I do tech for an email security service and we start blocking these very quickly once we see any anything we don't like.
I do tech for an email security service and we start blocking these very quickly once we see any anything we don't like.
The way I counter this is by not allowing people people to create generic links in the first place unless you are a paid customer. Plus, you need to add your custom domain to do something meaningful on the platform.
That pretty much weeds out 100% of scammers.
So what we find is that as new ones come into the market they are eagerly adopted and we start to see evil links. From our point of view the earlier we put in place a wholesale block the better, because otherwise they may become "too big to block" like bit.ly etc... Although even these are blocked by gmail from time to time (for example).
Instead we expand them later and visit and scan them after the fact. But at that point the email is often already delivered.
But bottom line url shorteners are so abused as to be a de facto sign of spam.