400 Clicks on Your Newsletter Ad. How Many Were Human?
The biggest source of non-human clicks in email is not fraud. It is corporate security software following every link to check it for phishing, and on a business audience it can account for a tenth to a third of your raw click count. How to separate the three populations, and which signals should be allowed to move money.

A newsletter ad click report contains three populations, not one. Humans who clicked because they were interested. Corporate email security systems that clicked every link in the message before the recipient ever saw it. And, far less often than the industry implies, actual fraud. On a business audience the second group can account for a tenth to a third of your raw click count, and almost nobody separates it out before invoicing.
This matters more in email than in display advertising, and for a reason that surprises most people: the largest source of non-human clicks in email is not fraudulent. It is benign, well-intentioned security software doing exactly what it was bought to do. That changes the entire response. You cannot block it, you would not want to, and the only useful move is to measure it and price around it.
Below: what each population looks like, how to separate them with timing alone, what real email ad fraud actually consists of, and how a serving platform should decide which signals are allowed to move money.
Where non-human clicks come from
Start with the mechanism, because it explains the shape of everything that follows.
When a message arrives at a company running Microsoft Defender for Office 365, Proofpoint, Mimecast, Barracuda, or any comparable link-protection product, the security layer fetches the URLs inside it. It has to. Checking whether a link leads to a phishing page requires visiting the page. Microsoft's own documentation for Safe Links describes this URL scanning as part of message processing, and the resulting fetch is indistinguishable, from the destination server's point of view, from a person clicking.
Your email service provider records it as a click. Your ad server records it as a click. If the advertiser is buying on a cost-per-click basis, they are billed for it.
Published estimates put the inflation this causes at roughly 10% to 35% of raw click-through rate on enterprise-heavy lists. The range is wide because it depends almost entirely on audience composition rather than on anything the publisher controls.
The second source is prefetching and preview generation. This is the same category of problem as Apple's Mail Privacy Protection, which we covered in detail in Gmail and Apple MPP tracking, and which has a close cousin in AI email summaries firing the impression pixel. Machine reading of email is now the norm rather than the exception, and every layer of it touches your measurement.
The third source is fraud proper. It exists. It is smaller than vendor marketing suggests, and it looks different in email than it does elsewhere. More on that below.
Why business audiences are the most exposed
Here is the part that inverts most people's intuition.
Scanner clicks are a function of delivery. They scale with how many of your subscribers sit behind corporate mail security. Human clicks are a function of engagement. They scale with how interesting the issue was.
Those two quantities move independently, which produces a result nobody plans for: as engagement declines, the scanner share of your remaining clicks rises. A list losing interest can hold a flat headline click-through rate for months while its human click count quietly falls, because the machine-generated portion of the number does not care whether anyone is reading.
It also means the most valuable inventory carries the most contamination. B2B newsletters command the highest CPMs in the market, as the figures in our 2026 CPM benchmarks show, precisely because their audiences are professionals at companies. Companies buy email security. A consumer newsletter read on personal Gmail has almost no scanner exposure. A software industry newsletter read at work has a great deal.
So the premium you charge for a business audience and the measurement noise in that audience come from the same underlying fact. Anyone selling into this market, and anyone buying, should understand that before negotiating on click metrics. Our B2B newsletter advertising guide treats the commercial side of that audience; this is the measurement side of the same coin.
What the arithmetic does to a CPC deal
Take a straightforward campaign. 50,000 delivered, 38% open rate, 400 recorded clicks on the sponsor placement, bought at $2.00 per click. The advertiser pays $800.
Now suppose 25% of those clicks were scanners, which sits comfortably inside the published range for a business list. 300 human clicks. The advertiser paid $800 for 300 real visits, an effective cost of $2.67 per click against a contracted $2.00. A 33% overpayment, invisible in every report either side is looking at.
Run it the other direction and it gets worse for the publisher. If the advertiser eventually measures conversions against their own analytics, which will not show the scanner visits as sessions at all, the campaign appears to convert at three-quarters of its true rate. The publisher is judged on a denominator inflated by software neither party installed.
This is the strongest practical argument for pricing on delivered impressions rather than clicks, which we make in more depth in newsletter ad pricing models. A delivery is a server-side fact. A click is an inference about a human, made from an event that machines also generate.
Separating them with timing
The good news is that scanner traffic is trivially identifiable if you keep the right fields, because security software has no incentive to hide. It is not evading you. It is just fast.
