What could cause unusual clicks and unsubscribes in SendGrid, and how can I troubleshoot it?

Summary

Unusual clicks and unsubscribes in SendGrid can arise from various sources, including bot activity (potentially due to aggressive cloud security), compromised accounts or email spoofing, list bombing attacks, poor email list quality leading to spam traps and high bounce rates, low engagement rates, and poor IP/domain reputation. Additionally, issues with email authentication (SPF, DKIM, DMARC) or changes in corporate mail systems can contribute. Troubleshooting involves analyzing unsubscribe patterns, securing accounts with 2FA, cleaning and validating email lists, verifying email authentication, monitoring engagement metrics, implementing feedback loops, investigating webhook data, and utilizing tools like Google Postmaster Tools. Identifying and blocking spambot or scraper activity is also critical.

Key findings

  • Bot/Scraper Activity: Spikes in unsubscriptions often indicate spambot or scraper activity using unsubscribe links for email validation. Identify and block offending IPs/User Agents.
  • Compromised Accounts/Spoofing: Compromised accounts or email spoofing can generate automated responses and damage reputation. Audit email authentication and user permissions.
  • List Bombing Attacks: Sudden subscription increases followed by unsubscribes suggest list bombing. Monitor signups and use CAPTCHAs.
  • Poor List Quality: Poor list quality leads to high bounce rates, spam complaints, and deliverability issues. Validate addresses and remove inactive subscribers.
  • Spam Traps: Hitting spam traps damages sender reputation. Practice list hygiene and double opt-in.
  • Low Engagement Rates: Low engagement can cause ISPs to filter emails as spam. Improve engagement through segmentation and targeted content.
  • Poor IP/Domain Reputation: Poor reputation affects deliverability. Warm up IPs, monitor sender scores, and follow best practices.
  • Authentication Issues: Incorrect SPF, DKIM, or DMARC configurations lead to emails being flagged as spam. Verify DNS records.

Key considerations

  • Analyze Unsubscribe Patterns: Investigate patterns in unsubscribes (IPs, user agents) to identify malicious activity.
  • Secure Accounts: Enable 2FA, monitor login activity, and regularly audit user permissions to prevent unauthorized access.
  • Maintain List Hygiene: Clean and validate email lists regularly to remove invalid addresses and inactive subscribers.
  • Verify Email Authentication: Ensure SPF, DKIM, and DMARC are correctly configured for email authentication.
  • Improve Engagement: Segment email lists and create targeted content to improve engagement and reduce spam complaints.
  • Utilize Feedback Loops (FBLs): Implement FBLs to remove subscribers marking emails as spam and improve sender reputation.
  • Monitor Webhooks: Set up and monitor SendGrid's event webhook to capture detailed data for analysis.
  • Use Google Postmaster Tools: Use Google Postmaster Tools to monitor your domain's reputation and deliverability performance.
  • Check Mail Systems: Consider changes in corporate mailbox provider or spam filters.

What email marketers say
14Marketer opinions

Unusual click and unsubscribe activity in SendGrid can stem from various factors, including bot activity (potentially from cloud security vendors), compromised accounts, list bombing attacks, poor list quality, spam traps, and issues with IP/domain reputation. Troubleshooting involves analyzing unsubscribe patterns, checking account security, cleaning email lists, verifying email authentication (SPF, DKIM, DMARC), monitoring engagement metrics, and utilizing tools like SendGrid's event webhooks and Google Postmaster Tools.

Key opinions

  • Bot Activity: Bot traffic can inflate click rates and trigger unsubscribes. Use bot detection tools and clean email lists to mitigate this.
  • Compromised Accounts: Compromised accounts can send spam, leading to deliverability issues. Enable two-factor authentication and monitor for unusual login activity.
  • List Bombing: A sudden surge in subscriptions followed by unsubscribes may indicate a list bombing attack. Implement CAPTCHAs and monitor signup sources.
  • List Quality: Poor email list quality can lead to high bounce rates and spam complaints. Validate email addresses and remove inactive subscribers.
  • Spam Traps: Hitting spam traps damages sender reputation. Practice list hygiene, use double opt-in, and regularly clean the email list.
  • IP/Domain Reputation: Poor IP/domain reputation impacts deliverability. Warm up IP addresses, monitor sender scores, and adhere to best practices.
  • Email Authentication: Incorrect email authentication (SPF, DKIM, DMARC) causes emails to be flagged as spam. Verify DNS records and ensure proper setup.

