The deliverability of one-time passwords (OTPs) versus one-time links isn't significantly different. Core deliverability practices, like sender reputation, proper authentication (SPF, DKIM, DMARC), list hygiene, and avoiding spam triggers, are paramount. While SMS OTPs offer immediacy, SMS deliverability depends on phone number validity and carrier filtering. Both methods have security vulnerabilities: SMS and email OTPs can be intercepted, while one-time links are also susceptible. Accurate tracking metrics are essential and should be interpreted with caution; relying solely on clicks and open rates can be misleading. Security measures, regulatory compliance, user experience, and cost must be considered when choosing a delivery method. The adoption of standards like TOTP aids in security. Alternatives such as authenticator apps provide heightened security.
9 marketer opinions
While OTPs delivered via SMS can be effective due to immediacy, email deliverability for both OTPs and one-time links hinges on sender reputation, authentication (SPF, DKIM, DMARC), list hygiene, and engagement. SMS deliverability is also affected by carrier filtering and content compliance. Both methods have vulnerabilities: SMS and email OTPs are susceptible to interception and phishing, while one-time links can be intercepted. The choice depends on security needs, user experience, cost, and regulatory compliance. Stronger authentication methods may be needed for higher security.
Marketer view
Email marketer from Mailjet shares that delivering one-time passwords (OTPs) via SMS can be highly effective due to the immediacy and high open rates of text messages. However, it's essential to comply with SMS regulations, obtain user consent, and optimize message content for mobile devices to ensure successful delivery and a positive user experience.
7 Mar 2025 - Mailjet
Marketer view
Email marketer from StackOverflow user user12345 points out that OTPs delivered via SMS or email are susceptible to man-in-the-middle attacks. While HTTPS helps protect against eavesdropping, it doesn't prevent phishing or SIM swapping. Stronger authentication methods, such as hardware tokens or biometrics, may be necessary for high-security applications.
5 Apr 2022 - Stack Overflow
6 expert opinions
Experts indicate that deliverability is not significantly different between one-time passwords (OTPs) and one-time links. Mailbox providers track opens via analytics, not just images, and often don't track clicks. Tracking clicks and open rates may not accurately represent deliverability. It's also noted that URL shorteners should be avoided in email marketing due to their association with spam.
Expert view
Expert from Word to the Wise explains that tracking clicks and open rates does not always accurately represent deliverability or receipt.
11 Nov 2024 - Word to the Wise
Expert view
Expert from Email Geeks explains that mailbox providers that track whether or not an email is opened do not use images to track the open and in terms of deliverability, there is zero difference between one time passwords and one time links (most places aren’t tracking clicks, either). Senders track open and clicks because that’s all they have access to.
7 Apr 2022 - Email Geeks
4 technical articles
Documentation suggests that OTPs are generally reliable due to their transactional nature, but SMS deliverability is influenced by phone number validity and carrier filtering. Authentication and lifecycle management are important to security. Standards like TOTP promote compatibility. Following best practices for bulk email senders, like SPF, DKIM, DMARC, low spam rates, and easy unsubscribe options, helps ensure email delivery.
Technical article
Documentation from NIST shares that authentication and lifecycle management of an application is an important step in securing it against potential threats.
27 Nov 2024 - NIST
Technical article
Documentation from Twilio states that OTPs are generally reliable for delivery, as they are typically transactional and time-sensitive. However, factors like phone number validity and carrier filtering can impact deliverability. Best practices include using a reputable SMS gateway, ensuring proper formatting, and providing clear instructions to users.
3 Oct 2022 - Twilio
Are Bitly links bad for email deliverability?
Are HTTP links penalized by spam filters in email marketing?
Are link shorteners bad for email marketing?
Are URL shorteners like bit.ly bad for email deliverability?
Do secure HTTPS links improve email deliverability?
Does using HTTP links instead of HTTPS links affect email deliverability?
How do HTTP tracking links affect email deliverability and user experience?