Blog · 11 June 2026 · 13 min read
The affiliate clicks filter you can't see — your tracking SaaS might be affected
Affiliate tracking SaaS and nearly all major affiliate networks on CNAME-based custom domains are likely affected when carriers where your audience lives block traffic before the page loads. Attribution will not flag it. There is a way around — I will cover that in another post.
affiliate marketing · attribution · adtech · ISP filtering · tracking
Check your custom tracking domain
Whether you run on affiliate tracking SaaS or an affiliate network, look at the main tracking domain behind your CNAME-based custom domain — the hostname your CNAME points at, not just your branded subdomain. This checker runs your link against three common DNS blocklists — EasyList, DeadEnd, and Pexcn. Carriers in this report are not confirmed to use these exact lists, but the same style of domain blocking shows up on ISP DNS, home-router filters, AdGuard Home, and privacy DNS setups worldwide. Most carrier filtering I document works at the DNS layer — the cheapest option for ISPs to maintain and roll out at scale. Passing every list here does not mean you are in the clear — carriers also run reputation feeds, security DNS, and other ISP-level filtering beyond any public blocklist.
The short version
This is not a browser extension blocking the request. The carrier network decides what loads.
Carriers rarely rely on a single filter. Many start from EasyList or similar blocklists at the DNS layer, then add security DNS, router-level controls, malware and phishing checks, and mobile content locks — all running on the carrier side, not on the user's device. One click can die because the domain is on a list, falls into a blocked category, or scores poorly on reputation — with no extension installed and nothing for the audience to see.
That is why this is so hard to spot: the block happens before your dashboards and in-house QA ever get involved.
- ▸Default carrier filtering is real and widespread. The clearest proof I found covers malware, phishing, and content controls — not products sold as ad blockers. Carriers market these as "security," "safe browsing," "web protection," "content lock," or "family safety."
- ▸The UK is the strongest example. Sky, Virgin Media, TalkTalk, and EE all document network-level filtering on their own sites, and several turn it on automatically or bundle it into standard plans.
- ▸The US matters but is harder to size. Charter says Security Shield is on by default for Advanced WiFi customers. Comcast rolls xFi Advanced Security in on gateway activation and has cited 18 million eligible households.
- ▸Carriers layer several filtering methods. EasyList-style lists are a common DNS baseline. Vendor-backed stacks also show up from Allot, CUJO AI, McAfee, and provider-owned DNS. Marketing talks security, but blocking known ad and tracker domains at the network layer is common in practice.
- ▸Legitimate sites do get blocked. TalkTalk publishes a HomeSafe appeal path. Spectrum has a URL check form. Xfinity offers website reassessment — proof that real domains get caught, not just obvious threats.
Where the filter sits
A click from your audience passes through several steps before a page loads. The carrier they use can block it at DNS or on the home router — long before your team can spot it from the office.
When the filter fires at step 2, steps 3–5 never happen. Server-side postbacks are missing. QA run from your office network — on a different carrier than the audience — sees nothing wrong.
These checks apply to every device on that carrier's network at once — phones, laptops, in-app browsers, TVs, and more — with no extension in sight. Missed clicks are easy to blame on "bad traffic," privacy settings, or noisy analytics when the real cause is upstream.
Where your audience is
How many people may be affected, by market — my best estimate for each country. The UK and US account for most of the reach I could document.
How big is this globally?
Where I could tie a product to a named carrier with public documentation, I estimate between 30M and 95M affected users worldwide. My best single-number estimate is about 60M.
Shaded band = my low-to-high range, 30M–95M. Against DataReportal's 5.56B internet users at the start of 2025, that is roughly 0.5%–1.7% — about 1% at my best estimate. Bundled products with unclear uptake could push the real number higher, but I did not find enough public data to pin down a single figure beyond that.
Each country uses three numbers: a low estimate where filtering is clearly on by default and subscriber counts are published; a best estimate that adjusts for overlap between fixed and mobile, multi-SIM lines, and unclear activation; and a high estimate for the full reach of documented bundled products, capped at that country's internet-user total.
