What we supply, and what you build
Datazag identifies the mail infrastructure for a recipient domain. The record names the mailbox platform and, where one is visible, the gateway in front of it. It also records what each vendor documents about URL inspection.
That tells you where automated URL interaction is plausible. It does not tell you which interactions a machine produced. You classify those from your own telemetry.
Four signals, each with a failure mode
No signal is conclusive alone. Combine them.
Timing relative to delivery
Automated interactions cluster near delivery. People act later. Timing is the cheapest signal, and you already hold it.
Fails when: A recipient with a push notification clicks within seconds. Or a product analyzes the message well after delivery.
Source network
A request from a security vendor's own infrastructure is strong evidence.
Fails when: The network belongs to a hyperscaler. Those networks carry scanners, corporate proxies and ordinary users alike.
User agent
Some scanners identify themselves.
Fails when: A product presents a desktop browser string. The absence of a bot string proves nothing.
TLS fingerprint
A request can claim to be a browser but use a handshake no browser produces. That mismatch is a reliable machine signal.
Fails when: You do not terminate TLS yourself. Behind most CDNs you will not see it.
What to log
Capture these fields for every pixel and link request:
- The token, resolving to recipient, send and link type
- The request timestamp, and the delivery timestamp to compare against
- The source IP address
- The full user-agent string
- The TLS fingerprint, where available
- The request method
- Whether redirects were followed
Store raw values. Classification rules will change. The telemetry will not.
Source provider networks from the vendor
Do not maintain a hand-written list of IP ranges. Take ranges from each vendor's published source, and refresh them on a schedule. Record the source and date of every entry.
Where a vendor publishes nothing, your own hidden-link data is the better source.
Pitfalls
- Frozen user-agent strings. Modern Apple platforms report a fixed OS version. Matching on it classifies large numbers of real people as machines.
- TLS version is not a machine signal. A JA4 fingerprint starts with the transport and TLS version. That says nothing about browser versus library. The signal is the mismatch between the claimed browser and its real handshake.
- Cloud networks are shared. Always combine source network with another signal.
- Analysis is often selective. A quiet domain is not evidence that its product never fetches.
- Two layers can act. A gateway in front of a mailbox platform puts two products on one delivery path.
- Client-side proxying is invisible to us. Image proxying by a mail app depends on the recipient's client, not their domain. No DNS observation reaches it. That part of machine engagement is yours to detect, not ours to predict.
The vendor documentation behind the classification →
Every product entry, what its vendor documents, the source and the date we reviewed it.
For ESPs: email intelligence under your brand.