Non-Human Interactions
Your open rates jumped and your clicks do not convert. Those are not real subscribers. They are security scanners following every link in your email, and Apple pre-loading every tracking pixel before anyone reads a word. Marketers call these bot clicks and bot opens. The industry term is Non-Human Interactions (NHI), and the distinction matters more than it sounds.
Almost nobody goes looking for the term first. What people notice is that the numbers stopped making sense.
A campaign reports a 60% open rate. Nothing about the send explains it, the subject line was ordinary, and revenue did not move. Open rates have drifted upward across the industry for years without any matching change in what people actually do.
The click report shows healthy engagement and the landing page analytics do not agree. Sometimes every single link in one email is clicked within a few seconds of delivery, which no human reader has ever done.
A re-engagement series skips people who never engaged. A lead score rises on a contact who has not read anything. Sunset rules keep addresses alive because something looked active. Every downstream decision inherits the error.
A Non-Human Interaction (NHI) is an email open or click generated by software rather than by the recipient. The message arrives, something automated opens it or follows its links, and your tracking records that as engagement because from the tracking pixel's point of view it is indistinguishable from a person.
Most of it is not an attack. The largest contributors are security products doing the job they were bought for: a corporate email gateway receives a message, extracts every URL in it, and visits each one to check whether it leads to malware or a phishing page. That happens before the recipient sees the message, and often whether or not they ever open it. Apple Mail Privacy Protection does something similar to opens, pre-loading the tracking pixel in every message it delivers so that the sender cannot tell who read what.
So there are two vocabularies for one phenomenon. Marketers say bot clicks and bot opens, because that is what it looks like from inside a reporting dashboard. Deliverability specialists, email service providers and the standards bodies say Non-Human Interactions, because bot implies an adversary and most of this traffic has no adversary in it. Both descriptions point at the same events. Only one of them tells you what to do about it.
The name was settled inside M3AAWG, the Messaging, Malware and Mobile Anti-Abuse Working Group, which is the industry body where mailbox providers, senders and security vendors agree how email should work. Its Senders Committee published the document that put the term into circulation: Exploring the Impact of Nonhuman Interactions on Email Send Metrics (M3AAWG-136, November 2020).
Omnivery's founder was part of the M3AAWG Senders Committee group that produced the Non-Human Interactions white paper, and argued for the term "Non-Human Interactions" over "bots" on the grounds that most such traffic originates from legitimate security vendors rather than from abuse. That argument prevailed. NHI is now the term in industry-wide use, and the vocabulary carries the reasoning with it: if you call the traffic bots, the obvious response is to block it, and blocking a recipient's own security gateway means your mail does not arrive.
The document is worth reading for a second reason. Written in 2020, it recorded that B2C senders "generally experienced less than 10% impact" on their click metrics, with B2B senders seeing between 20% and 80% of clicks affected. Six years later, Omnivery's own first-party measurement puts roughly half of B2C opens and about 16% of B2C clicks in the non-human column. The standards body identified the problem early and understated what it would become, which is the honest shape of most emerging measurement problems.
Its conclusion has aged well: "Identification of such interactions is already very difficult to detect and will become nearly impossible in the future." That is the case for treating NHI classification as specialist infrastructure rather than something to bolt on with a rule list.
Four distinct sources, with different signatures and different implications. Only the last one is abuse.
Security software sits in front of the recipient's mailbox and inspects inbound mail. Following the links is how it establishes whether a URL is safe, so a single delivery can produce a click on every link in the message. Dozens of vendors are involved and it is not confined to enterprise mail: gateways such as Mimecast, Proofpoint, Barracuda and Microsoft Defender for Office 365 are the most recognizable, but Microsoft scans links well beyond Defender, and Gmail, Yahoo and effectively every large consumer mailbox provider do the same. This is the largest source of non-human clicks and the one you least want to interfere with.
Since iOS 15, Apple Mail routes image loading through Apple's own proxy and pre-loads tracking pixels regardless of whether the recipient opens the message. It is a privacy feature working as intended, and it accounts for more than 95% of the non-human opens Omnivery identifies in B2C sending. It affects opens only.
Deliverability seed lists, inbox placement monitors, competitive intelligence scrapers and link checkers all open messages and follow links as a matter of routine. Individually small, collectively persistent, and concentrated on exactly the addresses you use to judge whether a send went well.
Where email engagement is monetized, it attracts deliberate fraud. Newsletter ad networks are targeted by botnets using diverse residential IPs, plausible user agents and realistic timing to inflate advertiser billing. This is the smallest share of NHI in most sending, and the only part that is genuinely adversarial.
First-party findings from The State of Email Bots 2026, each drawn from a separate Omnivery dataset covering our own sending and the traffic screened by the Bot Detection API. For scale, the M3AAWG Senders Committee recorded B2C click impact as "generally less than 10%" in November 2020. Also available as a 10-page PDF.
