Skip to main content
How-to

Android deep link security checks for production App Links

Teams often test whether deep links open, but miss whether routing is secure. Use this guide to harden Android App Links against host mismatch, route hijacking, and redirect-side attribution loss.

Security controls to enforce before launch

ControlPassing signalRisk if skipped
Verified App Links onlyRoutes use `https` + verified host with Digital Asset Links configured and reachable.Unverified hosts allow chooser flows or competing handlers to intercept traffic.
Intent-filter minimizationIntent filters only include required hosts/paths for production routes.Broad wildcards expose unintended routes and increase hijack surface.
Redirect and fallback controlRedirect chain is bounded, deterministic, and preserves UTM/query parameters.Open redirects can drop attribution or route users to attacker-controlled pages.
Installed vs non-installed QAInstalled app opens expected screen; non-installed users land on approved fallback.Security checks pass in one state but fail in another, causing inconsistent routing.

Quick validation sequence

  1. Confirm each production host publishes valid `assetlinks.json` entries for release package signatures.
  2. Run `adb shell pm get-app-links` and verify host state on target Android versions.
  3. Open representative campaign links on installed and non-installed devices.
  4. Inspect final URL and parameters to detect dropped attribution keys after redirects.

Related help articles