You send a campaign to your B2B list. The report comes back with a 9% click-through rate. Best result of the quarter. You tell your manager. You start planning to repeat whatever you just did.
Except a meaningful chunk of that 9% may never have reached a human. It was Microsoft Defender.
The short answer: on B2B email lists, industry research from the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) has found that non-human interactions can account for somewhere between 20% and 80% of recorded clicks, depending on how many recipients sit behind corporate security software. On consumer lists the number is far lower, typically under 10%. Either way, if you have never separated bot clicks from real ones, your click rate is not measuring what you think it is measuring.
Why Security Software Clicks Your Links Before Anyone Reads Them
Corporate email security tools exist to stop phishing and malware, and one of their core techniques is to automatically visit every link inside an incoming email before it lands in someone's inbox, or the moment it does. The system rewrites the original link, sends it through a scanning service, and checks the destination for malicious content.
This happens whether or not the email is actually opened by a person. The scan is designed to run quietly in the background, and because these systems intentionally avoid predictable patterns that a bad actor could exploit, there is no clean, universal way to separate a scan from a genuine click just by looking at the URL.
The tools most often responsible for this behaviour include:
| Security tool |
Vendor |
What it does |
| Safe Links |
Microsoft Defender for Office 365 |
Rewrites and scans links at delivery and at click time |
| URL Defense |
Proofpoint |
Rewrites URLs and inspects destinations before allowing access |
| URL Protect |
Mimecast |
Scans link destinations for malware and phishing content |
| Link Protection |
Barracuda |
Automatically follows and evaluates outbound links |
None of these products are doing anything wrong. They are protecting the recipient. But from your email platform's point of view, every one of those automated visits looks identical to a real subscriber clicking your call to action.
Why B2B Lists Take the Biggest Hit
The impact is not evenly distributed. It depends entirely on what sits between your email and the recipient's eyes.
A consumer subscriber checking a personal Gmail or iCloud account is unlikely to have enterprise link-scanning in front of their inbox. A B2B subscriber at a mid-size or large company almost certainly does, because their IT department deployed it. That is why the same underlying mechanism produces such different numbers by audience type:
- B2B lists: non-human clicks can represent a large minority to a clear majority of total recorded clicks, particularly on lists skewed toward larger organisations with mature security stacks.
- B2C lists: non-human clicks are typically a small share of the total, though they are not zero — some consumer mailbox providers and antivirus tools run lighter versions of the same scanning.
- Mixed lists: the more enterprise domains in your subscriber base, the more your blended CTR drifts away from reflecting real interest.
This is also why comparing your CTR against a generic industry benchmark can be misleading. A benchmark built mostly from consumer newsletters will look nothing like your numbers if your list is full of corporate email addresses, and the gap has nothing to do with how good your email was.
The Signals That Give Bot Clicks Away
You cannot always tell a bot click from a real one by looking at a single row of data, but patterns emerge once you look at timing and behaviour across a campaign.
Clicks that arrive too fast. A security scan typically happens within seconds of the email being delivered, often before a human has had time to open the message, read it and decide to click. A spike of clicks in the first minute after send, especially concentrated on the same handful of corporate domains every time you send, is one of the clearest tells.
The same link clicked more than once from one recipient in a short window. Real readers click a link once. Some scanning tools re-check links periodically, which can show up as repeat automated visits from the same address.
A bot-trap link. A well-established, low-tech detection method is to add a link inside the email that no human reader would ever notice or click, such as one hidden in a full stop or placed in white text on a white background. A real subscriber will never click it. A scanner that follows every link in the message will. Any traffic on that link is close to pure signal for non-human activity.
High opens with almost no meaningful downstream action. If your open and click numbers look healthy but replies, conversions or revenue never show up, that gap is often where bot activity is hiding.
The Damage This Does to Your Decisions
Inflated click data is not just a vanity problem. It quietly distorts almost every decision that depends on click rate.
A/B testing gets compromised. If Version A resonates more with genuine readers but Version B happens to reach more corporate inboxes running aggressive security scanning, Version B can win the test on paper while performing worse with real people. Teams that roll test winners into future campaigns can end up optimising toward whichever subject line or design a security scanner liked best.
ROI calculations get inflated. A campaign with a headline click rate of 9% looks like a very different investment than one converting real recipients at a fraction of that rate once bot clicks are stripped out. Budget and headcount decisions made on the inflated number are being made on the wrong number.
Lead scoring gets false positives. If your marketing automation platform assigns intent score based on clicks, a security bot silently clicking every link in your email can push a completely uninterested account to the top of a sales list.
Segmentation and journeys misfire. Automated journeys that branch based on "clicked" behaviour can move contacts into a "highly engaged" segment or trigger a follow-up sequence based on a scan that a human never saw.
What to Track Instead of Raw Click Rate
None of this means click rate is useless. It means raw, unfiltered click rate should not be the only number you trust, particularly on B2B or enterprise-heavy sends.
| Metric |
What it tells you |
Why it's more resistant to bot noise |
| Click-to-open rate (CTOR) |
Of the people who opened, how many clicked |
Still affected by bot opens, but narrows the denominator to engaged sessions |
| Unique clicks (bot-filtered) |
Real people who clicked at least once |
Removes repeat automated visits if your ESP filters known scanner user agents |
| Time-to-click distribution |
How long after send the click occurred |
Clicks arriving in the first few seconds are far more likely to be automated |
| Downstream conversions |
Replies, sign-ups, purchases, meetings booked |
Bots do not fill out forms, reply to emails or complete purchases |
| Revenue or pipeline per email |
The business outcome the campaign was built for |
The metric least distorted by any click-tracking noise upstream |
The practical move for most teams is not to abandon click rate, but to stop treating it as a precise, comparable number across campaigns and audiences, and to weight downstream, harder-to-fake outcomes more heavily when deciding what actually worked. If you have already noticed your click rate trending down even as your program improves, this bot-click effect is often part of the explanation, alongside the broader shifts covered in why email reports never match Google Analytics.
What Your ESP Can and Cannot Do About It
Some email platforms have started building in filtering for known security-scanner user agents and IP ranges, which strips out a portion of the obvious automated traffic before it reaches your dashboard. This helps, but it is not a complete fix. Newer or less common scanning tools are not always in the filter list, and vendors intentionally vary their scanning patterns over time to avoid being blocked, which is the same trait that makes them hard for marketers to filter out.
If your platform offers bot-click filtering, turn it on and treat the filtered numbers as your baseline going forward. If it does not, the manual signals above — click timing, a bot-trap link, and comparing click rate against actual downstream outcomes — are the next best option.
The Bottom Line
A high click rate on a B2B campaign is not automatically good news, and a lower one is not automatically bad news. Enterprise security software is designed to click every link in every email it scans, and that automated activity has been quietly inflating email metrics for years, at a scale M3AAWG's own research puts as high as 80% of recorded clicks on some B2B sends.
The fix is not to stop measuring clicks. It is to stop assuming every click came from a person, to watch for the timing and pattern signals that give bots away, and to put more weight on the outcomes a bot cannot fake — a reply, a meeting booked, a purchase, revenue. Your dashboard might still say 9%. What matters is how much of that number was ever actually read.
Related Articles
Related tools: Check whether an A/B test actually won once bot noise is accounted for with the Email A/B Test Significance Calculator, and see how your click-through rate compares once you separate campaign type and audience with the Email Click-Through Rate Calculator.