8 of 32 product entries document pre-delivery URL retrieval or deeper analysis
This page records what vendors document. It does not record what happens to any particular message. Selection, licensing and policy decide that, and none of them is visible from outside.
Last reviewed
What this page establishes, and what it does not
- A documented capability is not an observation of behavior.
- Reputation checking creates no request to a sender's tracking domain. Retrieval and dynamic analysis can.
- Click-time documentation does not prove that a product never fetches links earlier.
- No entry can be inferred from an MX record. MX identifies infrastructure, not licensing or policy.
- No vendor in this review unambiguously documents fetching all links in a message.
- Attachment sandboxing is out of scope.
Four groups
These are product entries, not vendors or customer deployments. Some entries cover related product families. The list is not a complete market census.
What email security vendors document about URL inspection, by product
Filter by group, vendor or MX visibility. Each row links to the vendor page we reviewed.
| Product | Group | URL method | Scope | Delivery timing | MX visibility | Confidence | Source |
|---|---|---|---|---|---|---|---|
Targeted Attack Protection Proofpoint | Pre-delivery retrieval or deeper analysis documented | dynamic_selective | Suspicious or predicted URLs | Pre-delivery capability documented; policy and selection apply | Gateway visible in MX | high | Checked |
| Suspicious messages can be held for URL sandbox analysis before delivery. Selection is risk-based. TAP and the hold/sandbox configuration are required. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Essentials Proofpoint | Pre-delivery retrieval or deeper analysis documented | dynamic_selective | Suspicious URLs selected by predictive triggers | Pre-delivery capability documented; policy and selection apply | Gateway visible in MX | high | Checked |
| Predictive URL Defense automatically sandboxes selected links and blocks compromised messages before inbox delivery. Package entitlement matters. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
URL Protect / Targeted Threat Protection Mimecast | Pre-delivery retrieval or deeper analysis documented | deep_scan_selective | Higher-risk URLs | Pre-delivery capability documented; policy and selection apply | Gateway visible in MX | high | Checked |
| Risk-based pre-delivery deep scanning is documented. Destination retrieval is inferred from deep scanning, rather than an explicit HTTP-method statement. Hold is a documented default, not proof of any domain policy. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Mail Assure / SpamExperts N-able | Mechanism not established | not_documented | Not established | See evidence notes; pre-delivery completion not established | Gateway visible in MX | low | Checked |
| Reviewed virus-scanning documentation describes attachment protection and central analysis, but does not establish receipt-triggered URL fetching. Absence of documentation is not proof of absence. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Email Gateway Defense / Advanced Threat Protection Barracuda | Pre-delivery retrieval or deeper analysis documented | dynamic_selective | Publicly accessible direct-download links | Pre-delivery possible in specified configuration; may also occur after delivery | Gateway visible in MX | medium | Checked |
| ATP analyzes direct-download links in a secured cloud environment. Deliver First can complete analysis after delivery. Scan First documentation emphasizes attachments, so do not generalize to all body URLs or all delivery modes. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Advanced Threat Protection Hornetsecurity | Mechanism not established | scan_mechanism_unknown | Not established | See evidence notes; pre-delivery completion not established | Gateway visible in MX | medium | Checked |
| Vendor confirms pre-delivery URL scanning. The reviewed statement does not establish live destination retrieval or browser execution. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Core Advanced Email Threat Protection Zix / AppRiver (OpenText) | Click-time checking documented | click_time_documented | Rewritten links | Click-time documented; pre-delivery fetch unestablished | Gateway visible in MX | high | Checked |
| Official datasheet documents click-time destination analysis and attachment sandboxing. It does not establish pre-delivery body-link fetching. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Email Security (Virtual Analyzer) Trend Micro | Retrieval documented, timing unresolved | dynamic_selective | URLs selected by policy and security level | See evidence notes; pre-delivery completion not established | Depends on deployment | medium | Checked |
| Email Security supports URL submission to Virtual Analyzer separately from reputation and click-time checks. Quotas, exceptions and licensing apply. The reviewed URL-analysis page does not establish whether retrieval finishes before delivery. Do not extend this evidence automatically to Cloud App Security. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Email Sophos | Click-time checking documented | reputation_and_click_time | URLs covered by policy | Click-time documented; pre-delivery fetch unestablished | Depends on deployment | high | Checked |
| Delivery-time URL checks and click-time reputation-based protection are documented. These do not establish automatic destination fetching before delivery. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Secure Email (IronPort) Cisco | Retrieval documented, timing unresolved | fetch_selective | Selected URLs from suspicious messages | See evidence notes; pre-delivery completion not established | Depends on deployment | high | Checked |
| Talos explicitly crawls selected URLs and follows up to 19 redirects. Triggering occurs through Outbreak Filters even without quarantine. Completion before inbox delivery is not established. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