Four signatures, in rough order of reliability:
Time from delivery to click. A click registered a fraction of a second after delivery is not a person. A human has to receive a notification, open the app, read enough of the message to develop intent, and find the link. Sub-second is a scanner. Under a few seconds is almost certainly a scanner. Reported observations put typical scanner latency around 0.4 seconds.
Every link, one timestamp. A single recipient recorded as clicking the sponsor placement, the editorial links, the privacy policy, and the unsubscribe link within the same second is a scanner walking the message. No human clicks their own unsubscribe link and then keeps reading.
Clicks with no corresponding open. Order of events matters. Some scanners follow links without ever triggering the tracking pixel, producing the physically impossible sequence of a click on a message that was never opened.
Datacenter origin. Security scanning runs in cloud infrastructure. A click whose source address belongs to a hosting provider rather than a consumer or corporate ISP is very unlikely to be a person on a couch.
Any single one of these can produce a false positive. Someone genuinely does click the unsubscribe link and the sponsor link in the same session sometimes. Someone on a corporate VPN can present an unusual address. This is why the useful rule is two independent signals before you act on a classification, a principle we come back to below because it turns out to matter enormously once money is involved.
What actual fraud looks like in email
Now the smaller population, and the one everybody worries about first.
Email newsletter advertising is structurally harder to defraud than display or search, for three reasons worth stating plainly because they are rarely acknowledged.
The inventory is not open. A fraudster running a fake website can spin up domains and pull programmatic demand within hours. A fraudster targeting newsletter inventory has to first build something that looks like a newsletter with real subscribers, then get it accepted by a network, then survive whatever vetting that network runs. The barrier is months, not hours.
The audience is enumerable. A publisher who claims 80,000 subscribers has, somewhere, 80,000 email addresses. Those addresses have acquisition dates, engagement histories, and domain distributions. Fabricating a plausible one of those at scale is considerably harder than fabricating page views.
Delivery is externally attested. Mailbox providers accept or reject your mail based on their own view of your sending reputation, and that view is not something the publisher controls. A sender pushing volume to fake addresses accumulates bounces and spam complaints that degrade the reputation the whole operation depends on. The economics work against the fraud, which is one reason list hygiene and revenue integrity are the same project, as covered in deliverability and ad revenue.
What does happen, in rough order of frequency:
- Purchased or appended subscribers padding a list that is sold as organic. Not click fraud, but it is inventory fraud, and it shows up as an engagement profile that looks nothing like a list built through the growth tactics real publishers use.
- Incentivised clicks, where a publisher tells readers to click sponsors to support the newsletter. Common, often well-meant, and it produces clicks with no purchase intent behind them.
- Reused or reassigned creative, where a placement sold as top-of-issue is quietly moved below the fold after the first send.
- Genuine automated click generation, which is rare against newsletter inventory specifically because the payout per click does not justify the setup cost compared to easier targets.
Notice that most of that list is commercial misrepresentation rather than technical attack. The defence is diligence, not just filtering. Our publisher vetting checklist is the practical version of that, and brand safety in newsletter advertising covers the reverse direction.
How a serving platform should classify this
This is the part we have opinions about, because we had to build it.
The governing constraint is not detection accuracy. It is that different confidence levels earn different rights over money. A signal you are 99.5% sure about can filter traffic in real time before anyone is billed. A statistical anomaly you are 90% sure about cannot, because 90% confidence applied to a publisher's payout means being wrong about one in ten publishers, and being wrong in that direction destroys the relationship permanently.
The industry vocabulary for this splits invalid traffic into two tiers. General invalid traffic is deterministic and identifiable from the request itself: known bot signatures, datacenter origin, duplicate events, malformed parameters. Sophisticated invalid traffic requires analysis across many events to detect, and is therefore probabilistic.
That distinction is not academic. It maps directly onto what a platform is allowed to do:
Layer 1 serve time, deterministic → filter now, never billed Layer 2 ingestion, sequence checks → tag, exclude from valid counts Layer 3 batch statistical scoring → flag for review, no auto-billing Layer 4 model scoring → rank the review queue only
Layer 1 runs inside the request path and has a latency budget measured in fractions of a millisecond, which means no database reads. It is a bot user-agent list, a datacenter address range check, a duplicate-event guard, and a rate limiter. These are list lookups, and list lookups are either right or the list is stale, so precision targets above 99% are reasonable.
Layer 2 catches protocol violations. In video advertising these are things like a completion event arriving without a start event. The email equivalent is a click with no preceding open, or two clicks from the same recipient on the same placement within a window too short to be physical.
Layer 3 is where statistics enter, and where discipline matters most. It works on slices of traffic rather than individual events, comparing each slice against a trailing baseline of comparable slices. Concentration of clicks in a handful of addresses. Click timing distributions with no human variance. Engagement patterns that do not decay the way real audiences decay. Each of those triggers when it sits several standard deviations from the baseline.
The rule that makes Layer 3 safe is the one from the timing section above, applied to money: a slice only auto-confirms when at least two independent signals fire, and at least one has to be close to deterministic. A single statistical anomaly never moves a payout on its own. Everything else goes to a human queue.
Layer 4, the modelling layer, is deliberately the least powerful. It ranks the review queue. It does not adjudicate. This is not modesty about model quality; it is that a model score is not an auditable reason. When a publisher disputes a withheld payment, "the classifier scored you 0.87" is not an answer that survives the conversation. "Ten addresses generated 88% of the clicks on this placement, and 71% of those clicks landed within two seconds of delivery" is.
Our full position, including the reconciliation window for post-serve reclassification, is published as the MailAdx invalid traffic policy. The ad server applies the serve-time layers, and the outcome surfaces in reporting as a split between raw and valid counts rather than as a single number you have to trust.
The labelling problem, briefly
One thing worth understanding if you are evaluating anyone's fraud claims, including ours.
Fraud detection has no ground truth. Nobody hands you a labelled dataset of which clicks were fake. You can measure precision by auditing what you filtered, but recall — the share of real fraud you caught — is unmeasurable in production, because the fraud you missed is by definition invisible.
There are two honest ways around this. A synthetic corpus, where you generate known-bad traffic yourself and measure what fraction of it your detectors catch. And a honeypot: a placement that is never actually distributed to a real reader, so that any activity on it is invalid by definition and produces free, continuous, certain labels.
If a vendor quotes you a recall figure without explaining which of those it came from, the number is decorative.
What to do about it, by role
If you are buying newsletter ads
Ask for the click timing distribution, not just the count. Any platform that keeps event timestamps can produce a histogram of time-from-delivery-to-click. A healthy one has a long right tail with a mode somewhere in the minutes-to-hours range. A contaminated one has a spike at zero.
Price on delivery where you can. Delivered impressions are the least corruptible unit in email because they are attested by the receiving mailbox provider rather than inferred from a beacon. If you must buy on clicks, agree in advance how scanner traffic is handled.
Measure at the far end. Your own analytics will not record scanner clicks as sessions, because scanners do not run your page scripts or persist state. The gap between reported clicks and landing page sessions is the single most useful diagnostic you have, and it costs nothing. Our guide to newsletter attribution without cookies covers how to close that loop properly.
Adjust expectations by audience type rather than treating all inventory as comparable. Business audiences will show a wider gap between recorded clicks and real sessions than consumer audiences will, for reasons that have nothing to do with the publisher's honesty. Judging them on the same benchmark punishes the better inventory. The industry figures in our 2026 benchmark data are more useful segmented this way.
If you are selling newsletter ads
Report valid and raw separately, before anyone asks. This is the single highest-return thing a publisher can do, and it is counterintuitive because it means voluntarily publishing a smaller headline number. The publisher who reports 300 valid clicks against 400 raw looks worse for exactly one meeting and better forever afterwards, because they are the only one in the process whose numbers reconcile with the advertiser's own analytics.
Know your corporate domain share. Run a distribution of your list by recipient domain. The proportion sitting on corporate mail rather than consumer providers is a decent proxy for your scanner exposure, and it is a number you should be able to state when a buyer asks why your click quality profile looks the way it does.
Do not let anyone sell you filtering you do not need. Newsletter inventory is not display inventory. If a vendor is quoting you display-market fraud rates, they are selling a solution to a problem you have in a much smaller quantity than they are implying.
Fix the incentivised-click habit if you have it. Asking readers to click sponsors as a favour feels supportive and it degrades the exact metric your renewals depend on. Sponsors who convert renew. Sponsors who get clicks that do not convert do not.
Model your revenue on valid counts. If your projections are built on raw clicks and your billing eventually settles on valid ones, you have a shortfall arriving later. The revenue calculator and sponsor delivery report are both easier to reason about once you have decided which denominator you are actually running the business on.
The uncomfortable summary
Most of the non-human activity in your newsletter ad reporting is not an attack. It is corporate IT departments doing their job, and the volume of it scales with exactly the audience quality that makes your inventory worth buying.
