Skip to main content

branch.io

Nov 10th 2026 01:52 PM

Gandi SAS

unsigned

Yes

Aug 11th 2026 11:48 PM

Branch.io is a domain used for mobile linking and deep linking solutions. It's a well-established domain since 2009, widely used by developers, and has a good reputation, but its DNSSEC status is unsigned, which may pose a security risk.

Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.

Copy Summary
Copy Link
Helpful
Not Helpful
Rarely seen
Vendor

Branch

Category: analytics

Description

Branch is a deep linking and attribution analytics platform for app and website developers. It helps clients understand user journeys across different platforms and devices to improve marketing and product decisions.

AI Review

The Branch.io scripts deployed across their domains focus on deep linking and user attribution, tracking user pathways and conversion metrics. While they aim to enhance user experience by linking web and app interactions, this creates a privacy concern as they may inadvertently monitor user behavior during payment sessions. The integration of callback functions indicates active data collection on user interactions, which, although justified for maintaining seamless experiences, raises significant data minimization questions when executed on PCI-scoped pages, especially around sensitive input fields. Despite no alerts detected in the past week, indicating stable operations, the continued reliance on third-party integration suggests potential risks within the broader supply chain, as any compromise could expose sensitive data collected during payment processes. Organizations should ensure that the vendor’s data collection practices are tightly scoped to avoid capturing sensitive information during payment interactions, and ongoing monitoring is advisable to maintain compliance and protect user privacy.

Script hostnames

branch.io app.link
WHOIS Information
Registrar Gandi SAS
Registration: November 10th, 2011
Expires: November 10th, 2026
Updated: August 11th, 2026
Nameservers
ns-1091.awsdns-08.org. 205.251.196.67
ns-1809.awsdns-34.co.uk. 205.251.199.17
ns-236.awsdns-29.com. 205.251.192.236
ns-991.awsdns-59.net. 205.251.195.223
Meta Tags

No meta tags found.

SSL Certificate
Status:

Enabled

Expires: December 26th, 2026
Issuer:

branch.io is one of thousands of third-party scripts on the web.

Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.