SpamTitan TitanHQ | Click-time checking documented | click_time_documented | Rewritten inbound links subject to exclusions | Click-time documented; pre-delivery fetch unestablished | Depends on deployment | high | Checked |
| Link Lock documents checking when clicked. SpamTitan Plus entitlement is required. This source does not establish pre-delivery retrieval. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Email Security.cloud Symantec / Broadcom | Retrieval documented, timing unresolved | fetch_scope_unknown | Links selected by Skeptic; current coverage unconfirmed | See evidence notes; pre-delivery completion not established | Gateway visible in MX | medium | Checked |
| Historical vendor guide documents live link following. The original current Broadcom page could not be retrieved. Do not retain the every-link claim or treat the 2015 guide as proof of current pre-delivery completion. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Mesh Mesh Security | Retrieval documented, timing unresolved | dynamic_selective | Links to unknown or suspicious objects | See evidence notes; pre-delivery completion not established | Depends on deployment | medium | Checked |
| Current vendor page goes beyond reputation feeds: it states that links to unknown or suspicious objects are sandboxed. The page does not establish exact delivery timing or fetch coverage. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
FortiMail Fortinet | Retrieval documented, timing unresolved | dynamic_configurable | All or unrated URIs; message selection and per-message cap | See evidence notes; pre-delivery completion not established | Depends on deployment | medium | Checked |
| FortiMail can submit URLs to FortiSandbox, with configurable selection and limits. This establishes URL sandbox capability but the reviewed URI settings do not establish pre-delivery completion for each deployment. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
URL Sandbox Libraesva | Click-time checking documented | click_time_dynamic | Rewritten links | Click-time documented; pre-delivery fetch unestablished | Depends on deployment | high | Checked |
| URLSand documents page inspection and redirect following at click time. Pre-delivery retrieval is not established. The vendor glossary says URL Sandbox is included in standard subscriptions; configuration still matters. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Protect / Secure Link mailinblack | Click-time checking documented | click_time_documented | Rewritten links | Click-time documented; pre-delivery fetch unestablished | Gateway visible in MX | high | Checked |
| Secure Link documents analysis when a recipient clicks. No pre-delivery destination fetch is established by the reviewed source. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Host mail filter Loopia | Mechanism not established | not_documented | Not established | See evidence notes; pre-delivery completion not established | Platform visible; feature is not | low | Checked |
| Hosting support describes spam-filter controls. It is insufficient to classify HTTP retrieval, URL sandboxing or click-time protection. Do not infer a specific network mechanism from generic spam filtering. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Defender for Office 365 Microsoft | Pre-delivery retrieval or deeper analysis documented | dynamic_selective | Eligible URLs covered by Safe Links policy; selected suspicious or insufficient-reputation URLs | Pre-delivery possible in specified configuration; may also occur after delivery | Platform visible; feature is not | high | Checked |
| Safe Links scans eligible URLs before delivery. Selected URLs can be detonated asynchronously. A policy can hold mail for real-time scanning or allow delivery before completion. Microsoft MX identifies hosting, not Defender licensing, recipient coverage or policy. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Workspace / Gmail Google | Click-time checking documented | click_time_documented | Links covered by Gmail client protection | Click-time documented; pre-delivery fetch unestablished | Platform visible; feature is not | high | Checked |
| Google documents click-time link protection. Extra pre-delivery security checks do not establish live retrieval of email-body URLs. Image proxying is a separate mechanism and is not evidence of link clicks. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Harmony Email & Collaboration (Avanan) Check Point | Retrieval documented, timing unresolved | receipt_scan_and_click_time_dynamic | Links covered by configured protection | See evidence notes; pre-delivery completion not established | Not visible in MX | medium | Checked |
| Avanan documents inspection at receipt, and URL emulation in the click-time engine. These statements alone do not prove that receipt-time inspection performs live retrieval. Downgraded from confirmed pre-delivery fetching. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Area 1 Email Security Cloudflare | Pre-delivery retrieval or deeper analysis documented | fetch_selective | URLs processed by the mail engine; exhaustive coverage not stated | Pre-delivery capability documented; policy and selection apply | Depends on deployment | high | Checked |
| Cloudflare explicitly describes URL fetching as part of mail delivery. This is distinct from proactive Internet crawling and click-time isolation. MX inference applies to MX-routed deployments only. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Advanced Email Security Perception Point | Pre-delivery retrieval or deeper analysis documented | dynamic_browser | URLs selected by the multilayer analysis pipeline | Pre-delivery capability documented; policy and selection apply | Not visible in MX | high | Checked |
| Vendor describes pre-inbox protection with dynamic URL browsing and emulation of following links and clicking. Scanning all email content does not prove that every URL is fetched on every message. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
INKY Email Security INKY | Click-time checking documented | click_time_documented | Rewritten incoming links | Click-time documented; pre-delivery fetch unestablished | Not visible in MX | high | Checked |
