You send a campaign. Thirty seconds later the dashboard already shows clicks.
Nobody has read anything. Those are machines, and their vendor documents it.
What Microsoft does to your links
Safe Links is the Microsoft Defender component that protects Outlook users against malicious links. Its official page describes two distinct moments, and it is the first that matters here:
“As long as Safe Links protection is turned on, URLs are scanned prior to message delivery, regardless of whether the URLs are rewritten or not. If rewriting is enabled, links are scanned on click.”
Prior to delivery. Not on click: before the message reaches the mailbox.
The protection stack documentation is more explicit still about what happens then:
“URL Detonation happens when upstream anti-phishing technology finds a message or URL to be suspicious. URL detonation sandboxes the URLs in the message at the time of delivery.”
Detonating a URL means opening it. In an isolated environment, but opening it: the HTTP request goes out, your tracking server receives it, and your tool records a click.
The admission, in Microsoft’s own documentation
The clearest proof is not in the product pages but in the attack simulation FAQ. The section heading is a question thousands of administrators must have asked:
“I see clicks or compromise events from users who insist they didn’t click the link in the simulation message OR I see clicks within a few seconds of delivery for many users (false positives). What’s going on?”
The answer lists the culprits: Outlook add-ins inspecting the message, email security applications, antivirus software, incident response automation.
And Microsoft gives the recognition test, which doubles as a method:
“If a click occurred a few seconds after delivery, and the IP address doesn’t belong to Microsoft, your company, or the user, then it’s likely that a non-Microsoft filtering system or another service intercepted the message.”
Finally, this sentence, which settles the question for its own tooling:
“Each URL in the simulation email is tied to an individual user, so Safe Links detonations are identified as clicks by the user.”
Safe Links detonations are counted as user clicks. That is the vendor writing it, about its own product.
On the opens side, the question is already settled
The tracking pixel met the same fate, but earlier and more completely.
Apple describes its mail client’s behaviour without ambiguity:
“Rather than only downloading remote content when you open an email, Protect Mail Activity downloads remote content in the background by default, regardless of whether you engage with the email.”
And to make correction impossible, the content travels through two successive relays operated by different entities, so that neither knows both the recipient’s IP address and the content retrieved.
Google, for its part, does not block images: it serves them from its own servers, after analysis. Its help page states that “Google scans images for signs of suspicious content before you receive them”.
Before receipt, again. Which is why the open rate has measured nothing since June 2021.
How much, exactly?
Nobody publishes it.
No Microsoft, Google or Apple page quantifies the share of clicks or opens produced by a machine. Microsoft describes the phenomenon in detail and never puts a number on it.
One figure circulates, and it is worth knowing where it comes from. M3AAWG, in a November 2020 document on nonhuman interactions, writes this about B2B:
“Data collected but not published show that overall impact was found to be between 20-80%.”
“Data collected but not published.” The authors themselves announce that the underlying data is not published. A range of 20 to 80 percent is not a measurement anyway; it is an admission of ignorance expressed in numbers.
The same document explains why an exact measurement is out of reach: “It is hard to quantify a summary effect, as most filter agents and ISPs work to mask detection. This is necessary to ensure filters are not circumvented.”
Filters hide, because a detectable filter is a circumventable filter. The imprecision is not a flaw in the system: it is a designed property of it.
So we will leave it there. The mechanism is documented by the vendors, its magnitude is not, and we are not going to invent a percentage to fill the gap.
What remains measurable
Three signals hold up, because no machine produces them.
The unsubscribe. A security robot does not cancel a subscription, and one-click unsubscribe leaves a clean protocol trace.
The complaint. No filter presses the junk button on the user’s behalf. Which is precisely why operators use that number as a threshold.
The conversion. A form completed, an order placed, a written reply: that happens after the click, and scanners do not go that far.
These three signals have one thing in common: they are far lower than open and click rates, and far less pleasant to present. That is exactly what makes them reliable.
What to do tomorrow morning
Open the timestamped click detail of your last campaign and look at the first minute. A cluster of clicks in the seconds after sending is not a success: it is your list of recipients sitting behind a filter.
Then compare two segments: your corporate mailbox recipients and your consumer mailbox recipients. If the first segment’s click rate is far above the second’s, you are not measuring professional interest. You are measuring the density of their security tooling.
Finally, change what you present. A report leading with opens and clicks describes machine behaviour. A report leading with unsubscribes, complaints and conversions describes human behaviour.
The second is less flattering. It is the only one that lets you decide anything.
Sources
- Microsoft (updated 22 May 2026). Safe Links in Microsoft Defender for Office 365, Microsoft Learn
- Microsoft (updated 30 July 2026). Attack simulation training FAQ, Microsoft Learn
- Microsoft (updated 7 July 2025). Protection stack in Microsoft Defender for Office 365, Microsoft Learn
- Apple (12 December 2025). Mail Privacy Protection
- Google. Images in Gmail, Gmail Help
- M3AAWG (November 2020). Exploring the Impact of Nonhuman Interactions on Email Send Metrics
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