Key considerations

  • Analyze Unsubscribes: Analyze unsubscribe patterns (IP addresses, user agents) to identify potential bot activity or scraping.
  • Check Account Security: Ensure SendGrid account security with two-factor authentication and monitor login activity.
  • Clean Email Lists: Regularly clean email lists to remove inactive subscribers and invalid addresses.
  • Verify Authentication: Verify that SPF, DKIM, and DMARC records are properly configured to authenticate emails.
  • Monitor Engagement: Track engagement metrics (opens, clicks) to identify potential issues and segment lists accordingly.
  • Use Webhooks: Set up SendGrid's event webhook to capture detailed event data for analysis.
  • Monitor with Postmaster Tools: Google Postmaster Tools allows you to monitor the health of your domain, which can help identify if you have any deliverability issues.
Marketer view

Email marketer from Mailjet Blog shares that poor IP reputation can cause deliverability problems. Suggestions include warming up IP addresses, monitoring sender scores, and adhering to best practices.

December 2022 - Mailjet Blog
Marketer view

Email marketer from Gmass explains that google postmaster tools allows you to monitor the health of your domain, which can help identify if you have any deliverability issues.

November 2023 - Gmass Blog
Marketer view

Marketer from Email Geeks asks about the method of connecting to Sendgrid (API usage) and whether there have been any changes to corporate mailbox providers or the addition of spam filters, to identify the cause of the issue.

January 2025 - Email Geeks
Marketer view

Email marketer from Email on Acid Blog explains that poor email list quality can result in high bounce rates, spam complaints, and ultimately, deliverability issues. Suggests validating email addresses and removing inactive subscribers.

May 2022 - Email on Acid Blog
Marketer view

Email marketer from SendGrid Help Center explains that suspicious activity can result from compromised credentials, unengaged recipients, or list bombing, and suggests taking steps to secure accounts, clean up lists, and monitor reputation.

July 2023 - SendGrid Help Center
Marketer view

Email marketer from Neil Patel's Blog shares that bot traffic can inflate click rates and lead to inaccurate data, emphasizing the importance of using bot detection tools and cleaning email lists to filter out invalid activity.

May 2022 - Neil Patel's Blog
Marketer view

Marketer from Email Geeks suggests the unusual click and unsubscribe activity could be due to bot activity, potentially from an over-zealous cloud security vendor like Barracuda, and that it is unlikely to be caused by SendGrid itself.

October 2021 - Email Geeks
Marketer view

Email marketer from Litmus Blog explains that hitting spam traps can damage sender reputation and cause deliverability issues. Suggests practicing proper list hygiene, using double opt-in, and regularly cleaning the email list.

July 2022 - Litmus Blog
Marketer view

Marketer from Email Geeks recommends analyzing the unsubscribes to see if they originate from a specific provider or via a particular method like a HTTP post in the list-unsubscribe header. Suggests using a manual unsubscribe group in Sendgrid for testing and contacting the account manager for more data.

May 2021 - Email Geeks
Marketer view

Email marketer from StackOverflow responds that incorrect email authentication (SPF, DKIM, DMARC) can cause emails to be flagged as spam. Verify DNS records and ensure proper setup.

June 2023 - StackOverflow
Marketer view

Marketer from Email Geeks explains that SendGrid may not be suppressing obvious bot activity and suggests submitting a feature request through support.

February 2022 - Email Geeks
Marketer view

Email marketer from Reddit explains that compromised accounts can send spam, leading to blacklisting and deliverability issues. Check for unusual login activity and enable two-factor authentication.

