NewSee how
FirstSales
Bot clicks and fake email engagement: why opens lie in 2026

#Bot clicks and fake email engagement: why opens lie in 2026

Copy page
19 min read read

TL;DR: Corporate security scanners from Microsoft, Proofpoint, Mimecast, and Barracuda auto-open links and pre-fetch images the second an email lands, and industry estimates put scanner-driven opens at 15 to 40 percent of total opens on enterprise-heavy lists. Add Apple Mail Privacy Protection, which now touches roughly half of all reported opens, and most open and click dashboards in 2026 are measuring machines, not people. Replies, meetings booked, and human-verified clicks are the only numbers left that mean what they say.


#What you will learn

  1. What bot engagement actually is
  2. The four sources faking your numbers
  3. Why 2026 makes this worse than 2022
  4. Real signal vs bot signal
  5. How to spot a bot open or click
  6. The path an email takes before a human sees it
  7. How to filter bot activity from real engagement
  8. What KPIs to trust instead
  9. Building a bot-aware reporting stack
  10. Frequently asked questions

A SendGrid user posted on Reddit that their open rate ran four times higher than every historical benchmark they had.

They checked their subject lines. They checked their send times. The actual cause was a corporate security gateway that clicked every link and loaded every pixel in every inbound email before a single employee saw it.

That is not a fluke. It is standard behavior for the security software sitting in front of most B2B inboxes today.

Security teams call it link detonation. Marketers call it a mystery spike. Sales reps call it a lead that never replies, no matter how many "hot" opens the dashboard shows.

This piece breaks down exactly which systems are faking your engagement data, how to catch them in the act, and which numbers you can still trust when you are running cold outbound in 2026.

#What bot engagement actually is

Bot engagement is any open, click, or preview triggered by software instead of a person reading your email.

It happens before, during, or immediately after delivery, and the recipient never sees the message.

Three categories cover almost all of it: security scanners that detonate links and attachments, image proxies that pre-fetch remote content for privacy, and antivirus or link-checking tools that follow every URL to test it for malware.

None of these are malicious. They exist to protect the recipient.

This layer sits alongside a newer trend worth watching too: AI-driven inbox assistants that pre-screen and summarize email before a human ever scrolls to it, which is its own source of engagement that does not map to traditional intent signals. Our piece on AI inbox screening in cold email covers how that assistant layer is starting to change what "opened" even means.

The side effect is that your tracking pixel fires and your link gets clicked by a machine that has no interest in your offer, and your reporting tool cannot tell the difference between that machine and a real prospect.

#The four sources faking your numbers

Four distinct technologies generate the bulk of non-human engagement, and each behaves a little differently.

Microsoft Defender for Office 365, formerly called ATP, rewrites every URL in an inbound email and checks it against a threat database at the moment of delivery.

On many enterprise tenants, that check includes a live fetch of the destination page, which happens within seconds of the message hitting the mail server.

Because Microsoft 365 covers a huge share of B2B inboxes, this single feature accounts for a large chunk of the "click" you see logged the instant an email arrives, long before any human has opened their inbox.

#Proofpoint, Mimecast, and Barracuda

These three vendors dominate the third-party email security gateway market, and all three use a technique commonly called sandboxing or detonation.

The gateway opens attachments in an isolated environment and follows every link to see where it leads and whether the destination is safe.

Proofpoint has confirmed publicly that URLs in delivered messages are rewritten and checked at click time, and separately, many of these gateways also perform pre-delivery detonation on a portion of traffic, meaning the click can register before the message even reaches the recipient's mailbox.

Endpoint antivirus suites and browser security extensions often prefetch links found in email clients to scan for malicious redirects.

This layer sits on the recipient's machine rather than the mail server, so it can fire again later, sometimes hours after delivery, when the antivirus software does a scheduled scan of the inbox.

That second wave of activity is one reason "click" timestamps on some campaigns show a strange gap: a burst at delivery, silence, then a smaller burst hours later with zero corresponding replies.

#Image proxy pre-fetching: Apple MPP and Gmail

Apple's Mail Privacy Protection, introduced in iOS 15, downloads every remote image in an email through Apple's own proxy servers regardless of whether the recipient ever opens the message.

Gmail runs a similar image proxy and has since 2013, caching images on Google's servers rather than the sender's, which also masks the recipient's real IP and device. Senders working within Gmail's 2026 sending limits should assume this proxy touches nearly every Gmail-hosted recipient on their list.

