Solution

QA unsubscribe, sign-in and purchase links without triggering them

Clicking through a test send can unsubscribe your test address or fire a real account action. SendProofs recognizes action-bearing links before any request is made, marks them Protected, never opens them, and lists them in the report so your review covers them deliberately — on your terms, not by accident.

How it works

  1. Upload the delivered test email

    The .eml file you save from your own inbox — works with an email saved from Gmail, Outlook on the web or Apple Mail. Every link and remote image is extracted from the message that actually arrived.

  2. Every URL is classified before any request leaves

    URL and link-text patterns recognize unsubscribe and preference-center links, sign-in, sign-out and password-reset links including magic links, verification and invitation accepts, and order, purchase, approval, cancellation, deletion and access-revoking actions. Recognized links are marked Protected and are never requested.

  3. Classification repeats on every redirect hop

    Ordinary links get bounded checks with HTTP redirects followed up to 3 hops. If a hop redirects toward a recognized action destination, the check stops at that hop and the resource is marked Protected — the redirect is not followed into the action.

  4. Protected items appear in the report marked "Not opened"

    Each one comes with a manual-review prompt, so the sensitive links in your campaign are a visible checklist for you instead of an invisible risk.

What the states mean here

Protected
Recognized as action-bearing — or a likely tracking pixel — and never requested. Shown "Not opened" in the report — this is your deliberate manual-review list.
Healthy
An ordinary link whose destination answered 2xx with no warnings. No action.
Broken
An ordinary link that failed a deterministic check. Fix it in your sending platform, send a fresh test, recheck.
Inconclusive
The destination limited automated access (401/403/429). Neither a pass nor a failure — review it manually.
Sample data Protected items, with one ordinary link, from the August launch sample run
ResourceStateEvidence
campaign.example/launch?utm_source=email&utm_campaign=aug-launch Healthy 200 after 2 redirects · 312 ms · 14:02 UTC
example.com/unsubscribe/%5BREDACTED%5D Protected Not opened — review manually
app.campaign.example/login?next=%5BREDACTED%5D Protected Not opened — review manually
img.campaign.example/open/%5BREDACTED%5D.gif Protected Not opened — review manually

Sample data — the 3 Protected items from the 24-resource August launch sample run. In this sample all three were recognized at upload, so none consumed a check. (A link that turns Protected mid-redirect was attempted, and that attempt consumes one check.)

What still needs a human

Detection is pattern-based, on English keywords in URLs, query parameters and link text. That catches the common cases decisively, but it is not a guarantee that every action link is caught — a bare tokenized path with no recognizable words, or a non-English unsubscribe path, can be classified as an ordinary link and checked. Your own review of the sensitive links still matters; the Protected list is a strong assist for it, not a substitute.

Opening a protected link is a human step by design. Do it deliberately and in a controlled way: right before send, from your own test message, knowing the click is real — an unsubscribe click really unsubscribes your test address, an approval link really approves. Confirm the page loads, reads correctly and points at the right list or account, then undo what the click did before it matters.

The same discipline applies to the ordinary links around them: an automated 200 is evidence that a destination answered at check time — on its own it does not prove the campaign is correct.

Get the protected list for your next campaign

Upload the delivered test — recognized action links are listed unopened in every report.

Create workspace