How do HTTP tracking links affect email deliverability and user experience?

Summary

Using HTTP tracking links negatively impacts email deliverability, user experience, and security. Subscribers encounter security warnings and mixed content issues, leading to distrust and potential abandonment. Email providers may block or filter content with non-HTTPS links, reducing deliverability. HTTP links signal a lack of security and can harm sender reputation. Conversely, HTTPS builds trust, improves SEO, and signals credibility to email providers, improving inbox placement. HTTP exposes users to man-in-the-middle attacks and other security threats. Redirects and tracking parameters must lead to HTTPS destinations. Protecting PII over HTTPS is crucial.

Key findings

  • Security Warnings and Mixed Content: HTTP links trigger security warnings and mixed content errors, deterring user engagement.
  • Deliverability and Reputation: HTTP links harm sender reputation and decrease email deliverability rates.
  • Trust and Credibility: HTTPS enhances user trust and signals credibility, improving engagement and inbox placement.
  • SEO Impact: HTTPS improves SEO ranking, while HTTP negatively impacts search engine visibility.
  • Security Vulnerabilities: HTTP exposes users to man-in-the-middle attacks, eavesdropping, and data theft.
  • Impact of Redirects: If you are using redirects, the final destination must be HTTPS to not negate any security gains.

Key considerations

  • Implement HTTPS Across All Links: Transition all links, including tracking links, to HTTPS to avoid security issues and improve deliverability.
  • Secure Redirects: Ensure redirects and tracking parameters lead to HTTPS destinations.
  • Protect Sensitive Information: Use HTTPS to protect personally identifiable information (PII) and other sensitive data.
  • Monitor Reputation: Check your sending domain reputation for issues.
  • Review tracking links: Check third party link tracking providers as issues might exist there.

What email marketers say
14Marketer opinions

Using HTTP tracking links in emails, especially when the main website is HTTPS, negatively impacts both deliverability and user experience. Subscribers may encounter security warnings and mixed content errors, leading to distrust and potential abandonment. Email providers may block content with non-HTTPS links or flag emails as spam. Conversely, using HTTPS builds user trust, improves SEO ranking, and signals credibility to email providers, improving inbox placement. Not using HTTPS can also put visitors at risk of man-in-the-middle attacks.

Key opinions

  • Security Warnings: HTTP links trigger security warnings in browsers, deterring users from clicking and reducing conversions.
  • Mixed Content: Using HTTP links on HTTPS sites causes mixed content warnings, negatively impacting user experience and potentially blocking content.
  • Deliverability Issues: Email providers may block or filter emails containing HTTP links due to security concerns, reducing deliverability.
  • Trust and Credibility: HTTPS links build user trust and signal credibility to email providers, positively influencing user engagement and inbox placement.
  • SEO Impact: Using HTTPS is crucial for SEO, as Google prioritizes secure sites. HTTP links can negatively impact search engine rankings.
  • Security Risk: Non-HTTPS traffic increases the risk of man-in-the-middle attacks, potentially compromising user data.

Key considerations

  • SSL Certificates: Ensure you have valid SSL certificates to establish trust and avoid browser security warnings.
  • HTTPS Implementation: Transition all links, including tracking links, to HTTPS to avoid mixed content issues and deliverability problems.
  • User Experience: Prioritize a seamless user experience by ensuring links are secure and trustworthy, reducing friction and increasing engagement.
  • Reputation Management: Monitor and maintain your sender reputation by using secure practices to avoid being flagged as spam.
  • Compliance: Ensure that your email marketing practices adhere to security standards to protect user data.
Marketer view

Marketer from Email Geeks disagrees with the notion that it's not an issue unless submitting PII. Explains if the traffic isn't secured by encryption that could put the visitor at the risk of a man-in-the middle attack where something malicious ends up on their machine.

December 2021 - Email Geeks
Marketer view

Email marketer from Cloudflare Blog explains that using HTTP links on HTTPS sites causes mixed content warnings, which negatively impact user experience and security. Browsers may block insecure content, hindering site functionality.

March 2024 - Cloudflare Blog
Marketer view

Email marketer from Neil Patel's Blog explains that HTTPS is crucial for SEO ranking as Google prioritizes secure sites. HTTPS also builds user trust and confidence by protecting sensitive information.

July 2022 - Neil Patel's Blog
Marketer view

Marketer from Email Geeks explains that subscribers might see a message about an unsecure link, leading them to either go back or click "Advanced" to proceed. This is unless they have security settings turned off. They also ask if a third-party link tracker is being used.

October 2021 - Email Geeks
Marketer view

Marketer from Email Geeks shares that mailbox providers may block content with non-HTTPS links, especially concerning for B2B senders and corporate spam filters, but also a concern for consumer mail.

July 2023 - Email Geeks
Marketer view

Email marketer from EmailToolTester shares that using HTTP links can make your site appear outdated and less trustworthy, leading to reduced conversions and increased bounce rates. Security is a very important part of email marketing.

July 2022 - EmailToolTester
Marketer view

Email marketer from Reddit shares that emails containing only HTTP links, including tracking pixels, will trigger some spam filters since most modern email systems now require HTTPS for secure data transmission.

April 2024 - Reddit
Marketer view

Email marketer from EmailGeeks forum mentions that mixed content issues due to HTTP links on HTTPS pages can lead to warnings and blocked content, which degrades the user experience and can impact deliverability rates.

December 2022 - EmailGeeks Forum
Marketer view

Email marketer from a Digital Agency Blog mentions the SEO benefits of using HTTPS throughout your site. Switching to HTTPS across your website and email links is an important step for building consumer trust.

