Blog

Stop bots from unsubscribing your readers and burning login links

Email scanners follow every link, including one-click unsubscribes, confirmation links and passwordless logins. Here is how to make those links safe.

Here is a support ticket every email sender eventually gets: "I never unsubscribed, why did I stop getting your newsletter?" Or its cousin: "Your login link says it has already been used."

In both cases, nobody did anything wrong. A link scanner did.

Why it happens

Security tools visit links in incoming emails to check them. If one of those links performs an action the moment it is opened, the scanner performs the action. That includes:

  • One-click unsubscribe links
  • Double opt-in "confirm your subscription" links
  • Passwordless "magic" login links that work once
  • "Accept invite" and "verify email" links

The real fix: don't act on a page visit

The most reliable solution has nothing to do with IPs. Make the link open a page with a button, and only perform the action when the button is pressed.

Scanners load pages. They don't press buttons. A visit (a GET request) shows the page; the action happens on a form submit (a POST request). This one change solves most of the problem on its own.

Where an IP check still helps

Sometimes a button is not an option. For example, the standard one-click unsubscribe header that mailbox providers support is designed to work without extra steps. And some teams have flows they can't redesign quickly.

In those cases, check the IP before you act:

  • If the request comes from a clean home or mobile network, go ahead.
  • If it comes from a datacenter or bot network within seconds of sending, show the confirmation page instead of acting immediately.

Nobody gets blocked. A real person on a flagged network, say a corporate VPN, just sees one extra button.

Respect real unsubscribes

None of this should make unsubscribing harder for people. When a human clicks unsubscribe, it should work right away, every time. The goal is only to stop machines from making that choice for them.

Get this right and you keep readers who never meant to leave, cut support tickets about broken links, and protect your sender reputation, because people who are silently dropped often come back later and hit "report spam" instead.