DNS Records
Hostname Type TTL Priority Content
branch.io NS 172800
ns-1091.awsdns-08.org.
branch.io NS 172800
ns-1809.awsdns-34.co.uk.
branch.io NS 172800
ns-236.awsdns-29.com.
branch.io NS 172800
ns-991.awsdns-59.net.
branch.io A 35
65.8.54.3
branch.io A 35
65.8.54.62
branch.io A 35
65.8.54.93
branch.io A 35
65.8.54.107
branch.io AAAA 60
2600:9000:204d:2600:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:6600:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:e600:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:0:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:e00:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:da00:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:7200:e:6c93:2e80:93a1
branch.io AAAA 60
2600:9000:204d:c000:e:6c93:2e80:93a1
branch.io MX 300 1
aspmx.l.google.com.
branch.io MX 300 10
aspmx2.googlemail.com.
branch.io MX 300 10
aspmx3.googlemail.com.
branch.io MX 300 5
alt1.aspmx.l.google.com.
branch.io MX 300 5
alt2.aspmx.l.google.com.
branch.io TXT 300
"adobe-idp-site-verification=2a89b891432143ce2403c051e2ba92b042188556f48ed29a21f58f7a19425836"
branch.io TXT 300
"anthropic-domain-verification-vxgwse=7vzaxsvDZC1tWjjEGU23reiCR"
branch.io TXT 300
"atlassian-domain-verification=cQVPHGxF7xozv8YN7f0YFszavoQXsa4jIyy0YTh1l703iGGjj1aEM+lLVqB198Vn"
branch.io TXT 300
"box-domain-verification=b50bb9d4c71875c10b09cd6e310b592b20353cd15bbbefb4fad5b398c35f6281"
branch.io TXT 300
"bugcrowd-verification=c44172c0849844f8508e7908047a84bf"
branch.io TXT 300
"canva-site-verification=5aT9JJUuponuDnyrDMzOpw"
branch.io TXT 300
"default-domain-verification-s0yes6=0gsTXeTPfvCpLAIu7xxvPeyyr"
branch.io TXT 300
"docker-verification=8e34f3f0-0aa5-4d34-bb94-f54b00bb7e81"
branch.io TXT 300
"docusign=6295a189-1693-4624-bfae-ebdd192e05c1"
branch.io TXT 300
"figma-domain-verification=6b48ca69b772dd85a5eafc93089ccbce085476786d8eaf45e1609b34df675411-1747842463"
branch.io TXT 300
"gc-ai-domain-verification-fyngm9=DmVW9GtGZRxbjMeek7HHZoGyV"
branch.io TXT 300
"google-site-verification=A6Wokcxexs3h8RCPep5ikPj_5Ou35JR9zynIBt4_VOs"
branch.io TXT 300
"google-site-verification=IT9U2rOS45RPU4SahdQirbmjpGxqlIDq2WZX4NDmwSs"
branch.io TXT 300
"google-site-verification=QTcEoV1p6n5Wlr0HAHzEe5RBESSyKsi_fWsLRYGwOPo"
branch.io TXT 300
"google-site-verification=QkSu5Qzm3bnrSyy0MRphM8GB8wL3gbISeqrGOwnV0h8"
branch.io TXT 300
"google-site-verification=VYcubAv9DhS-FXW62xNkvua2iyEN-0SfyyY7xP47Zw4"
branch.io TXT 300
"google-site-verification=ZEAcwPyVJrLK8UiyTfLALfAb3RtGeKMm9GHQf62PROk"
branch.io TXT 300
"google-site-verification=d-LV6kMUE24jvMMrtDY8uzCXNhljPeWP4pho55cHBuE"
branch.io TXT 300
"google-site-verification=mOSvNFm6z5fqbFkSxjQly5TWxPyScSXCEdSXSur_Siw"
branch.io TXT 300
"lyb8vwnk417tpq35llqvmnkt5fhgrvtk"
branch.io TXT 300
"notion-domain-verification=h4Hv4k0X4eQZsSUGQGXLDeJTULRMzfxchQE9lZEv8df"
branch.io TXT 300
"rippling-domain-verification=96f39fac3e0393f3"
branch.io TXT 300
"status-page-domain-verification=l8kq9jjk7nvg"
branch.io TXT 300
"uber-domain-verification=ce94fe1c-f3e0-4dc4-8497-0880cb913fa8"
branch.io TXT 300
"v=spf1 include:_spf.google.com include:mg-spf.greenhouse.io include:stspg-customer.com include:mktomail.com include:spf.tipalti.com include:mail.zendesk.com include:mailgun.org -all"
branch.io TXT 300
"zapier-domain-verification-challenge=6a0cebdf-aee7-44e7-92c4-fe878ab152f3"
branch.io TXT 300
"zapier-domain-verification-challenge=8cf9e29c-60c9-4452-a2db-9a86307fdbe3"
branch.io TXT 300
"zapier-domain-verification-challenge=eaaa362d-2eda-4ada-a189-3b1be7ac34af"
branch.io SOA 900
ns-991.awsdns-59.net. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400
branch.io CAA 300
0 issue "amazon.com"
branch.io CAA 300
0 issue "amazonaws.com"
branch.io CAA 300
0 issue "amazontrust.com"
branch.io CAA 300
0 issue "awstrust.com"
branch.io CAA 300
0 issue "digicert.com"
branch.io CAA 300
0 issue "letsencrypt.org"
branch.io CAA 300
0 issue "pki.goog; cansignhttpexchanges=yes"
branch.io CAA 300
0 issue "ssl.com"

FAQ

Frequently Asked Questions

View all

This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.

The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.

The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.

Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.

Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.

If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.

Subscribe to our newsletter to get the full picture

Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.

Your inbox stays chill, we pop in monthly.

A pixelated, glitchy rendition of the cside shield
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead