Suped

Why are we seeing automatic opens and clicks on Office 365 hosted recipient domains?

Summary

Many email marketers and deliverability professionals observe what appear to be automatic opens and clicks on emails sent to Office 365 hosted recipient domains. This phenomenon often leads to confusion regarding campaign performance and subscriber engagement. The primary driver behind these automated interactions is typically Microsoft's robust security features, particularly Microsoft Defender for Office 365's Safe Links and Safe Attachments policies. These systems are designed to pre-scan emails for malicious content, including URLs and attachments, by simulating user interaction. While beneficial for security, this pre-scanning can inadvertently trigger tracking pixels (opens) and even click on links (including unsubscribe links) before the actual recipient has viewed the email.

What email marketers say

Email marketers frequently express concern over misleading engagement metrics resulting from automated opens and clicks on Office 365 recipient domains. They often seek clarification on whether others are experiencing similar issues and how to accurately interpret their campaign data. The primary impact noted is the skewing of open and click rates, making it difficult to assess true subscriber interest and campaign effectiveness. There's also a significant point of concern around automated clicks on unsubscribe links, which can artificially inflate unsubscribe rates or lead to unexpected list churn.

Marketer view

Email marketer from Email Geeks notes a pattern of automatic opens and clicks originating from Office 365 hosted recipient domains. This observation highlights a common issue where email campaign engagement metrics appear inflated due to automated security scans rather than genuine user interaction. They are seeking confirmation from other senders if they are experiencing similar discrepancies in their reporting, suggesting that this is a widespread challenge in accurately assessing email performance when targeting Office 365 users.

24 Jul 2023 - Email Geeks

Marketer view

Email marketer from Email Geeks confirms that Microsoft Defender is indeed clicking on all links, including unsubscribe links, causing significant issues for their email programs. This behavior directly impacts the accuracy of unsubscribe metrics, potentially leading to unintended subscriber loss or misinterpretations of list health. This unsolicited interaction by automated systems means that a click on an unsubscribe link cannot be definitively attributed to a user's desire to opt out, complicating list management and compliance efforts.

30 Aug 2023 - Email Geeks

What the experts say

Deliverability experts consistently identify Microsoft Defender for Office 365's Safe Links and Safe Attachments as the primary cause of artificial opens and clicks. They emphasize that this behavior is a security feature, not an indication of a problem with the sender's email program (unless the email is genuinely malicious). Experts advise senders to understand the technical mechanisms behind these interactions and to adjust their reporting methodologies accordingly. A key takeaway is that these automated scans are a defensive measure to protect end-users from phishing and malware, even if they introduce complexities for email marketers.

Expert view

Email expert from Spam Resource discusses the challenge of distinguishing between legitimate and automated engagement. They emphasize that while security features like Safe Links are necessary, they complicate the interpretation of traditional email metrics. Senders must adapt their analytical approaches to account for this prevalent bot activity, focusing on downstream conversions rather than just open and click rates.

10 Mar 2024 - Spam Resource

Expert view

Deliverability expert from Word to the Wise explains that automated clicks on unsubscribe links are a side effect of aggressive security scanning, not necessarily a sign of malicious intent from the scanner. They point out that these systems are designed to test all URLs for safety, and an unsubscribe link is just another URL. This behavior underscores the need for senders to implement robust unsubscribe processes that handle such automated requests gracefully, preventing unintended removals.

05 Apr 2024 - Word to the Wise

What the documentation says

Official Microsoft documentation and security advisories confirm that Microsoft Defender for Office 365 (formerly ATP) actively employs features like Safe Links and Safe Attachments. These features are designed to protect users from phishing, malware, and other threats by performing real-time, sandboxed analysis of email content. This analysis includes detonation of URLs and attachments, which inherently triggers tracking pixels and clicks on links within the email environment before it reaches the end-user's inbox. The documentation outlines the configurable policies for these features, including options for exclusions, but emphasizes their role in maintaining a secure email ecosystem.

Technical article

Microsoft Learn documentation for Safe Links explains how this feature is designed to protect users from malicious URLs in emails. It details that Safe Links analyzes links by rewriting them and then performing a reputation check at the time of click. This process may involve pre-scanning, which can result in automated 'clicks' as the system verifies the safety of the destination URL. The core purpose is to prevent users from accidentally navigating to harmful websites, prioritizing security over perfect tracking accuracy.

15 Apr 2024 - Microsoft Learn

Technical article

Practical 365 documentation discusses how third-party mail filtering integrates with Office 365 and the methods attackers use to bypass these systems. It highlights that if not properly secured, malicious content can be delivered directly to Office 365 without passing through the intended filtering gateway. This emphasizes the critical role of Office 365's native security features, like Safe Links, in catching threats that might otherwise slip through, even if it leads to automated interactions.

20 Mar 2024 - Practical 365

6 resources

Start improving your email deliverability today

Get started