An email platform once decided to show its customers the truth.
They built filtering to strip machine-generated opens out of reporting.
Apple had published enough technical detail around MPP to make it possible.
So they shipped it.
Open rates dropped.
Customers complained that the platform's numbers looked worse than everyone else's.
The feature came out.
This week on Audience Bridge Insights, I sat down with Travis Hazlewood, Head of Email Deliverability at Ortto, now a Canva company, to talk about what your ESP can see that you can't.
Travis is in his eighth year focused on deliverability.
He runs global platform delivery audits, blocklist remediation, and sender reputation repair for high-volume senders.
He works in Kibana, Mailgun, SendGrid, Grafana, Postmaster Tools, and SNDS all day.
He is the person who gets the call when a large sender's reputation catches fire.
I've been arguing about opener bloat for months.
This time I got the story from the other side of the glass.
You can watch the entire podcast now or scroll down to get the full breakdown.
The Feature That Got Deleted
Travis told me about the machine-open filtering early in his time at Ortto.
They built it.
Turned it on.
Watched customers revolt.
Not because the numbers were wrong.
Because the numbers were right, and right looked worse than the competition.
We were filtering it out. And it looked bad. So we pulled it.
The problem was never that ESPs can't identify machine opens.
The problem is that a platform reporting a 22% real open rate loses the evaluation to one reporting 41%.
Honest reporting is a competitive disadvantage.
So nobody ships it as a default.
Opener bloat isn't a bug in your ESP. It's a market outcome.
The work survived, just not as the default.
Travis built the identification fields, the dashboards, and the human-versus-machine reporting templates.
They're still in the product. You just have to go looking for them.
Google Can Already See What You Can't
Here's the part that should change how you read your numbers this week.
We discussed that Postmaster Tools was surfacing a message on accounts that are clean on every other signal.
Authentication passing.
Complaint rate under threshold.
Domain reputation fine.
And Google still tells the sender that users aren't engaging with their email.

That isn't a compliance warning.
That's Google saying it can see which of those opens are human, which clicks are real, and there aren't enough of them.
You're looking at 40%.
Google is looking at the real number.
Only one of you is making decisions with accurate data.
If Postmaster Tools flags engagement on a fully compliant account, your opener segment is the first place to look.
Microsoft Is Camouflaging Its Scanners On Purpose
This is where it stops being a measurement annoyance.
Microsoft 365 is the largest source of machine clicks Travis sees.
And those clicks aren't sloppy.
Machine opens are mostly a privacy function.
Machine clicks are a security function.
Links are the riskiest content in an email short of an attachment, so the scanner has to check them.
And if the scan were easy to detect, bad actors would route around it.
So Microsoft makes the scan look organic.
They are intentionally making them more organic looking, because they need the bad actors to not be able to figure out how to get around it.
Which breaks the heuristic most of us lean on.
Ortto filters clicks that land within a few seconds of delivery. Useful, and nowhere near sufficient.
Travis has watched Microsoft machine clicks fire an hour after delivery.
A day after delivery.
At the individual level they look human.
Only zoomed out across hundreds of recipients does the pattern appear.
Ortto tested an interstitial page, forcing a second click.
Microsoft 365 was able to preload and fetch the next page anyway.
Then the detail I hadn't heard anywhere: Proofpoint has openly acknowledged that it fires server clicks retroactively, on messages it already delivered, once a sender crosses a complaint threshold on a newer send.
The industry pushed back.
The answer was essentially that this is how the system works.
The 2-Minute Rule catches the fast fakes. It cannot catch a scanner that waits a day, and nothing catches clicks injected backward in time.
Your Fixed Send Time Is an Asset, Not a Limitation
This was the segment built for this audience.
Travis calls send time optimization a crutch, and his reasoning applies directly to daily senders.
STO computes a precise "best time" from engagement data that isn't real.
MPP fires the open whenever you send.
So the optimal hour you calculated is partly an artifact of your own schedule.
He also rejects the top-of-inbox goal outright.
You can't control it.
And the AI inbox is dismantling chronological ordering anyway, between Gemini-backed summarization in Gmail and Apple Mail's sender view that doesn't even sort by time.
