codexier.

Mobile Apps

Deep Links and Universal Links Explained

By CodexierPublished 5 min read

When someone taps a link to your product in an email, a text message or an ad, they expect to land on the right screen, in the app if they have it installed. Getting there is less obvious than it sounds. Links pass through click trackers, in-app browsers and operating system rules, and each can send the user to your website instead. This guide explains how deep links work, why they break and what to test.

Testing and maintaining them

  1. Keep a list of every link pattern the app supports and the screen it should open.
  2. Test each on a real iPhone and Android device, with and without the app installed.
  3. Test from Mail, Gmail, SMS, Notes and at least one social app.
  4. Check the verification files after every website deploy; automate it if you can.
  5. Include deep link tests in the release checklist for each app update.

Deep links touch the website, the app and marketing tools at once, which is why they break quietly. We check them as part of app maintenance. When you do not need it: if your app is used only after login and never linked from outside, simple in-app navigation may be enough. If your campaigns keep landing users in the browser, book a free call.

Frequently asked questions

Why does my link open the website even though the app is installed?

Most often the link was rewritten by a click tracker, tapped inside an in-app browser, or the verification file on your domain is missing or wrong. On iOS, the user may also have chosen to open the domain in Safari earlier.

Do we still need a custom URL scheme?

Rarely for links from outside. Verified https links are better for users and security. A custom scheme can still be useful for app-to-app callbacks, for example from payment or login flows.

What replaced Firebase Dynamic Links?

Google recommends using Universal Links and App Links directly, combined with an attribution or deep linking provider if you need deferred deep links and campaign tracking.

Can deep links be a security risk?

Yes, if the app trusts parameters in the link blindly. Validate every parameter, require login for sensitive screens and never perform actions just because a link was opened.

Links not opening your app?

Send us a link that fails. In fifteen minutes we can usually tell you where it breaks and what the fix involves.

Book a free 15-minute call