February 2025 - Reddit
Marketer view

Email marketer from Email Marketing Forum answers that a sudden increase in subscriptions followed by unsubscribes may indicate a list bombing attack. Monitor signup sources and implement CAPTCHAs.

October 2022 - Email Marketing Forum
Marketer view

Marketer from Email Geeks recommends setting up SendGrid's event webhook and storing all event data to get user agent and remote IP address information, which would help in determining if SendGrid is the cause of the unusual activity.

April 2021 - Email Geeks

What the experts say
2Expert opinions

Unusual unsubscriptions and click activity can be caused by spambot or scraper activity, which uses unsubscribe links to validate email addresses. Additionally, compromised accounts or email spoofing can generate automated responses like unsubscribe requests. Blocking offending IPs or user agents and regularly auditing email authentication and user permissions are crucial for troubleshooting and prevention.

Key opinions

  • Spambot/Scraper Activity: Sudden spikes in unsubscriptions often indicate spambot or scraper activity, using unsubscribe links for email validation.
  • Compromised Accounts/Spoofing: Compromised accounts or email spoofing can generate automated unsubscribe requests.

Key considerations

  • Investigate Unsubscribe Patterns: Look for patterns in unsubscriptions, such as common IP addresses or user agents, to identify spambot/scraper activity.
  • Block Offending IPs/User Agents: Block the IPs or user agents identified as engaging in spambot/scraper activity from accessing unsubscribe links.
  • Audit Authentication/Permissions: Regularly audit email authentication and user permissions to prevent spoofing and unauthorized access.
Expert view

Expert from Spam Resource shares that compromised accounts or email spoofing where spammers send email that appears to originate from your domain but doesn't, can generate automated responses such as out-of-office replies or unsubscribe requests. Regularly audit email authentication and user permissions to prevent spoofing and protect against unauthorized access.

January 2022 - Spam Resource
Expert view

Expert from Word to the Wise explains that a sudden spike in unsubscriptions often comes from spambot or scraper activity. You can investigate the unsubscribes, looking for patterns. Are they all from the same IP address? Are they all using the same user agent? If so, they are likely a scraper, using the unsubscribe link as a convenient way to validate email addresses. The best approach is to block the offending IPs or user agents from accessing the unsubscribe links.

May 2024 - Word to the Wise

What the documentation says
3Technical articles

Unusual activity can be caused by compromised credentials, which can lead to unauthorized use. Low engagement rates can also lead to emails being filtered as spam by ISPs. Utilizing feedback loops helps identify and remove subscribers who mark emails as spam, improving sender reputation and reducing deliverability issues.

Key findings

  • Compromised Credentials: Compromised credentials can lead to unauthorized account use and suspicious activity.
  • Low Engagement: Low engagement rates can cause ISPs to filter emails as spam.
  • Feedback Loops: Feedback loops help identify and remove subscribers marking emails as spam, improving sender reputation.

Key considerations

  • Enable 2FA: Set up two-factor authentication to prevent unauthorized account access.
  • Improve Engagement: Regularly engage with subscribers and segment lists based on activity to improve engagement rates.
  • Implement FBLs: Utilize feedback loops to identify and remove subscribers who mark emails as spam.
Technical article

Documentation from RFC explains that utilizing feedback loops (FBLs) helps identify and remove subscribers who mark emails as spam, thus improving sender reputation and reducing deliverability issues.

February 2023 - RFC
Technical article

Documentation from SparkPost Documentation answers that low engagement rates can lead to ISPs filtering emails as spam. SparkPost recommends regularly engaging with subscribers and segmenting lists based on activity.

May 2023 - SparkPost Documentation
Technical article

Documentation from SendGrid Documentation states that abnormal or suspicious activity may be due to compromised credentials, which can lead to unauthorized use. SendGrid recommends setting up 2FA to prevent this.

October 2023 - SendGrid Documentation