skip to content

What does click-time URL rewriting in a mail gateway catch that delivery-time scanning cannot?

level: juniorimportance: must knowfreq 62%

answer

  1. the destination can change after delivery
  2. the check moves to the moment of use
  3. gateway-owned redirect replaces the link
  4. every click leaves a record
  5. warning pages can be clicked past

basics

~20 s

A link that is harmless when the message arrives and armed hours later. Delivery-time scanning judges the destination as it was at delivery; rewriting routes every click through the gateway, so the destination is judged again at click time.

solid answer

~50 s

At delivery the gateway resolves each URL, looks up its reputation and makes a keep-or-quarantine decision once. An operator who registers a clean domain, serves a harmless page for two days and only then swaps in a credential-harvesting form defeats that check: the verdict was correct when made and stale by the time anyone clicks. Click-time rewriting replaces every URL in the body with a gateway-owned redirect carrying a token for that message and recipient. The click reaches the gateway first, which re-resolves the destination, applies the verdict it holds now, then allows, warns or blocks. The second thing it buys is telemetry: every click transits the service, so you learn which mailbox clicked which link and when, which is the containment worklist when a campaign is confirmed later. It does not cover a URL delivered as a QR image, an address copied out of the message, or a user who clicks through the warning.

go deeper

for a junior

Be ready to state plainly that the gateway substitutes its own redirect for every link so the destination is checked again when someone clicks, and that this is what catches a link armed after delivery.

for a middle

Explain the mechanics: the token-bearing rewritten URL, the three possible click outcomes of allow, warn and block, and the fact that each click is evaluated independently against the verdict held at that moment.

for a senior

Show that you value the click log as much as the block. Be able to say how you would use it when a campaign is confirmed two days late, and name the coverage gaps you would not rely on it to close.

for a principal

Own the tradeoff. Rewriting mangles every URL in the organisation's mail, breaks hover-to-verify training and can consume single-use links, so be ready to argue what the telemetry is worth against those costs and how you would scope click-through permissions.

## The check that goes stale A mail gateway evaluates a message once, at the moment it is delivered. For links, that means expanding shorteners, following redirects, resolving the final host and looking it up against reputation and category feeds, sometimes with a quick fetch of the page. If nothing is adverse, the message is delivered. That decision is a snapshot, and it is correct only for the state of the internet at that instant. The cheapest way past it is patience. Register a domain with clean history or compromise a real one, serve an innocuous page while the campaign is delivered, and flip the content to a credential-harvesting form a day or two later. Nothing about the message changes. The gateway's delivery-time verdict was not wrong; it was answering a question about a different page than the one the recipient will see. ## What rewriting changes mechanically With click-time URL protection enabled, the gateway does not just judge the link, it *replaces* it. Every URL in the message body is substituted with a URL owned by the protection service, carrying an opaque token that encodes the original destination and identifies the message and recipient. What lands in the mailbox is that rewritten link. When someone clicks, the request reaches the protection service, not the destination. The service decodes the original URL, re-resolves it, applies whatever verdict it holds at that second, and then does one of three things: redirect the browser to the destination, show an interstitial warning that the user may be allowed to click past, or block outright with an error page. Each click is evaluated independently, so the same link can be allowed at 09:00 and blocked at 15:00 once the destination is reclassified. This moves the control from purely preventive to something that keeps working after delivery. It is the only gateway control that gets a second chance at a message it already let through, other than post-delivery retraction. ## The second product: a click record Because every click transits the service, rewriting produces telemetry that no other mail control produces: which mailbox requested which rewritten link, at what time, what verdict the service applied, and whether the user clicked past a warning. When a campaign is confirmed forty hours after delivery, this is what turns four thousand delivered messages into a list of twelve people who actually engaged. Retraction removes the messages; the click record tells you who you have an incident about. Many teams value the telemetry more than the block. ## Where it does not reach - **No text link, no rewrite.** A URL rendered as a QR code or embedded in an image is pixels. There is nothing to substitute, and the user typically scans it with a phone that is off the corporate network and outside the gateway entirely. - **The user can leave the path.** Someone who copies the address out of a rendered page, retypes it, or reaches the same site from a search result never touches the service, so there is neither protection nor a record. - **Warning pages are advisory.** If policy allows click-through, a determined user reaches the site anyway; you get a record that says so, which is evidence, not prevention. - **It judges a destination, not a lure.** A link to a real, uncompromised file-sharing service hosting a malicious document is a legitimate destination at click time. - **Coverage depends on the path.** Mail that reaches mailboxes without traversing the gateway policy, or links inside some attachment types, may never be rewritten. ## Operational costs to be honest about Rewritten URLs are long and opaque, which breaks the hover-and-read-the-domain habit that user training teaches, and means the warning page becomes the only visible signal. Automated fetches of the original URL, by the protection service or by other tooling, can consume single-use links such as password resets and meeting invitations. And a click record can be generated by a machine rather than a person, which matters enormously when you are counting victims. ## How to say it in an interview Delivery-time scanning answers *is this destination bad now?* once. Click-time rewriting re-asks it at the moment of use and writes down who asked. That is why it is the control that survives an adversary who arms a link after delivery, and why its log is the first thing you pull when a campaign is confirmed late.

  • Why does click-time rewriting do nothing about a phishing URL delivered as a QR code?
    There is no text link to substitute. The address exists only as pixels in an image, so the gateway has nothing to rewrite, and the user usually resolves it by pointing a personal phone at the screen, which is off the corporate network and outside every gateway control you own.
  • A recipient forwards the message to a personal address and clicks from there. Is the click still protected and logged?
    Usually yes, because the rewritten URL travels with the body, so the click still transits the protection service and is still evaluated. But the token identifies the original delivered message and recipient, so the record attributes the click to the employee's mailbox rather than to whoever actually clicked.
  • The same rewritten link was allowed in the morning and blocked in the afternoon. Is that a bug?
    No. Each click is evaluated against the verdict held at that second, so a reclassification between the two clicks produces exactly this. The earlier allowed click is not retroactively fixed, which is why that record is your worklist: someone reached the destination while it was still considered clean.

A delivery-time scan is a bouncer checking an ID at the door at 21:00. Click-time rewriting is checking it again at the bar, every time a drink is ordered, and writing down who ordered what.

saying these in an interview costs you the question

  • Claims rewriting stops the user from ever reaching the site
  • Thinks the URL is scanned once, at delivery, and never again
  • Treats the presence of a rewritten link as evidence of malice
  • Forgets that clicks can be generated by scanners, not people
  • Assumes QR codes and copied addresses are covered

context