Litmus data shows Apple Mail accounted for roughly 49 to 50 percent of all tracked opens through most of 2025, and by early 2026 that figure had climbed toward 58 percent of reported opens, which means well over half of your "open" number now comes from a device category where the open event may be entirely automated.

#Why 2026 makes this worse than 2022

The Apple MPP story broke in 2021 and 2022, and most marketers absorbed that shock years ago.

What gets far less attention is that the bot-click layer has grown quietly on top of it, and 2026 is the first year the two problems have fully stacked.

"As of May 2025, MPP accounted for more than 50 percent of all email opens, and Apple Mail Privacy Protection alone inflates open rates by 15 to 20 points or more," according to Litmus Email Client Market Share data cited across multiple 2025 to 2026 industry reports.

Security scanning has expanded in parallel because enterprise IT budgets for email security grew every year this decade, and every new gateway deployment adds another layer of automated pre-opens sitting between your send and the human recipient.

Stack the two together and a cold email sent to a mid-size company today can rack up an open from Apple's proxy, a click from Microsoft Safe Links, a second click from a Barracuda scan, and still never be seen by the actual person in the To field.

Industry estimates put scanner-driven opens at 15 to 40 percent of total opens on enterprise-heavy prospect lists, layered on top of an MPP effect that already touches roughly half your list.

Run the arithmetic on a 40 percent reported open rate and the honest human-open number could realistically sit somewhere between 10 and 20 percent, with no way to know exactly where in that range without instrumenting for it.

That gap is why so many teams are quietly abandoning open rate as a primary metric. Our companion piece on why email open rates are a dead metric in 2026 walks through the mechanics of that shift in more detail.

#What bot-inflated data actually costs you

What bot-inflated data actually costs youWhat bot-inflated data actually costs you

The damage is not cosmetic. A dashboard full of fake opens changes real decisions, and those decisions cost money.

#Lead scoring breaks first

Most lead-scoring models weight opens and clicks heavily, on the assumption that engagement predicts intent.

Feed that model bot-inflated data and it starts ranking prospects at security-heavy enterprises above prospects at smaller companies with lighter security stacks, even though the enterprise contact never saw the email.

Sales reps then chase the wrong accounts first, working down a priority list built on scanner noise instead of actual interest, which wastes the exact hours you were trying to save by scoring leads in the first place.

#Budget gets allocated to the wrong channel

Marketing teams comparing channel performance often lean on click-through rate as a proxy for message quality across email, LinkedIn, and paid ads.

Email's bot-inflated CTR looks artificially strong next to channels that do not have an equivalent automated-scanning problem, which can pull budget toward email campaigns that are actually underperforming once the fake clicks are stripped out.

#Sequence and cadence decisions get built on noise

A/B tests that compare subject line A against subject line B on open rate alone are really testing which version triggers more security scanning, not which version a human finds more compelling, because scanner behavior is largely indifferent to subject line content while genuine human open behavior is not.

Teams that optimize send times based on "when opens spike" often end up optimizing for when corporate mail servers process their morning batch of inbound scanning, not for when employees actually check their inbox.

Our guide on sales funnel metrics covers how to rebuild a funnel model around stages that survive this kind of data contamination, starting further down the funnel than open rate.

#Real signal vs bot signal

The table below compares the behavioral fingerprints of genuine human engagement against the patterns bots and scanners leave behind.

SignalHuman engagementBot or scanner engagement
Time to open after delivery✓ Minutes to hours, varies by recipient's schedule✗ Under 5 to 10 seconds, almost instant
Number of opens per recipient✓ Usually 1 to 3, spread over days✗ Multiple simultaneous opens at the exact same timestamp
IP or ASN of the opener✓ Residential or corporate office ISP✗ Data center, cloud hosting, or known security vendor ASN
Device and client string✓ Real mail client, consistent with recipient's known device✗ Generic or missing user agent, or Apple's proxy signature with no client data
Click followed by page activity✓ Scroll, time on page, form fills, secondary clicks✗ Single hit, zero time on page, no scroll depth
Click-to-reply correlation✓ Opens and clicks that precede a reply within days✗ High click volume with zero corresponding replies across the whole list
Geographic consistency✓ Location matches the recipient's known company HQ or region✗ Location jumps to a data center region unrelated to the recipient
Repeat pattern across sends✓ Engagement varies naturally send to send✗ Identical open timestamp behavior on every single send to that domain

#How to spot a bot open or click

Four patterns show up consistently enough to build detection rules around, and none of them require expensive tooling to check manually on a small sample.

