Which email security products document fetching links before delivery?

8 of 32 product entries document pre-delivery URL retrieval or deeper analysis

This page records what vendors document. It does not record what happens to any particular message. Selection, licensing and policy decide that, and none of them is visible from outside.

Last reviewed

What this page establishes, and what it does not

  • A documented capability is not an observation of behavior.
  • Reputation checking creates no request to a sender's tracking domain. Retrieval and dynamic analysis can.
  • Click-time documentation does not prove that a product never fetches links earlier.
  • No entry can be inferred from an MX record. MX identifies infrastructure, not licensing or policy.
  • No vendor in this review unambiguously documents fetching all links in a message.
  • Attachment sandboxing is out of scope.

Four groups

These are product entries, not vendors or customer deployments. Some entries cover related product families. The list is not a complete market census.

What email security vendors document about URL inspection, by product

Filter by group, vendor or MX visibility. Each row links to the vendor page we reviewed.

32 of 32 shown
ProductGroupURL methodScopeDelivery timingMX visibilityConfidenceSource
Targeted Attack Protection
Proofpoint
Pre-delivery retrieval or deeper analysis documenteddynamic_selectiveSuspicious or predicted URLsPre-delivery capability documented; policy and selection applyGateway visible in MXhigh
Checked
Suspicious messages can be held for URL sandbox analysis before delivery. Selection is risk-based. TAP and the hold/sandbox configuration are required. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Essentials
Proofpoint
Pre-delivery retrieval or deeper analysis documenteddynamic_selectiveSuspicious URLs selected by predictive triggersPre-delivery capability documented; policy and selection applyGateway visible in MXhigh
Checked
Predictive URL Defense automatically sandboxes selected links and blocks compromised messages before inbox delivery. Package entitlement matters. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
URL Protect / Targeted Threat Protection
Mimecast
Pre-delivery retrieval or deeper analysis documenteddeep_scan_selectiveHigher-risk URLsPre-delivery capability documented; policy and selection applyGateway visible in MXhigh
Checked
Risk-based pre-delivery deep scanning is documented. Destination retrieval is inferred from deep scanning, rather than an explicit HTTP-method statement. Hold is a documented default, not proof of any domain policy. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Mail Assure / SpamExperts
N-able
Mechanism not establishednot_documentedNot establishedSee evidence notes; pre-delivery completion not establishedGateway visible in MXlow
Checked
Reviewed virus-scanning documentation describes attachment protection and central analysis, but does not establish receipt-triggered URL fetching. Absence of documentation is not proof of absence. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Email Gateway Defense / Advanced Threat Protection
Barracuda
Pre-delivery retrieval or deeper analysis documenteddynamic_selectivePublicly accessible direct-download linksPre-delivery possible in specified configuration; may also occur after deliveryGateway visible in MXmedium
Checked
ATP analyzes direct-download links in a secured cloud environment. Deliver First can complete analysis after delivery. Scan First documentation emphasizes attachments, so do not generalize to all body URLs or all delivery modes. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Advanced Threat Protection
Hornetsecurity
Mechanism not establishedscan_mechanism_unknownNot establishedSee evidence notes; pre-delivery completion not establishedGateway visible in MXmedium
Checked
Vendor confirms pre-delivery URL scanning. The reviewed statement does not establish live destination retrieval or browser execution. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Core Advanced Email Threat Protection
Zix / AppRiver (OpenText)
Click-time checking documentedclick_time_documentedRewritten linksClick-time documented; pre-delivery fetch unestablishedGateway visible in MXhigh
Checked
Official datasheet documents click-time destination analysis and attachment sandboxing. It does not establish pre-delivery body-link fetching. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Email Security (Virtual Analyzer)
Trend Micro
Retrieval documented, timing unresolveddynamic_selectiveURLs selected by policy and security levelSee evidence notes; pre-delivery completion not establishedDepends on deploymentmedium
Checked
Email Security supports URL submission to Virtual Analyzer separately from reputation and click-time checks. Quotas, exceptions and licensing apply. The reviewed URL-analysis page does not establish whether retrieval finishes before delivery. Do not extend this evidence automatically to Cloud App Security. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Email
Sophos
Click-time checking documentedreputation_and_click_timeURLs covered by policyClick-time documented; pre-delivery fetch unestablishedDepends on deploymenthigh
Checked
Delivery-time URL checks and click-time reputation-based protection are documented. These do not establish automatic destination fetching before delivery. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Secure Email (IronPort)
Cisco
Retrieval documented, timing unresolvedfetch_selectiveSelected URLs from suspicious messagesSee evidence notes; pre-delivery completion not establishedDepends on deploymenthigh
Checked
Talos explicitly crawls selected URLs and follows up to 19 redirects. Triggering occurs through Outbreak Filters even without quarantine. Completion before inbox delivery is not established. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
SpamTitan
