Android deep link security checks for production App Links
Teams often test whether deep links open, but miss whether routing is secure. Use this guide to harden Android App Links against host mismatch, route hijacking, and redirect-side attribution loss.
Security controls to enforce before launch
| Control | Passing signal | Risk if skipped |
|---|---|---|
| Verified App Links only | Routes use `https` + verified host with Digital Asset Links configured and reachable. | Unverified hosts allow chooser flows or competing handlers to intercept traffic. |
| Intent-filter minimization | Intent filters only include required hosts/paths for production routes. | Broad wildcards expose unintended routes and increase hijack surface. |
| Redirect and fallback control | Redirect chain is bounded, deterministic, and preserves UTM/query parameters. | Open redirects can drop attribution or route users to attacker-controlled pages. |
| Installed vs non-installed QA | Installed app opens expected screen; non-installed users land on approved fallback. | Security checks pass in one state but fail in another, causing inconsistent routing. |
Quick validation sequence
- Confirm each production host publishes valid `assetlinks.json` entries for release package signatures.
- Run `adb shell pm get-app-links` and verify host state on target Android versions.
- Open representative campaign links on installed and non-installed devices.
- Inspect final URL and parameters to detect dropped attribution keys after redirects.
Related help articles
- Deep Link Inspection Guide - verify route and parameter parity across platforms.
- Deep Link Test Guide - run installed/fallback deep link QA before campaigns go live.
- Universal Links Troubleshooting - diagnose iOS domain association failures in parallel.