#Opens within seconds of delivery

A human recipient needs time to notice a new email, switch to their inbox, and open the message.

If your logs show an open timestamp within 5 to 10 seconds of the send timestamp, that is a scanner, not a person, because no realistic reading behavior compresses that fast.

#Opens or clicks from data center IPs and ASNs

Every IP address maps to an autonomous system number, and ASN lookups distinguish residential and business ISPs from hosting providers and known security vendors.

Recurring opens from ranges belonging to Microsoft, Proofpoint, Mimecast, Barracuda, or generic cloud hosts like AWS and Azure are the clearest fingerprint of automated scanning, and free ASN lookup tools can check this in bulk against your engagement logs.

#Multiple simultaneous opens

A real person opens an email once, then maybe again a day later to reread it.

Five or six opens logged within the same one-minute window on a single send almost always trace back to a security gateway re-scanning the message across mirrored mail servers or a scheduled antivirus sweep.

#Click without any subsequent time on page

Real clicks generate real session data: time on page, scroll depth, sometimes a second click to a pricing page or a form submission.

A click that registers zero seconds of session time and no further activity on your landing page is a bot following the link to check where it goes, not a prospect reading your offer.

#The path an email takes before a human sees it

The diagram below traces one email from send to (maybe) a real human open, showing every automated checkpoint that fires a false engagement signal along the way.

Notice how many automated checkpoints fire before the box that actually matters, the recipient reading the message.

Every one of those checkpoints adds an open or click to your dashboard, and none of them tell you anything about buying intent.

#How to filter bot activity from real engagement

How to filter bot activity from real engagementHow to filter bot activity from real engagement

Filtering starts with data you likely already have sitting in your sending platform's raw event logs, not with buying a new tool.

#Step 1: pull raw timestamps, not aggregated rates

Most email platforms show you a single open rate percentage by default, which hides the underlying event-level data you need.

Export the raw open and click event log with timestamps, IP addresses, and user agent strings for at least one full campaign before you try to filter anything.

#Step 2: flag opens under 10 seconds

Any open event where the timestamp gap from send is under 10 seconds should be flagged as likely automated and excluded from your "engaged" segment.

This single rule alone typically removes a meaningful share of the scanner-driven noise on enterprise lists without touching legitimate fast responders, who are rare enough not to matter statistically.

#Step 3: cross-reference IPs against known ASN ranges

Run the flagged IPs through a free ASN lookup and build a static exclusion list of ranges belonging to Microsoft, Proofpoint, Mimecast, Barracuda, and major cloud hosts.

Several dedicated bot-detection vendors now sell this as an API specifically for email marketers, which is worth the cost if your list skews heavily toward large enterprise accounts with mature security stacks.

#Step 4: require a secondary action for "engaged" status

Do not count a click as real engagement on its own. Require at least one additional signal, such as time on page over 15 seconds, a scroll event, or a form interaction, before a click counts toward your qualified engagement number.

#Step 5: correlate against replies weekly

Every week, check whether your top "engaged" segment by opens and clicks is actually generating replies at a rate consistent with your list-wide average.

If a segment shows triple the click rate but the same or lower reply rate as the rest of the list, that segment is bot-inflated and should be excluded from any lead-scoring model.

A weekly cadence also makes it easier to spot the campaigns worth escalating for a real reply, which is where a structured reply handling playbook earns its keep once the bot noise is stripped out.

#What KPIs to trust instead

Three metrics survive the bot problem because they require a genuine human decision to occur, something no scanner or proxy can fake.

Replies. A scanner does not write a sentence back to you. A reply, even a short "not interested," proves a real person read the message and made a choice.

Meetings booked. Booking a calendar slot requires clicking through a scheduling tool, picking a time, and confirming, a multi-step action that automated scanning never performs. Our guide on automated meeting booking in outbound covers how to wire this into your sequence so booked calls become the primary metric your reps see first.

Human-verified clicks. Clicks that pass the secondary-action filter from the previous section, meaning real time on page and real scroll behavior, are close enough to trustworthy for most reporting needs.

Everything downstream of those three should be treated with skepticism, including cost per meeting and pipeline velocity numbers if the top-of-funnel data feeding them is bot-contaminated.