TitanHQ
Click-time checking documentedclick_time_documentedRewritten inbound links subject to exclusionsClick-time documented; pre-delivery fetch unestablishedDepends on deploymenthigh
Checked
Link Lock documents checking when clicked. SpamTitan Plus entitlement is required. This source does not establish pre-delivery retrieval. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Email Security.cloud
Symantec / Broadcom
Retrieval documented, timing unresolvedfetch_scope_unknownLinks selected by Skeptic; current coverage unconfirmedSee evidence notes; pre-delivery completion not establishedGateway visible in MXmedium
Checked
Historical vendor guide documents live link following. The original current Broadcom page could not be retrieved. Do not retain the every-link claim or treat the 2015 guide as proof of current pre-delivery completion. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Mesh
Mesh Security
Retrieval documented, timing unresolveddynamic_selectiveLinks to unknown or suspicious objectsSee evidence notes; pre-delivery completion not establishedDepends on deploymentmedium
Checked
Current vendor page goes beyond reputation feeds: it states that links to unknown or suspicious objects are sandboxed. The page does not establish exact delivery timing or fetch coverage. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
FortiMail
Fortinet
Retrieval documented, timing unresolveddynamic_configurableAll or unrated URIs; message selection and per-message capSee evidence notes; pre-delivery completion not establishedDepends on deploymentmedium
Checked
FortiMail can submit URLs to FortiSandbox, with configurable selection and limits. This establishes URL sandbox capability but the reviewed URI settings do not establish pre-delivery completion for each deployment. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
URL Sandbox
Libraesva
Click-time checking documentedclick_time_dynamicRewritten linksClick-time documented; pre-delivery fetch unestablishedDepends on deploymenthigh
Checked
URLSand documents page inspection and redirect following at click time. Pre-delivery retrieval is not established. The vendor glossary says URL Sandbox is included in standard subscriptions; configuration still matters. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Protect / Secure Link
mailinblack
Click-time checking documentedclick_time_documentedRewritten linksClick-time documented; pre-delivery fetch unestablishedGateway visible in MXhigh
Checked
Secure Link documents analysis when a recipient clicks. No pre-delivery destination fetch is established by the reviewed source. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Host mail filter
Loopia
Mechanism not establishednot_documentedNot establishedSee evidence notes; pre-delivery completion not establishedPlatform visible; feature is notlow
Checked
Hosting support describes spam-filter controls. It is insufficient to classify HTTP retrieval, URL sandboxing or click-time protection. Do not infer a specific network mechanism from generic spam filtering. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Defender for Office 365
Microsoft
Pre-delivery retrieval or deeper analysis documenteddynamic_selectiveEligible URLs covered by Safe Links policy; selected suspicious or insufficient-reputation URLsPre-delivery possible in specified configuration; may also occur after deliveryPlatform visible; feature is nothigh
Checked
Safe Links scans eligible URLs before delivery. Selected URLs can be detonated asynchronously. A policy can hold mail for real-time scanning or allow delivery before completion. Microsoft MX identifies hosting, not Defender licensing, recipient coverage or policy. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Workspace / Gmail
Google
Click-time checking documentedclick_time_documentedLinks covered by Gmail client protectionClick-time documented; pre-delivery fetch unestablishedPlatform visible; feature is nothigh
Checked
Google documents click-time link protection. Extra pre-delivery security checks do not establish live retrieval of email-body URLs. Image proxying is a separate mechanism and is not evidence of link clicks. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Harmony Email & Collaboration (Avanan)
Check Point
Retrieval documented, timing unresolvedreceipt_scan_and_click_time_dynamicLinks covered by configured protectionSee evidence notes; pre-delivery completion not establishedNot visible in MXmedium
Checked
Avanan documents inspection at receipt, and URL emulation in the click-time engine. These statements alone do not prove that receipt-time inspection performs live retrieval. Downgraded from confirmed pre-delivery fetching. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Area 1 Email Security
Cloudflare
Pre-delivery retrieval or deeper analysis documentedfetch_selectiveURLs processed by the mail engine; exhaustive coverage not statedPre-delivery capability documented; policy and selection applyDepends on deploymenthigh
Checked
Cloudflare explicitly describes URL fetching as part of mail delivery. This is distinct from proactive Internet crawling and click-time isolation. MX inference applies to MX-routed deployments only. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Advanced Email Security
Perception Point
Pre-delivery retrieval or deeper analysis documenteddynamic_browserURLs selected by the multilayer analysis pipelinePre-delivery capability documented; policy and selection applyNot visible in MXhigh
Checked
Vendor describes pre-inbox protection with dynamic URL browsing and emulation of following links and clicking. Scanning all email content does not prove that every URL is fetched on every message. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
INKY Email Security
INKY
Click-time checking documentedclick_time_documentedRewritten incoming linksClick-time documented; pre-delivery fetch unestablishedNot visible in MXhigh
