Skip to content
Back to blog
technical

Why mail scanners can break one-time password links

P
PassTransfer
Published March 1, 20223 min read

The unexpected interaction between security tools

One-time links and email security scanners have an unfortunate property: they work against each other. Understanding why helps you avoid a frustrating (and potentially dangerous) situation.

How email security scanners work

Corporate email environments, Microsoft 365, Google Workspace, and many email security products include URL scanning features. When an email arrives containing a link, the email security system automatically visits that URL. The purpose is to check whether the link leads to a malicious site, a phishing page, or malware.

This is a legitimate and useful security function. The problem is that it is invisible to both the sender and the recipient, and it visits the URL without the recipient's knowledge.

What happens when a scanner visits a one-time link

A one-time link is designed to be consumed exactly once. When the security scanner visits the link to check it, that visit counts as the first open. By the time the recipient clicks the link in their inbox, the secret has already been retrieved — by the scanner — and the link is now empty or shows an error.

The recipient sees "this link has already been opened" or "this secret no longer exists." They contact the sender, confused. The sender resends. This cycle can repeat if the scanner visits every resent link too.

Worse: the scanner has now retrieved the secret and the recipient never received it. Depending on the scanner's logging behaviour, the secret may now exist in the email security system's logs.

How to detect if this is happening

If recipients consistently report that one-time links are empty before they open them, a scanner is likely consuming the links. You can test this by sending a link to yourself via your work email system. If it shows as opened before you click it, a scanner is active.

Workarounds

Use a tool that detects scanner access: Some one-time link tools attempt to detect automated requests (using browser fingerprinting, JavaScript challenges, or IP reputation checks) and do not count scanner visits as a retrieval. PassTransfer uses such protections to mitigate this issue.

Deliver the link via a different channel: If email is causing scanner issues, deliver the one-time link via a channel that does not have URL scanning — a phone call reading out the URL, a QR code, or a messaging platform that does not scan links.

Separate the URL from the context: If you must use email, send the link without obvious context that would trigger scanning interest. A bare URL without surrounding text describing it as a "secure credential link" may be scanned with lower priority (though this is not reliable).

Communicate with your IT team: If you are in an environment where scanner consumption is a known issue, your IT team may be able to whitelist the one-time link tool's domain, ensuring scanner visits do not trigger link consumption.

The bigger picture

This is a genuine conflict between two security mechanisms. Email scanning protects against malicious links. One-time delivery protects against persistent credential exposure. Both are legitimate security controls.

The most reliable resolution is to use a one-time link tool that is aware of this interaction and handles it gracefully — either by ignoring scanner visits or by offering alternative delivery mechanisms for environments where scanning is aggressive.

Send a secure one-time link with PassTransfer →

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password