His replacement is consistency.
Send at a predictable time.
Build an experience they anticipate.
And they'll come find you.
That's what publishers think STO is buying them, and it isn't.
You send at the same hour every day because you have to. That constraint is the exact behavior he tells enterprise senders to manufacture.
Your Signup Form Might Be Someone Else's Weapon
Travis coined a term I'll be stealing: Secondhand Spam.
Damage you cause without intent.
Not bad practice, just setup you never audited.
The mechanism he sees most: bots crawl the web for signup forms without CAPTCHA and abuse the ones they find.
Sometimes you're the target.
More often you're collateral, and the real goal is burying a fraud alert from someone's bank under a thousand welcome emails.
Subscribers are the ones ultimately deciding what spam is. Not the legal system.
Then the one that made me go check my own forms.
Attackers notice your welcome email personalizes with a first name.
They submit a stolen address with an entire paragraph of scam copy in the name field.
No character limit on that field means your welcome email ships as "Hi," followed by a full scam pitch, with your real content buried underneath.
Your domain.
Your authentication. T
Their scam.
Put a CAPTCHA on every embedded form you own and a character limit on your name field. Both are ten-minute fixes.
Where We Disagreed
During the lightning round, I asked what metric should be deleted from every ESP dashboard.
He named the machine-open metric.
The one he built the reporting for.
His reasoning: identification is unreliable enough that it becomes a distraction.
Marketers stare at a number they can't trust instead of moving the one they can.
His method is trend-based.
If half your clicks are fake, improve the number anyway.
The real component moves with it.
I don't fully agree.
I also don't think either of us is wrong.
He serves thousands of senders at once.
He can't ship a heuristic that quietly deletes real engagement, because the blast radius is everyone.
You run one list.
You can tune a threshold, watch what happens, and back it off if you cut too deep.
Platform defaults and operator strategy have different tolerances for error.
The reason your ESP won't filter this for you is the same reason you have to.
The Black Box Might Finally Get a Window
One piece of real news from the conversation.
There's a proposed standard moving through the IETF called APRF, Aggregate Performance Reporting.
It works like DMARC.
Publish a TXT record, name a reporting address, and supporting mailbox providers send back daily aggregate reports.
Two buckets of data.
Where your mail actually landed, inbox versus spam.
And what users did with it.
Not a seedlist estimate.
Real placement data from the provider itself.
The draft comes from Alex Brotman at Comcast, Tom Corbett at Iterable, and Emil Gustafsson at Google.
Comcast is already running a beta.
Travis's caveat is the right one: expect it gated to quality senders, the way BIMI is.
Full placement transparency helps bad actors reverse-engineer the filters, and parsing that data for every sender on earth is expensive.
For the first time, inbox placement could be something you're told instead of something you estimate.
My Take After This Conversation
Three things stuck with me:
1. Your dashboard isn't neutral, and it never was.
Every platform that showed customers the honest number got punished for it.
The flattering number became the standard because the market selected for it.
Read your open rate as a marketing artifact, not a measurement.
2. No single timing rule survives contact with modern scanners.
I'm keeping the 2-Minute Rule. It works on what it was built for.
But Microsoft firing a day late and Proofpoint injecting clicks backward mean timing alone can't carry the job.
Multi-signal, or you're guessing with extra steps.
3. Gate on clicks anyway.
Travis won't, and his reason is a good one.
He can't risk it across thousands of senders.
You aren't thousands of senders.
You're one list, and you can measure exactly what happens when you cut.
That asymmetry is the entire argument for building your Base Sending Segment yourself instead of waiting for a platform to hand it to you.
Nobody is coming to fix your open rate.
The incentives point the other way, and they always have.
See you next week,
Chris Miquel
P.S. Everything Travis and I talked about lands in the same place: the numbers your ESP shows you were shaped by what customers wanted to see, not by what's true.
That's why we built Smart Delivery, domain-level deliverability and engagement monitoring, so you know what Gmail is actually doing with your email instead of what your dashboard says.
And Smart Reactivation, which finds the dormant subscribers still worth winning back using real click signals, not opener bloat.
If you want to know how much of your engaged segment is actually engaged, book a call.