Checked
INKY documents deep analysis and redirect following on click. This establishes click-time retrieval, not automatic pre-delivery fetching. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
VIPRE Email Security
VIPRE Security Group
Click-time checking documentedclick_time_documentedRewritten URLs subject to policy and exclusionsClick-time documented; pre-delivery fetch unestablishedGateway visible in MXhigh
Checked
Vendor support documents URL rewriting and rescanning on each click. Pre-delivery destination retrieval is not established. Replaces the reseller citation as primary evidence. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
MailMarshal
Trustwave / LevelBlue
Click-time checking documentedclick_time_documentedHTTP/HTTPS URLs covered by rewrite rulesClick-time documented; pre-delivery fetch unestablishedDepends on deploymenthigh
Checked
Vendor support describes Blended Threats URL rewriting and analysis when clicked. MailMarshal may run under customer-owned gateway hostnames, so MX vendor identification is conditional. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
SonicWall Email Security
SonicWall
Click-time checking documentedclick_time_documentedRewritten linksClick-time documented; pre-delivery fetch unestablishedDepends on deploymentmedium
Checked
Official Email Security release notes list time-of-click URL protection. No pre-delivery body-link retrieval is established. Appliance installations may use customer-owned MX names. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Kaspersky Secure Mail Gateway
Kaspersky
Mechanism not establishedreputation_documentedURL and IP reputationSee evidence notes; pre-delivery completion not establishedDepends on deploymenthigh
Checked
The vendor describes URL/IP reputation filtering. KATA integration and attachment sandboxing do not alone establish live body-URL retrieval. Removed unsupported fetch_selective classification. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Abnormal Email Protection
Abnormal AI (formerly Abnormal Security)
Mechanism not establishedmechanism_not_establishedNot established for receipt-time retrievalSee evidence notes; pre-delivery completion not establishedNot visible in MXmedium
Checked
Original citation was a different vendor and did not prove fetching. Abnormal now documents URL rewriting and click-event reporting, so the original no-rewriting claim is also unsafe. Receipt-time live retrieval remains unestablished. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Ironscales Email Protection
Ironscales
Mechanism not establishedmechanism_not_establishedNot establishedSee evidence notes; pre-delivery completion not establishedNot visible in MXlow
Checked
Official material describes continuous link monitoring but does not establish the original all-link rewriting claim or exact fetch timing. Replaced the third-party ranking source and removed unsupported certainty. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Sublime Platform
Sublime Security
Pre-delivery retrieval or deeper analysis documenteddynamic_selectiveSuspicious links selected by LinkAnalysis rules and modePre-delivery possible in specified configuration; may also occur after deliveryNot visible in MXhigh
Checked
LinkAnalysis sends selected URLs to a headless browser. Aggressive mode can issue HEAD requests to common click trackers. Default deployment is post-delivery; optional inline protection completes analysis pre-delivery without MX changes. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Email Security / Advanced URL Defense (FireEye)
Trellix / FireEye
Retrieval documented, timing unresolveddynamic_selectiveUnknown suspicious URLsSee evidence notes; pre-delivery completion not establishedDepends on deploymenthigh
Checked
Trellix Advanced URL Defense performs live site analysis on selected suspicious URLs. Vendor workflow explicitly allows inline mail delivery with rewritten URLs while analysis runs. Add as a documented machine-interaction source with timing caveat, not an unconditional pre-delivery fetcher. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed.
Defend (formerly Egress Defend)
KnowBe4 / Egress
Mechanism not establishedreceipt_scan_mechanism_ambiguousLinks inspected at receipt and clickSee evidence notes; pre-delivery completion not establishedNot visible in MXmedium
Checked
KnowBe4 Defend (formerly Egress) documents receipt-time and click-time scanning, including redirect-hop checks. This suggests network interaction but does not explicitly establish receipt-time HTTP fetching or sandboxing. Retain as an ambiguous candidate. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never.
Source: Datazagas of 2026-10-0132 product entries

Method and download

Every entry comes from the vendor's own public documentation. Each row carries its source URL and the date we reviewed it. The CSV holds every field we recorded, including our original classifications for comparison.

Download machine-clicks-vendor-evidence-v1.csv

Permitted use: you may use, share and adapt this file. Credit "Datazag Observatory" and link to this page.

Maintenance

Vendor documentation changes without notice. We re-check every entry at least once a quarter. Each row shows the date we last checked it. A row not re-checked within a year is marked as due.

Correct an entry

Vendors can correct their own entry. Email corrections@datazag.com with the product and a link to your published documentation.

  1. We acknowledge your message within two working days.
  2. We review the correction against your own published documentation.
  3. Where it holds, we update the row, refresh its checked date and record the change below.
  4. Where the documentation is ambiguous, we say so on the row rather than pick a side.

Change log

DateChangeRaised by
2026-10-01First published. Every entry was reviewed against primary vendor sources.Datazag review