Our guide on cost per meeting in outbound walks through building that math on reply-based data instead of raw send volume.

For teams still reporting on raw open and click rates to leadership, the shift to reply-centric reporting is also the fastest way to explain why last quarter's "high engagement" campaign produced no pipeline. Our cold email benchmarks piece has current reply-rate ranges by industry to set realistic targets against.

#How this changes deliverability strategy too

Bot engagement does not just distort reporting. It changes how you should think about deliverability itself, because inbox providers increasingly use engagement signals to decide inbox placement.

#Engagement-based filtering cannot fully distinguish bot from human either

Gmail and Microsoft both use recipient engagement, including opens and clicks, as one input into their spam filtering and inbox placement algorithms.

If a meaningful share of the "engagement" feeding those algorithms is scanner-driven rather than human, the filtering decision is partly built on the same noisy data your own reporting struggles with, which is one reason sender reputation can behave in ways that seem inconsistent with actual recipient interest. Tools like Google Postmaster Tools for cold email give a view into reputation that sits closer to the provider's actual filtering decision than your own open rate ever will.

#Authentication matters more than ever as a baseline

None of the bot-filtering techniques in this article substitute for basic authentication hygiene, because a domain that fails SPF, DKIM, or DMARC checks gets flagged harder by every security gateway in this piece, which paradoxically produces more scanner-driven fake opens while human deliverability collapses.

Getting SPF, DKIM, and DMARC set up correctly for 2026 is the floor every sender needs before engagement data of any kind, real or fake, becomes worth analyzing.

#Warm-up and reputation building need a longer measurement window

Because bot engagement front-loads at delivery and human engagement trails over hours or days, a new domain that looks "hot" on day one based on opens is often just showing scanner activity, not genuine reputation building.

Give any new sending domain at least two to three weeks of reply-rate data, not open-rate data, before drawing conclusions about how the warm-up is going.

Continuous monitoring matters here too, since a domain's scanner-triggered open rate can shift the moment your list mix changes toward more enterprise accounts. Our email deliverability monitoring guide covers tracking reputation signals that hold up even when the underlying engagement data is partly automated.

#Building a bot-aware reporting stack

Most teams do not need custom bot-detection software to get 80 percent of the value here.

A spreadsheet with timestamp filtering, an ASN exclusion list, and a weekly reply correlation check catches the majority of the noise described above.

Where dedicated tooling helps is scale: once you are sending thousands of emails a week across dozens of campaigns, manual filtering stops being practical, and a platform that separates verified human engagement from raw pixel fires at the data layer saves real analyst time.

This is the exact gap platforms built around AI-assisted outbound are starting to close. FirstSales.io surfaces reply-based and human-verified engagement metrics by default instead of leading with raw opens and clicks, which matters more every quarter as the bot layer thickens.

The point is not to abandon opens and clicks entirely. It is to stop treating them as a trustworthy proxy for interest and start treating them as a rough, noisy signal that needs a reply or a booked meeting to confirm it meant anything.

Deliverability work still matters here too, because a domain with a poor reputation gets flagged harder by security gateways, which paradoxically can inflate scanner-driven opens even further while human deliverability drops. Our inbox placement rate guide and cold email deliverability checklist cover the reputation side of that equation.

If your sending domain also touches Google Workspace or Microsoft 365 recipients directly, the Google bulk sender rules and Microsoft cold email rules for 2026 explain the authentication floor you need before any engagement metric, real or fake, matters at all.

#Frequently asked questions

#What is a bot click in email marketing?

A bot click is a link click generated by automated software, such as a security scanner, antivirus tool, or image proxy, instead of a human recipient. It registers in your analytics exactly like a real click but carries zero buying intent.

#How do I know if my email opens are fake?

Check the timestamp gap between send and open. Opens registered within 5 to 10 seconds of delivery are almost always automated scanning rather than a human reading the message.

Yes, on tenants with Advanced Threat Protection enabled, Microsoft rewrites and checks every URL in an inbound email at delivery or click time, which fires your tracking link regardless of whether a human ever clicks it.

#What percentage of email opens are from Apple Mail Privacy Protection?

Litmus data shows Apple Mail accounted for roughly 49 to 50 percent of tracked opens through most of 2025, climbing toward 58 percent of reported opens by early 2026, and MPP inflates open rates by an estimated 15 to 20 points or more.

