QA unsubscribe, sign-in and purchase links without triggering them
Clicking through a test send can unsubscribe your test address or fire a real account action. SendProofs recognizes action-bearing links before any request is made, marks them Protected, never opens them, and lists them in the report so your review covers them deliberately — on your terms, not by accident.
How it works
-
Upload the delivered test email
The
.emlfile you save from your own inbox — works with an email saved from Gmail, Outlook on the web or Apple Mail. Every link and remote image is extracted from the message that actually arrived. -
Every URL is classified before any request leaves
URL and link-text patterns recognize unsubscribe and preference-center links, sign-in, sign-out and password-reset links including magic links, verification and invitation accepts, and order, purchase, approval, cancellation, deletion and access-revoking actions. Recognized links are marked Protected and are never requested.
-
Classification repeats on every redirect hop
Ordinary links get bounded checks with HTTP redirects followed up to 3 hops. If a hop redirects toward a recognized action destination, the check stops at that hop and the resource is marked Protected — the redirect is not followed into the action.
-
Protected items appear in the report marked "Not opened"
Each one comes with a manual-review prompt, so the sensitive links in your campaign are a visible checklist for you instead of an invisible risk.
What the states mean here
- Protected
- Recognized as action-bearing — or a likely tracking pixel — and never requested. Shown "Not opened" in the report — this is your deliberate manual-review list.
- Healthy
- An ordinary link whose destination answered 2xx with no warnings. No action.
- Broken
- An ordinary link that failed a deterministic check. Fix it in your sending platform, send a fresh test, recheck.
- Inconclusive
- The destination limited automated access (401/403/429). Neither a pass nor a failure — review it manually.
| Resource | State | Evidence |
|---|---|---|
| campaign.example/launch?utm_source=email&utm_campaign=aug-launch | Healthy | 200 after 2 redirects · 312 ms · 14:02 UTC |
| example.com/unsubscribe/%5BREDACTED%5D | Protected | Not opened — review manually |
| app.campaign.example/login?next=%5BREDACTED%5D | Protected | Not opened — review manually |
| img.campaign.example/open/%5BREDACTED%5D.gif | Protected | Not opened — review manually |
Sample data — the 3 Protected items from the 24-resource August launch sample run. In this sample all three were recognized at upload, so none consumed a check. (A link that turns Protected mid-redirect was attempted, and that attempt consumes one check.)
What still needs a human
Detection is pattern-based, on English keywords in URLs, query parameters and link text. That catches the common cases decisively, but it is not a guarantee that every action link is caught — a bare tokenized path with no recognizable words, or a non-English unsubscribe path, can be classified as an ordinary link and checked. Your own review of the sensitive links still matters; the Protected list is a strong assist for it, not a substitute.
Opening a protected link is a human step by design. Do it deliberately and in a controlled way: right before send, from your own test message, knowing the click is real — an unsubscribe click really unsubscribes your test address, an approval link really approves. Confirm the page loads, reads correctly and points at the right list or account, then undo what the click did before it matters.
The same discipline applies to the ordinary links around them: an automated 200 is evidence that a destination answered at check time — on its own it does not prove the campaign is correct.
Related
Unsubscribe, sign-in, reset and purchase links are identified before any request and never opened. SendProofs lists them for your manual review instead.
Pre-send QA checklistA practical checklist for the last hour before a campaign send: delivered-test checks, tracking review and protected-action review.
Get the protected list for your next campaign
Upload the delivered test — recognized action links are listed unopened in every report.