Country-by-country
My estimates for markets where carriers document filtering on their own sites. These are modeled reach figures, not carrier-published subscriber counts. The Data column grades how strong the underlying sources are.
| Country | Carriers found | Filtering type | Default status | Best est. | Low–high | Data |
|---|---|---|---|---|---|---|
| United Kingdom | Sky, Virgin Media, TalkTalk, EE | DNS / category, malware-phishing, mobile content lock | Mixed: auto-on, opt-out, bundled, default lock | 24.0M | 12–40M | B |
| United States | Spectrum, Comcast Xfinity | Managed-router security, malicious-site / phishing | Auto-enabled (Spectrum AWiFi); immediate on xFi gateway | 18.0M | 10–30M | C |
| Czechia | O2 | Network safe-browsing, mobile + home | Bundled as part of tariff, no app | 2.0M | 0.8–4M | C |
| Spain | Movistar | Network malware / phishing, fixed + mobile | Free / eligible, activation required | 1.5M | 1–3M | B |
| Australia | Optus | DNS / reputation home-network security | Included on some plans, auto on compatible modem | 1.0M | 0.4–2M | C |
| Portugal | MEO | Clientless mobile + fixed protection, parental | Bundled / offer, activation required | 0.6M | 0.2–1.2M | C |
| Bulgaria | Yettel | Network-level filtering | Included in some tariffs or paid add-on | 0.4M | 0.1–1M | C |
| Slovakia | O2 | Mobile-network phishing / malware | Opt-in / activation uncertain | 0.3M | 0–0.8M | D |
| Panama | Más Móvil | Network-native cybersecurity, parental | Residential postpaid first phase | 0.15M | 0–0.5M | C |
| Serbia | Yettel | Mobile-network malicious-site blocking | Opt-in | 0.1M | 0–0.3M | D |
| Singapore | Singtel | Malicious-site / phishing / malware / botnet | Add-on, not default | 0.05M | 0–0.2M | D |
- A
- Strong on-the-record proof — carrier documents the product, default status, and filtering behavior clearly.
- B
- Solid public evidence — product page or vendor announcement, with some gaps on uptake or defaults.
- C
- Weaker evidence — bundled, opt-in, or activation and uptake remain unclear.
- D
- Weakest — product exists, but reach and default uptake are very uncertain.
Poland, Brazil, France, Germany, India, and Japan are not listed — I found opt-in-only products or launch announcements, not enough public data to estimate reach.
Carriers I verified
Each row links to a carrier with a public page, press release, or help doc that describes a consumer filtering product or a default restriction.
| Provider | Country | Product | Type | Default status | Vendor / feed | Data |
|---|---|---|---|---|---|---|
| Sky | UK | Broadband Shield | Fixed | Automatically turned on | Provider-managed | A |
| Virgin Media | UK | Essential Security / Web Safe | Fixed | Auto-block unless opt-out | Provider-managed | A |
| TalkTalk | UK | HomeSafe | Fixed | Bundled / standard | TalkTalk DNS | B |
| EE | UK | Content Lock | Mobile | Switched on by default | Provider-managed | A |
| Spectrum | US | Security Shield | Fixed | Auto-enabled (Advanced WiFi) | Not publicly named | B |
| Comcast Xfinity | US | xFi Advanced Security | Fixed | Immediate on gateway activation | CUJO AI | B |
| Movistar | Spain | Conexión Segura | Both | Bundled, activation required | Allot + McAfee | B |
| MEO | Portugal | Net Segura / Casa Segura | Both | Bundled offer, activation required | Allot NetworkSecure / HomeSecure | B |
| O2 | Czechia | O2 Security | Both | Bundled as part of tariff | Allot DNS Secure | B |
| O2 | Slovakia | O2 Security | Mobile | Activation / default unclear | Not publicly named | C |
| Yettel | Bulgaria | Online Protection | Mobile | Tariff-included or add-on | Allot (group) | B |
| Yettel | Serbia | Safe Net | Mobile | Opt-in | Allot (group) | C |
| Optus | Australia | WiFi Secure | Fixed | Standard on some plans | McAfee GTI | B |
| Más Móvil | Panama | NetworkSecure | Both | Launch-stage, default unclear | Allot NetworkSecure | C |
| Singtel | Singapore | Broadband Protect | Fixed | Add-on | Not publicly named | C |
- A
- Strong on-the-record proof — carrier documents the product, default status, and filtering behavior clearly.
- B
- Solid public evidence — product page or vendor announcement, with some gaps on uptake or defaults.
- C
- Weaker evidence — bundled, opt-in, or activation and uptake remain unclear.
- D
- Weakest — product exists, but reach and default uptake are very uncertain.
Across these carriers, filtering usually stacks EasyList-style blocklists with reputation feeds and vendor platforms such as Allot, CUJO AI, and McAfee. Carrier sites rarely spell out which lists they use, but domain-level blocking of ads, trackers, malware, and risky categories is common.