| INKY documents deep analysis and redirect following on click. This establishes click-time retrieval, not automatic pre-delivery fetching. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
VIPRE Email Security VIPRE Security Group | Click-time checking documented | click_time_documented | Rewritten URLs subject to policy and exclusions | Click-time documented; pre-delivery fetch unestablished | Gateway visible in MX | high | Checked |
| Vendor support documents URL rewriting and rescanning on each click. Pre-delivery destination retrieval is not established. Replaces the reseller citation as primary evidence. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
MailMarshal Trustwave / LevelBlue | Click-time checking documented | click_time_documented | HTTP/HTTPS URLs covered by rewrite rules | Click-time documented; pre-delivery fetch unestablished | Depends on deployment | high | Checked |
| Vendor support describes Blended Threats URL rewriting and analysis when clicked. MailMarshal may run under customer-owned gateway hostnames, so MX vendor identification is conditional. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
SonicWall Email Security SonicWall | Click-time checking documented | click_time_documented | Rewritten links | Click-time documented; pre-delivery fetch unestablished | Depends on deployment | medium | Checked |
| Official Email Security release notes list time-of-click URL protection. No pre-delivery body-link retrieval is established. Appliance installations may use customer-owned MX names. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Kaspersky Secure Mail Gateway Kaspersky | Mechanism not established | reputation_documented | URL and IP reputation | See evidence notes; pre-delivery completion not established | Depends on deployment | high | Checked |
| The vendor describes URL/IP reputation filtering. KATA integration and attachment sandboxing do not alone establish live body-URL retrieval. Removed unsupported fetch_selective classification. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Abnormal Email Protection Abnormal AI (formerly Abnormal Security) | Mechanism not established | mechanism_not_established | Not established for receipt-time retrieval | See evidence notes; pre-delivery completion not established | Not visible in MX | medium | Checked |
| Original citation was a different vendor and did not prove fetching. Abnormal now documents URL rewriting and click-event reporting, so the original no-rewriting claim is also unsafe. Receipt-time live retrieval remains unestablished. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Ironscales Email Protection Ironscales | Mechanism not established | mechanism_not_established | Not established | See evidence notes; pre-delivery completion not established | Not visible in MX | low | Checked |
| Official material describes continuous link monitoring but does not establish the original all-link rewriting claim or exact fetch timing. Replaced the third-party ranking source and removed unsupported certainty. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Sublime Platform Sublime Security | Pre-delivery retrieval or deeper analysis documented | dynamic_selective | Suspicious links selected by LinkAnalysis rules and mode | Pre-delivery possible in specified configuration; may also occur after delivery | Not visible in MX | high | Checked |
| LinkAnalysis sends selected URLs to a headless browser. Aggressive mode can issue HEAD requests to common click trackers. Default deployment is post-delivery; optional inline protection completes analysis pre-delivery without MX changes. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Email Security / Advanced URL Defense (FireEye) Trellix / FireEye | Retrieval documented, timing unresolved | dynamic_selective | Unknown suspicious URLs | See evidence notes; pre-delivery completion not established | Depends on deployment | high | Checked |
| Trellix Advanced URL Defense performs live site analysis on selected suspicious URLs. Vendor workflow explicitly allows inline mail delivery with rewritten URLs while analysis runs. Add as a documented machine-interaction source with timing caveat, not an unconditional pre-delivery fetcher. Machine-click implication: Can produce automated requests when analysis visits a tracking URL; a recorded ESP click is not guaranteed. | |||||||
Defend (formerly Egress Defend) KnowBe4 / Egress | Mechanism not established | receipt_scan_mechanism_ambiguous | Links inspected at receipt and click | See evidence notes; pre-delivery completion not established | Not visible in MX | medium | Checked |
| KnowBe4 Defend (formerly Egress) documents receipt-time and click-time scanning, including redirect-hop checks. This suggests network interaction but does not explicitly establish receipt-time HTTP fetching or sandboxing. Retain as an ambiguous candidate. Machine-click implication: Reviewed evidence does not establish automatic pre-delivery machine clicks; unknown does not mean never. | |||||||
Method and download
Every entry comes from the vendor's own public documentation. Each row carries its source URL and the date we reviewed it. The CSV holds every field we recorded, including our original classifications for comparison.
Download machine-clicks-vendor-evidence-v1.csv
Permitted use: you may use, share and adapt this file. Credit "Datazag Observatory" and link to this page.
Maintenance
Vendor documentation changes without notice. We re-check every entry at least once a quarter. Each row shows the date we last checked it. A row not re-checked within a year is marked as due.
Correct an entry
Vendors can correct their own entry. Email corrections@datazag.com with the product and a link to your published documentation.
- We acknowledge your message within two working days.
- We review the correction against your own published documentation.
- Where it holds, we update the row, refresh its checked date and record the change below.
- Where the documentation is ambiguous, we say so on the row rather than pick a side.
Change log
| Date | Change | Raised by |
|---|---|---|
| 2026-10-01 | First published. Every entry was reviewed against primary vendor sources. | Datazag review |