details are published at /.well-known/security.txt.
@zip1.io address is not delivered. The two forms are the whole intake.
How fast we act
| Step | Target |
|---|---|
| A report is read and investigated | Within 2 business days |
| Confirmed phishing or malware is removed | Same day we confirm it |
| Proactive sweep of the whole collection | Monthly |
Two business days is what we can hold to, not what we aim for — most reports are handled the day they arrive. We publish the number we can meet rather than the one that sounds better.
We do not send a case number or a status email, because there is no mailbox to send it from. If you need a reply, say so in the contact form and leave an address.
What we remove
A short link is removed when its destination is any of the following. This is the working list our scanner and blocklist are built from, not a legal summary.
- Phishing and credential theft — fake sign-in pages, payment-detail harvesting, fake delivery and invoice lures, account-takeover flows.
- Malware — anything that serves or drops executable content, including drive-by downloads.
- Piracy indexes and file lockers — curated warez link lists and the one-click hosters they run on.
- Redirect chains — links pointing at another URL shortener, or at a channel whose contents can be swapped after we check them. If we cannot see the real destination, we do not carry the link.
- Impersonation — a brand's name used to make a destination look like that brand's own site.
- Pornographic hosts — a policy choice, not a legal one. zip1.io is not the right tool for this and the traffic is not worth the reputation cost.
- Harassment, threats and non-consensual imagery.
- Bulk spam campaigns — many links minted from many addresses onto one destination in a short window.
Removal means the link document is deleted. The short link stops resolving, and its code is reserved so the same name cannot be registered again — otherwise an operator can re-point a burned code and keep the audience they already built.
What we will not do
Saying what we refuse is part of being predictable to work with.
- We cannot change the destination site. We control a redirect, nothing else. If the content itself needs to come down, report it to the destination's host or registrar — removing our link only removes one route to it.
- We do not remove a link on click volume alone. A popular link is a popular link. Traffic measures reach, not intent, and treating volume as evidence is how a legitimate customer gets deleted.
- We do not remove links we merely dislike. Lawful content stays up, including content that is commercial, political, or unflattering to someone.
- We do not act on an unverifiable claim of ownership. Anyone can shorten a public URL. If someone else's short link points at your site and you want it gone, tell us on the contact form and we will look — but "I own the destination" is not by itself grounds for removal.
If we removed something we should not have, say so on the contact form. We keep a restorable snapshot of every removal, so putting a link back is a real option rather than a polite phrase.
What we do without being asked
Reports are the last line, not the first. Three checks run before a link is ever created, on every route into the service — the web form, the emoji form, the API and the MCP tool:
- A blocklist of destination patterns learned from campaigns we have already cleaned up.
- A fan-out limit that counts distinct submitters per destination domain per hour. This is what catches a campaign nobody has classified yet, because it reads the shape of the traffic rather than the text of the URL.
- Google Safe Browsing, checked at submission. It is a lagging indicator, so we treat it as a floor rather than a defence.
On top of that, the whole collection is swept monthly for clusters the per-link checks cannot see, and everything found is deleted rather than merely blocked. The runbook we follow is public: docs/ABUSE.md.
FAQ
-
How long until you act on my report?
We investigate within two business days. Confirmed phishing or malware is deleted the same day we confirm it. Most reports are handled faster than the stated target; two days is the number we will not miss.
-
Do I need an account to report a link?
No. The report form takes a short code and a reason, and that is all. There is no sign-in on zip1.io at all.
-
I run a blocklist or a hosting abuse desk. Who do I talk to?
The same two forms, and /.well-known/security.txt for the machine-readable version. Use /report for a specific link and /contact for anything that needs a written reply. Mail to
@zip1.iodoes not reach us — the domain has no mail server. -
The link is already dead. Is it still worth reporting?
Yes, if it still resolves from our side. The report form rejects codes that no longer exist, so a rejection tells you it is already gone. A destination that is offline but whose short link still redirects is worth reporting — the destination can come back.
-
Someone shortened a link to my site. Can you remove it?
Tell us on the contact form and we will look at it. Shortening a public URL is not abuse on its own, so we weigh what the link is being used for rather than who owns the destination.
-
Can I get a removed link restored?
Ask on the contact form. Every removal writes a verified snapshot of the deleted records before anything is deleted, so a restore is a real operation and not a best-effort one.
Related
Found an abusive zip1.io link?
Report it now. No account, and we read every one.