The same phenomenon, arriving through different infrastructure. Treating one set of benchmarks as universal is how NHI gets misread.
| Criteria | B2C sending | B2B sending |
|---|---|---|
| Dominant source | Apple Mail Privacy Protection | Enterprise security gateways |
| Mostly affects | Opens | Clicks |
| Typical pattern | Pixel pre-loaded when an Apple device running Apple Mail is idle and on power, not at the moment of delivery | Varies with how advanced the gateway is: every link fetched at delivery, clicks scattered at random over hours or days, or the link intercepted at the moment the recipient clicks it |
| Malicious share | Higher where engagement is monetized | Low |
| M3AAWG 2020 finding | Generally under 10% of clicks impacted | Between 20% and 80% of clicks affected |
| Research study 2026 | ~50% of opens, 16% of clicks | Corporate and institutional recipient domains click 80-95% of the links they receive, and have done so since 2020 |
M3AAWG-136, Exploring the Impact of Nonhuman Interactions on Email Send Metrics, November 2020; Omnivery, The State of Email Bots 2026.
Apple MPP is a known actor. It uses published proxy infrastructure and a recognizable request signature, so the events it generates can be identified reliably. That is why the industry absorbed the open-rate problem relatively quickly after iOS 15: everyone could see the cause, and most platforms now filter at least the MPP portion.
The consequence is that a raw open rate is no longer a measurement of readership. It is a measurement of deliveries plus automation. Around half of B2C opens are non-human, and that share has not moved much since MPP arrived.
Clicks have no single actor. They come from hundreds of security vendors, each with its own infrastructure, plus tracking tools and botnets that are deliberately built to look human: residential IP ranges, current browser user agents, plausible intervals between actions.
This is where the trend is moving. B2C bot clicks went from about 2% in 2023 to about 16% in 2026, and half of the clicks screened by Omnivery's Bot Detection API were non-human by June 2026, up from 34% a year earlier. A click used to be the metric you could trust when the open rate went strange. That is no longer safe to assume.
The practical difference: filtering opens mostly restores a sane denominator. Filtering clicks changes decisions, because clicks drive segmentation, lead scoring, sunset rules and, where engagement is sold, revenue.
Fingerprint, Cloudflare, Akamai and Auth0 all do bot detection well. They do a different job, on a different kind of traffic, with a different definition of success. We wrote about this in detail in Why Web Bot Detection Fails for Email.
| Criteria | Web bot detection | Email NHI classification |
|---|---|---|
| Who the traffic is | An adversary probing your site | Your recipient's own security vendor |
| Correct response | Block, challenge or rate limit | Classify, never block |
| Signal available | A live session: JavaScript, headers, mouse and timing behavior | One event: IP, user agent, timestamp |
| Can you challenge it | Yes, a CAPTCHA is available | Possible, but difficult to implement and adds friction |
| Cost of a false positive | A visitor is inconvenienced | Higher churn and a worse customer experience |
| What it optimizes for | Keeping bad traffic out | Labeling all traffic correctly |
None of this involves blocking anything. The goal is a set of numbers that reflects what people did.
Report it if you like, but do not make decisions from it. If a platform gives you an MPP-adjusted open rate, that is the one to use, and it is still an estimate rather than a count.
A campaign-level correction factor spreads the error evenly across a list, which is exactly wrong: NHI concentrates on particular recipients and particular mailbox providers. Classification has to happen on the individual interaction, using the source IP, user agent and timing of that event.
Clicks feed segmentation, lead scoring, sunset rules and ad billing. A non-human click therefore causes a decision, whereas a non-human open mostly causes a bad report. Clicks are also the harder half, which is why rule-based filtering tends to stop at Apple MPP.
Sunset and re-engagement rules built on last activity will quietly keep addresses alive because a scanner touched them. M3AAWG flagged this in 2020 and it is still the most common way NHI damages a list rather than just a dashboard.
A documented M3AAWG finding: messages mixing secure and non-secure tracking links attract disproportionate unwanted attention. Consistent HTTPS reduces the amount of NHI a send provokes in the first place.
NHI correlates inversely with reputation. Senders with genuinely engaged recipients see measurably less of it, because gateways scan aggressively where they are least sure of the sender.
The Omnivery Bot Detection API returns a per-event verdict using 20+ proprietary datasets developed over 8+ years. It is included for Omnivery customers using Omnivery open and click tracking, and available as a standalone API for third-party tracking data.
A Non-Human Interaction is an email open or click generated by software rather than by the recipient. The main sources are corporate security gateways scanning links for malware and phishing, Apple Mail Privacy Protection pre-loading tracking pixels, inbox tracking and deliverability testing tools, and malicious botnets. NHI is the term established by the M3AAWG Senders Committee and now in industry-wide use. Marketers usually describe the same thing as bot opens and bot clicks.