#Can Proofpoint and Mimecast inflate my click-through rate?

Yes. Both vendors sandbox and detonate links in inbound email as part of their threat-scanning process, which fires the tracking pixel and registers a click before a human recipient ever sees the message.

#Why did my open rate suddenly quadruple with no change in strategy?

A likely cause is a shift in your recipient list toward companies running aggressive security gateways, since Proofpoint, Mimecast, and Barracuda-style scanning can add anywhere from 15 to 40 percent scanner-driven opens on enterprise-heavy lists.

#Is Gmail's image proxy the same as Apple Mail Privacy Protection?

They work similarly, both cache remote images on the provider's own servers rather than fetching directly from the sender, but Gmail's proxy has existed since 2013 while Apple MPP launched in 2021, and each masks IP data differently.

#How do I filter bot opens out of my email reporting?

Flag opens under 10 seconds from send time, cross-reference IP addresses against known data center and security vendor ASN ranges, and require a secondary action like time on page before counting a click as real engagement.

#What is an ASN and why does it matter for bot detection?

An ASN, or autonomous system number, identifies the network an IP address belongs to. Cross-referencing engagement IPs against ASNs for Microsoft, Proofpoint, Mimecast, and cloud hosting providers is the fastest way to spot automated traffic in bulk.

#Should I stop tracking open rate entirely?

No, but stop treating it as a primary success metric. Keep it as a rough deliverability signal while shifting your core reporting to replies, meetings booked, and human-verified clicks.

#What KPI should replace open rate for cold email campaigns?

Reply rate is the closest thing to a bot-proof metric, since no scanner or image proxy writes a response back to you. Meetings booked is the next most reliable signal.

#Do bot clicks affect my sender reputation or deliverability?

Indirectly. High click volume with no corresponding replies can distort engagement-based sending algorithms at Gmail and Microsoft, which factor real engagement into inbox placement decisions over time.

#How many simultaneous opens indicate bot activity?

More than two or three opens logged at the exact same timestamp on a single send is a strong signal of automated re-scanning rather than a human reopening the email.

#Can antivirus software on the recipient's computer trigger a fake open?

Yes. Endpoint antivirus and browser security extensions often prefetch links found in emails to scan for malicious redirects, sometimes hours after the message was delivered, creating a delayed second wave of fake clicks.

Link detonation is the process security gateways use to open links and attachments in an isolated sandbox environment to check for malware before or at the moment a recipient would click them, which fires tracking pixels and registers clicks automatically.

#Why do bot opens matter more for B2B cold email than B2C marketing?

B2B recipients sit behind corporate security gateways like Proofpoint, Mimecast, and Microsoft Defender far more often than consumer inboxes, which means enterprise-targeted cold email absorbs a much higher share of scanner-driven fake engagement.

#Is a click with zero time on the landing page always a bot?

Not always, but it is a strong signal. Real prospects usually spend at least a few seconds scanning a landing page, so a click with zero recorded session activity is far more likely to be an automated scan than genuine interest.

#How do I explain low reply rates despite high open rates to my team?

Show the raw timestamp data. A cluster of opens within seconds of delivery, concentrated on enterprise domains, demonstrates that the reported open number includes scanner activity rather than real reader attention.

#Does sending fewer emails reduce bot-driven engagement?

No, bot engagement scales with the security infrastructure of your recipient's company, not your send volume. A smaller, more targeted list to security-heavy enterprise domains can still show a high percentage of scanner-driven opens.

#What tools can help detect bot engagement automatically?

Dedicated bot-detection APIs exist that cross-reference IP and ASN data against known scanner ranges in real time, which is worth adopting once your list is large enough that manual timestamp and IP review is no longer practical.

#Where this leaves your reporting

Open rate was never a perfect metric, and it has been getting worse for years, not months.

Apple MPP started the erosion in 2021. The bot and scanner layer from Microsoft, Proofpoint, Mimecast, and Barracuda has quietly stacked on top of it since, and 2026 is the year the combined effect is large enough that most enterprise-facing campaigns cannot trust their open or click dashboard at face value.

The fix is not complicated. Pull raw timestamps, flag anything under 10 seconds, cross-reference IPs against known scanner ASNs, and require a secondary action before counting a click as real.

Then build your reporting, your lead scoring, and your team's targets around replies and meetings booked, the two things a piece of security software cannot fake no matter how good its sandboxing gets.