The industry response to this has mostly been silence, because the incentives point that way. Publishers do not want to publish a smaller number. Platforms do not want to explain a discrepancy. Advertisers frequently do not know to ask.
That silence is a temporary condition rather than a stable one. Machine reading of email is increasing on every axis at once, and the gap between what an ad platform reports and what an advertiser's own analytics show is getting wider each year. Whoever closes that gap first, voluntarily, gets to be the one whose numbers everybody trusts.
If you want to see what raw-versus-valid reporting looks like on your own inventory, you can start as a publisher or start as an advertiser. If you are running campaigns through an agency, the agency workflow covers how the reconciliation reporting works across multiple clients.
Frequently asked questions
Are bot clicks in email marketing the same as click fraud?
No, and conflating them causes bad decisions. The dominant source of non-human clicks in email is corporate security software following links to check them for phishing, which is benign and unavoidable. Click fraud is deliberate and, against newsletter inventory specifically, comparatively rare because the barrier to entry is much higher than it is for display or search. The response to each is completely different: you filter and price around scanners, you vet and enforce against fraud.
How can I tell if a click came from a security scanner?
Timing is the strongest single signal. A click recorded within a second or two of delivery is not a person, and reported scanner latency clusters around 0.4 seconds. Supporting signals include one recipient clicking every link in the message within the same second, clicks arriving with no corresponding open, and a source address belonging to cloud hosting infrastructure rather than a consumer or corporate ISP. Use at least two together before classifying anything, because each alone produces occasional false positives.
Does this affect B2B newsletters more than consumer newsletters?
Yes, substantially. Scanner clicks come from corporate email security, so exposure tracks the share of your subscribers reading at work rather than on personal accounts. A software or finance newsletter read predominantly at companies carries far more of this than a lifestyle newsletter read on personal Gmail. The awkward implication is that the inventory commanding the highest CPMs also carries the most measurement noise, and the two facts have the same cause.
Should I switch from CPC to CPM pricing because of this?
It removes the exposure, though it introduces a different question about which impression denominator you use. A delivered impression is a server-side fact attested by the receiving mailbox provider. An open-based impression is exposed to machine-reading inflation from privacy protection and assistant fetching. If you move to impression pricing, price against delivered sends rather than opens and you have closed both gaps at once.
Can I just block security scanners from clicking?
No, and you should not want to. The scanning happens between the mailbox provider and the recipient, outside anything you control, and it is a precondition of your mail being delivered to that organisation at all. Attempting to interfere with link scanning is a reliable way to have your messages rejected. The correct posture is measurement rather than prevention: identify the traffic, exclude it from billable counts, and report it separately.
What is the difference between GIVT and SIVT?
General invalid traffic is deterministic and identifiable from a single request: known bot user agents, datacenter origins, duplicate events, malformed parameters. It can be filtered in real time and should never be billed. Sophisticated invalid traffic requires statistical analysis across many events, is probabilistic by nature, and should therefore only be flagged post-serve and reconciled within a defined window rather than blocked live. The distinction determines what a platform is entitled to do with your money.
What should a publisher report to advertisers?
Both numbers, always: raw recorded activity and valid billable activity, with the difference explained. Publishing only the raw figure means your reporting will not reconcile with the advertiser's own analytics, and that discrepancy will eventually be discovered by someone who did not expect it. Publishing both costs you a smaller headline number once and buys you a reputation for numbers that hold up, which is the thing renewals are actually made of.
Stay ahead of the newsletter ad space
Get weekly articles on email monetisation, ad tech, and platform updates.
Subscribe + request demo →Editorial & Product
Related articles

Four Newsletters Capped at 3. Your Reader Saw It 11 Times.
Every publisher honoured the cap. The campaign report shows an average near three. A subscriber to all four newsletters saw the same ad eleven times, and nothing in standard reporting reveals it.

Q4 Newsletter Ad Pricing: The Flat-Rate Trap
Every pricing guide says raise Q4 rates 20-40%. None cover what happens to flat-rate deals when open rates fall in the same weeks — a $2,400 placement that quietly costs 31% more per reader on Black Friday week.

Ad Journeys: How to Run Drip Campaigns in Newsletter Ads
Most newsletter ads treat every reader the same. Ad Journeys change that — sequential native campaigns that follow subscribers across sends, building...
Ready to monetise your newsletter?
See how MailAdx fits your setup in a personalised 30-minute demo.