Because a large share of those opens were never read by a person. Since Apple Mail Privacy Protection launched with iOS 15, Apple pre-loads the tracking pixel in every message it delivers whether or not the recipient opens it, and corporate security gateways do the same when they scan a message. Around 50% of the B2C opens Omnivery measures are non-human. An open rate is therefore the sum of real readers and Non-Human Interactions, with no way to separate them until each event is classified.
Bot clicks are link clicks recorded in your reporting that no person made. Most come from security software following every link in a message to check it for malware or phishing before the recipient sees it. Dozens of vendors do this rather than a handful: enterprise gateways such as Mimecast, Proofpoint, Barracuda and Microsoft Defender are the most recognizable, and Gmail, Yahoo and effectively every large consumer mailbox provider scan links too, so it is not an enterprise-only problem. A smaller share is deliberate fraud, such as botnets clicking newsletter ads to inflate advertiser billing. The industry term covering both is Non-Human Interactions. Omnivery measures B2C bot clicks at about 16% in 2026, up from about 2% in 2023.
Because bot implies abuse, and most of this traffic is not abusive. It is security software checking links. The term was settled in the M3AAWG Senders Committee, and Omnivery's founder was part of the group that produced the Non-Human Interactions white paper and argued for Non-Human Interactions over bots on the grounds that most such traffic originates from legitimate security vendors rather than from abuse. The document is Exploring the Impact of Nonhuman Interactions on Email Send Metrics, M3AAWG-136, published November 2020.
Web bot traffic means an adversary probing a website, and web bot detection exists to block or challenge it. NHI differs in origin and in the correct response: most of it comes from legitimate security vendors performing a service the recipient's employer paid for, so it cannot be blocked and has to be classified accurately instead. The available signal is different too. A website sees a live session and can run JavaScript or show a CAPTCHA; an email tracking event is a single record with an IP, a user agent and a timestamp.
Yes. Apple MPP routes opens through Apple's proxy infrastructure and pre-loads tracking pixels whether or not the recipient reads the message, so the resulting open was generated by software rather than by a person. It is the single largest source of non-human opens in B2C sending, accounting for more than 95% of the non-human opens Omnivery identifies there. MPP affects opens only. Non-human clicks come from security scanners, tracking tools and botnets instead.
You do not, and you should not try. The largest source is security infrastructure that your recipients' own employers pay for, so blocking it means your mail stops being delivered. The workable approach is classification rather than prevention: identify which interactions were non-human, then keep them out of the metrics, list hygiene decisions and automation triggers that would otherwise act on them. Two things do reduce how much NHI a send provokes: using HTTPS for every link, and maintaining a strong sender reputation.
Some of them. In B2C sending, roughly half the opens Omnivery measures are non-human and have been since Apple Mail Privacy Protection launched. In B2B the share varies much more widely, because it depends on the security stack in front of each recipient. An open rate on its own cannot tell you which is which. Classifying each event is what separates the two, and clicks now need the same treatment as opens, for different reasons.
No, and conflating them leads to the wrong response. Most NHI is benign automation from security vendors and tracking tools. A minority is deliberate fraud, and that minority concentrates where engagement is monetized: beehiiv, which screens over 60 million engagements a month through the Omnivery Bot Detection API, sees 30% of them classified as non-human with over 66% of those deemed malicious. That inverts the usual mix precisely because newsletter advertising pays out on clicks.
It depends on your audience and it concentrates rather than spreading evenly. Omnivery measures bot clicks at around 30% at Outlook against 2% to 4% at Yahoo and GMX, so a single blended figure hides most of what matters. In B2C, expect roughly half of opens and about 16% of clicks to be non-human. In B2B the range is much wider because it tracks whatever security products sit in front of your recipients.
Partly. Apple MPP opens are identifiable from published proxy infrastructure and a consistent request signature, which is why most platforms filter at least that. Clicks are the hard half: they come from hundreds of security vendors with changing infrastructure, plus botnets deliberately built to look human on residential IPs with current browser user agents. M3AAWG's own 2020 conclusion was that identifying these interactions is already very difficult and will become nearly impossible, which is the argument for data built for the problem rather than a rule list.
The Omnivery Bot Detection API returns a per-event verdict, is_bot true or false, using 20+ proprietary datasets developed over 8+ years, combining IP reputation, user agent analysis, behavioral pattern matching and honeypot data. It applies no blocking, no CAPTCHAs and no suppression. It is included at no extra charge for Omnivery customers using Omnivery open and click tracking, and available as a standalone API for third-party tracking data subject to vetting.
Non-Human Interactions are not going away, and the share of clicks they account for is still rising. The Omnivery Bot Detection API returns a verdict per event so your metrics, list hygiene and automation rest on what people actually did.