Risk to affiliate tracking
The risk sits at the architecture level, not with any one vendor. It affects affiliate tracking SaaS and nearly all major affiliate networks — hosted click trackers, performance marketing platforms, partner management suites, and network redirect infrastructure all typically route traffic through CNAME-based custom domains, redirect chains, and shared vendor hostnames. In markets I tested, carrier DNS filtering sometimes interrupts that layer. It is not universal across every carrier or market, but the pattern is common enough to affect clicks and attribution whether you buy media in-house or run through a network. Use the blocklist checker above to see whether your tracking domain's CNAME chain appears on EasyList, DeadEnd, or Pexcn.
What you see in the numbers: fewer clicks, landing pages that never load, conversions that undercount, broken post-click attribution, odd gaps by country or network, and ROAS that looks worse than it should. Office-based QA will not reproduce the issue unless you test on the same ISP, router setup, or carrier SIM as your audience. Blaming bad traffic or privacy tools instead of a carrier block is the expensive mistake.
How to actually test for it
The practical test: compare what happens on the audience's carrier network in each target market against a clean network or resolver you trust. Two free tools make that workable at scale.
- ›Compare ISP DNS answers against Quad9, 1.1.1.1, 8.8.8.8, or an internal control resolver.
- ›Test the visible click domain, the landing domain, and the ultimate CNAME target separately.
- ›Watch for broken DNS responses such as NXDOMAIN or SERVFAIL, carrier block pages, silently rewritten answers, or TLS failures on specific networks.
- ›Run synthetic tests with a mobile-carrier SIM and a fixed-broadband ASN in the target market — not just by country label.
- ›Diff raw server logs by country + ASN + resolver path to find drop-offs between click and page view.
- ›Alert on spikes in first-hop failures and sharp deltas between server-side postbacks and browser-side conversions.
Recommendations
- ▸Favor SaaS with client isolation on a dedicated IP for custom tracking domains. That is the setup I have seen offer the best resilience against DNS filtering — you are not sharing click infrastructure with every other client on the platform.
- ▸Monitor domain reachability by audience market, ASN, and carrier DNS. Assume browser-only QA from your own network is insufficient.
- ▸Treat custom tracking domains like core production systems. Avoid risky naming patterns, disposable-looking redirect domains, and long redirect chains.
- ▸Continuously test both the customer-visible subdomain and the CNAME target. If a provider operates at the DNS/reputation layer, either can become the point of failure.
- ▸Keep a clear unblock process with carriers and vendors. TalkTalk, Spectrum, and Xfinity already publish appeal paths — others may too, even when the docs are thin.
You can still push back on false blocks — but only if you test from the same carrier networks your audience uses and treat tracking domains as production-critical.
What I don't know
- ▸Carriers do not publish everything. Many confirm a product exists but not how many customers use it, whether it is on by default, or which blocklists and feeds power it.
- ▸Overlap is hard to untangle. One person may use both home broadband and mobile filtering, and mobile line counts often exceed real users because of work phones, tablets, and multi-SIM plans.
- ▸Block rules are a black box. When a carrier labels something "malicious," "unsafe," "adware," or "phishing," the exact logic is rarely public — you see the block, not the rule that triggered it.
Sources
I kept estimates conservative. Country totals start from DataReportal Digital 2025 internet-user figures. Carrier numbers come from official sites, support pages, filings, and named vendor announcements where available. I treated home and mobile reach as overlapping and capped each country at its total internet-user count.
Primary sources: Charter / Spectrum, Comcast Xfinity, CUJO AI, Sky, Virgin Media, TalkTalk, EE, Telefónica / Movistar, Allot, MEO / Altice Portugal, O2 Czech Republic and Slovakia, Yettel Bulgaria and Serbia, Optus, Más Móvil Panamá, Singtel, RIPE Atlas, OONI, and DataReportal. Full citation list available on request.
Scope covers default or bundled carrier filtering — DNS blocks, domain and URL reputation checks, malware, phishing, and content controls at the network layer. Excludes browser extensions, enterprise-only tools, and government censorship. I carried out this research independently and am not affiliated with any named carrier.
Get in touch
Message me on LinkedIn or Telegram if you want a full tracking audit and a practical path to bulletproofing your click infrastructure when carrier filtering is cutting off users before they reach your landing pages.
No sales team. No agency inbox. One person who owns affiliate and media buying tracking.