Skip to content
LumyOne

Bot clicks in email: why your click rate looks too good

A campaign that shows clicks seconds after delivery, or a click rate far above your usual, is often counting machines, not people. Here is where those clicks come from and how to keep them out of your numbers.

Updated

Who clicks your links before your subscribers do

Many inboxes sit behind a security gateway. Before a message reaches the person, the gateway opens the links in it to check where they lead. Most corporate email security services work this way, and most company inboxes are protected by one.

Those checks look like clicks to your sending tool. They usually come from cloud or datacenter IP addresses, often from a headless browser, and they hit every link in the email within seconds of delivery. Link previews, archiving tools and scripts that copy links from forwarded emails add more.

Signs that your email clicks are not real

A few patterns give bot clicks away. One on its own proves little; several together usually do.

  • Clicks arrive within seconds of delivery, before anyone could have read the email.
  • One recipient clicks every link in the email, including the footer and the unsubscribe link.
  • Clicks with no open recorded for the same message.
  • The click comes from a cloud or hosting network (the big cloud providers and hosting companies) instead of a home or mobile ISP.
  • The same IP address clicks links that were sent to many different recipients.
  • The browser is a headless or automated one, or the user agent names a crawler.
  • Click rates jump on B2B lists, where corporate gateways are common, but not on consumer lists.

Why it matters

Inflated clicks make subject-line and content tests unreliable: the variant that went to more corporate inboxes wins for the wrong reason. Automations that trigger on a click, such as a follow-up sequence or a sales alert, fire for people who never read the email.

The scanner also loads your landing page. Your page analytics count a visit that was never a person, and anything on that page, from an offer to a one-time link, has been seen by a machine first.

How to filter bot clicks

Some sending tools mark known scanner clicks in their reports. That cleans up the numbers, but the scanner still reaches your landing page. To keep it away from the page as well, the decision has to happen at the link itself, before the redirect.

Point every link in the email at a tracking domain you control, and check each click on the server before deciding where it goes:

  • Bot signatures and headless browsers in the user agent.
  • Datacenter and server IP ranges, where scanners run.
  • Tor exit nodes and visits with no identifiable ISP.
  • Repeated clicks from one IP in a short time.

Send filtered clicks to a neutral page

Blocking a scanner outright can make the security tool mark the link as suspicious. A better answer is a second destination: a plain page, such as a blog article, that loads normally. The scanner sees a harmless page, real readers reach your offer, and only real clicks count toward conversions.

How LumyFlow handles it

In LumyFlow, the links in your email run on your own subdomain, such as go.yourbrand.com. Each campaign can block bots, datacenter and server traffic, Tor exit nodes, visitors with no ISP or no referrer, IPv6 visitors and repeated clicks from one IP. Blocked clicks go to destination B; everyone else reaches destination A.

The Traffic log shows every click with the destination it got and the reason, so you can check a suspicious spike click by click. Conversions are recorded against the click, so a scanner that never buys never inflates them. Use it with LumySend, or with the email tool you already have.

Questions

Many do. Corporate email security services open links to check them, usually from datacenter IP addresses and within seconds of delivery. Behaviour varies by provider and by how each company configures it.

See it on your own traffic.

Book a demo and we will set up a campaign on your domain with you.