July 2021 - Digital Agency Blog
Marketer view

Email marketer from Stack Overflow explains that an SSL certificate establishes trust and helps avoid browser security warnings. If links in an email use HTTP, the user might be presented with a security warning that creates an obstacle to the desired user experience.

August 2024 - Stack Overflow
Marketer view

Marketer from Email Geeks shares that their SFMC link tracking is HTTP and they aren’t aware of it being directly attributed to any deliverability problems but it’s absolutely a UX issue.

November 2021 - Email Geeks
Marketer view

Email marketer from WP Beginner says that HTTPS/SSL is important for SEO because Google favors secure websites. Using HTTP tracking links on a website that is HTTPS may result in lower search engine rankings.

October 2023 - WP Beginner
Marketer view

Email marketer from LinkedIn argues that using HTTPS not only protects user data but also signals credibility to email providers, which can help improve email deliverability and placement in inboxes versus spam folders.

January 2025 - LinkedIn
Marketer view

Email marketer from Sendinblue shares that HTTPS protects visitors' data from attacks. HTTP sites are marked as 'not secure' by modern web browsers, which impacts user trust and reduces the credibility of the site.

October 2021 - Sendinblue

What the experts say
3Expert opinions

Experts indicate that HTTP tracking links can impact email deliverability and user experience by signaling a lack of security, potentially harming sender reputation and affecting deliverability rates. Ensuring that the final destination of redirects and tracking parameters is HTTPS is crucial to maintain security benefits. Submitting PII over HTTP poses a personal security risk.

Key opinions

  • Deliverability Impact: HTTP links can negatively impact sender reputation and, consequently, email deliverability.
  • Security Concerns: Lack of HTTPS signals a security vulnerability, affecting user trust and potentially leading to data compromise.
  • Redirects: If using redirects, the final destination must be HTTPS to maintain security.
  • Data security: Submitting PII or Financial information is a security concern

Key considerations

  • Prioritize HTTPS: Implement HTTPS across all links, including tracking links, to ensure data security and maintain a positive sender reputation.
  • Monitor Reputation: Regularly check sender reputation to identify and address any negative impacts from HTTP usage.
  • Ensure Secure Redirects: Verify that all redirects and tracking parameters lead to HTTPS destinations.
  • Evaluate Deliverability: Check whether it is a deliverability problem or a different problem where the recipient can’t get to the link.
Expert view

Expert from Wordtothewise.com responds to the fact that if you are using redirects and tracking parameters in your email, it's important to ensure that the final destination is indeed HTTPS so as not to negate any gains you have made by using HTTPS in the email.

March 2023 - Wordtothewise.com
Expert view

Expert from Email Geeks asks if it’s a deliverability problem or a different problem where the recipient can’t get to the link, and that non https is a personal security issue if you’re submitting PII or financial information.

June 2021 - Email Geeks
Expert view

Expert from Spamresource.com explains that HTTP links in emails can signal a lack of security and can negatively impact the sender's reputation, affecting deliverability. Senders should prioritize security for better email performance. Using HTTPS links helps build credibility.

August 2023 - Spamresource.com

What the documentation says
5Technical articles

Technical documentation highlights the security vulnerabilities associated with HTTP tracking links. These links lack privacy and integrity, exposing users to man-in-the-middle attacks, eavesdropping, tampering, and data theft. Modern browsers restrict functionality in insecure contexts. Switching to HTTPS, secured by SSL/TLS encryption, is recommended for data integrity, user security, compliance, and improved search engine ranking.

Key findings

  • Man-in-the-Middle Attacks: HTTP is susceptible to man-in-the-middle attacks where attackers can intercept and alter data.
  • Lack of Privacy: Insecure contexts (HTTP) lack privacy, making them vulnerable to eavesdropping and tampering.
  • Restricted Functionality: Modern browsers restrict features in insecure contexts, diminishing functionality.
  • Ranking Signal: HTTPS is a ranking signal for Google search results.
  • Data Theft: HTTP links can expose users to data theft and malware injection.

Key considerations

  • Implement HTTPS: Switch to HTTPS across the entire website and all tracking links to enhance security and functionality.
  • Secure Sensitive Data: Protect sensitive user data by using HTTPS connections, preventing eavesdropping and tampering.
  • Comply with Security Standards: Adhere to security standards to ensure data integrity, user security, and compliance with regulations.
  • Monitor security protocols: Ensure SSL/TLS encryption is setup correctly and up to date.
Technical article

Documentation from Google Search Central Blog shares that HTTPS is a ranking signal. Switching to HTTPS by securing your website with SSL/TLS encryption can help improve your ranking in Google search results.

January 2025 - Google Search Central Blog
Technical article

Documentation from OWASP explains that HTTP is susceptible to man-in-the-middle attacks, where attackers can intercept and alter data transmitted between the user and server, potentially leading to data theft or malware injection. If you use HTTP tracking links, you may be vulnerable to this type of attack.

June 2024 - OWASP
Technical article

Documentation from Let's Encrypt clarifies that HTTPS protects website users from eavesdropping and man-in-the-middle attacks, ensuring data integrity and user security. It also covers compliance requirements.

June 2023 - Let's Encrypt
Technical article

Documentation from MDN Web Docs details that insecure contexts (HTTP) lack privacy and integrity, making them vulnerable to man-in-the-middle attacks. Modern browsers restrict features in insecure contexts, diminishing functionality.

May 2024 - MDN Web Docs
Technical article

Documentation from IETF explains the security issues of using HTTP, especially when dealing with sensitive user data. HTTP links can expose users to eavesdropping, tampering, and other security threats, impacting user trust and experience.

June 2024 - IETF