Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TrackBack is a way for one blog to notify another that it has published a related post. It can make cross-site conversations visible, but public TrackBack endpoints can also attract unsolicited links. If you still need TrackBacks for legacy blog interoperability, accept them only with moderation and spam controls; otherwise, turning them off is the simplest way to remove that exposure.

What is a TrackBack?

TrackBack is an open protocol for weblog-to-weblog notifications. Movable Type says it was first released as an open specification in August 2002 and first implemented in Movable Type 2.2. When a blogger writes a post related to another, the sending blog can ping the destination post’s TrackBack endpoint. The receiving blog may then display the referring site and an excerpt, creating a visible map of related writing.

This is a push model: the authoring site initiates the notification rather than waiting for the destination to discover the link. Movable Type’s manual explains: “Using TrackBack, the other weblogger can automatically send a ping to your weblog, indicating that he has written an entry referencing your original post.” Movable Type’s TrackBack beginner guide and TrackBack manual describe the protocol and workflow.

TrackBack versus pingback

Both mechanisms notify a site that another post refers to it, but they differ in how the notification starts and what the receiver checks. WordPress documentation describes the distinction as follows:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Axis TrackBack Pingback
How it starts The author manually enters the destination endpoint and sends a notification. It is generated automatically when a post is published with a link to another site that supports pingbacks.
Content sent An excerpt, title, URL, and blog name. A notification without a content excerpt.
Verification Uses a legacy endpoint workflow with weaker trust assumptions. The destination fetches the source post to verify that the link exists.
Best current use Consider it for legacy interoperability or intentionally curated conversations. Use it only if the platform still supports it and it benefits your workflow; this is a recommendation, not a universal rule.

A WordPress TrackBack URI commonly ends in /trackback/. See WordPress’s explanation of TrackBacks and pingbacks.

Why TrackBack endpoints attract spam

A public endpoint accepts incoming HTTP pings. That openness helped blogging tools exchange notifications, but it also gave spammers a low-friction route to submit unwanted links and excerpts. The paper TrackBack Spam: Abuse and Prevention examines this abuse. The cited sources do not establish a current global figure for TrackBack adoption or spam volume, so a precise percentage or count would be misleading.

How to reduce TrackBack spam without losing useful links

If your readers or publishing partners still rely on TrackBacks, you can keep the feature while preventing unreviewed submissions from appearing publicly. Movable Type documents controls for acceptance, moderation, spam handling, and outgoing pings. Its administrator documentation says TrackBacks can be “moderated, published, deleted and searched.”

  • Moderate incoming pings: hold TrackBacks for review before publication so useful references can be approved and unwanted ones kept off the site.
  • Filter or mark spam: use the platform’s spam tools, then delete flagged items or leave them unpublished.
  • Add nofollow: apply rel="nofollow" to URLs submitted through TrackBacks and comments to avoid passing ordinary link credit through untrusted submissions.
  • Limit acceptance: disable incoming TrackBacks at the blog or system level if you do not need them.
  • Constrain outgoing pings: turn off outbound TrackBacks or restrict them to selected domains.
  • Disable auto-discovery: turn off external and internal auto-discovery when you do not want automatic pings.

These controls are covered in Movable Type’s TrackBack manual and TrackBack administration documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing whether to keep TrackBacks

Make the decision based on whether the feature serves a real audience need, not simply because it is available. Keeping it can preserve interoperability with older blogs, but it adds a moderation task and leaves a public notification surface exposed to abuse.

  • Keep it with safeguards if you exchange links with legacy blogs and value the visible conversation. Require moderation, spam filtering, and nofollow; try the workflow on a staging or low-risk post before enabling it broadly.
  • Disable it if no meaningful readers or partners use it. Turn off incoming and outgoing TrackBacks and use ordinary links or a newer mention-notification method supported by your platform.

What developers should know

Movable Type’s standalone TrackBack tool is a CGI script that stores pings locally and can expose them through a browser or RSS. It requires a CGI-capable web server and Perl modules; it is not a drop-in feature for every hosting setup. Details are in the standalone TrackBack documentation.

WordPress provides TrackBack sending through its editor and developer functions. A receiving site may choose not to display a sent TrackBack, so sending one does not guarantee a public listing. WordPress documents these behaviors in its user guidance and TrackBack developer reference.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.