Click-through rate has always been a metric marketers could genuinely stand behind in a budget conversation. Opens were the softer signal, inflated for years by preview panes and now further distorted by Apple and Google's mail privacy protections.
But prospects have been trained not to click, and it's working.
A New Email Reality
Somewhere in the last few years, most companies started running security awareness programmes. Simulated phishing tests, warning banners on external mail, and mandatory training that tells employees to slow down and question every link.
It's a sensible response, as business email compromise results in more than $3 billion in losses in a single year, and it's working exactly as intended.
Employees are clicking less.
The problem for us, as marketers, is that this caution doesn't stop at the phishing email. It also reduces the tendency to click on legitimate ones. It creates a general reflex to hesitate on hyperlinks. And a recipient's inbox doesn't sort a carefully written case-study link from a threat - it's all just a link, in a work inbox, from a sender they haven't met.
That means your open rate might be healthy, your subject line might have done its job, your buyer might have read the whole email properly, and the click still doesn't come. Not because the campaign failed, but because clicking has become a small professional risk in your prospect's mind.
The result? Your CTR dashboard may not mean what you think it means
Research from M3AAWG has found that between 20% and 80% of B2B email clicks aren't human. They come from enterprise security tools like Microsoft Defender, Proofpoint, and Mimecast, which pre-scan every link in an incoming email before your actual recipient has opened it. Even on the B2C side, non-human clicks run as high as 10%.
A spread from twenty to eighty percent is a real possibility that a meaningful share of the clicks in your platform came from a security appliance, not a prospect. Average B2B campaign CTR now sits around 1.7–2.1%, with click-to-open rate around 6.8%, and we genuinely don't know how much of either number belongs to software rather than a human being reading your email.
For those building marketing plans, or justifying spend to leadership, this matters enormously. Click-through rate turns out to be unreliable in its own way - a click might be a bot doing its job and a non-click might be a genuinely engaged buyer who read every word and simply, sensibly, chose not to touch the link on a work laptop.
What this means for how we should be measuring success
I don't think the fix is chasing CTR harder. I think it's accepting that CTR alone is not a complete picture of engagement and building the rest of the picture back in. Here are five key considerations to get better performance results in this new email reality.
#1 - Weight reply rate and direct enquiries more heavily than click volume
- A prospect who reads your email and replies, or forwards it internally to a colleague, or picks up the phone, is showing you real intent without ever needing to click a tracked link.
#2 - Report CTR alongside context, not alone
- If you're presenting click-through rate to a client or a leadership team, it's worth naming the bot-contamination issue upfront rather than letting a flat or declining number read as a campaign failure. A dip in CTR alongside a healthy open rate and steady reply volume tells a vastly different story from one read in isolation.
#3 - Design the email so the reader doesn't need to click to get value or take the next step
- A named sender the recipient can recognize, a plain-text preview of where a link actually leads, a phone number as an alternative path to action, a calendar link on your own branded domain rather than a generic scheduler's raw URL - all of this reduces the "is this safe" calculation and gives more than one way to say yes.
#4 - Protect your sending reputation like the asset it now is
- SPF, DKIM, DMARC, a consistent from-address, no last-minute domain switches. This has stopped being background deliverability hygiene. It's now part of the unconscious checklist a trained, wary recipient runs before deciding your email and your links can be trusted at all.
#5 - Bring this into how you talk to your own team and clients about targets
- If click-through rate is baked into KPIs or into how success is defined for a campaign, it's worth having the bot-contamination and click-hesitancy conversation early, so targets are set against a realistic baseline rather than a number nobody can fully verify.
None of this solves the underlying measurement problem. What it does is give B2B marketers a more honest set of signals to build a strategy around, rather than optimizing ever harder against a metric that is breaking down.
The click always signaled attention and trust, and right now, in B2B, attention and trust often look like a buyer who read every word of your email carefully and, quite sensibly, didn't touch the link.
About the Author
PETRA SMITH is founder and Managing Director of marketing and PR consultancy Squirrels & Bears, a London-based PR, marketing, and design consultancy, with over 18 years of experience in corporate, agency, and B2B/B2C global marketing strategy.
She is a strong advocate for the idea that business size is not an obstacle — whether a business is “squirrel-sized” or “bear-sized,” it can build a highly visible brand that drives customer loyalty and sales.
Her specialism sits at the intersection of marketing psychology, PR strategy, and commercial thinking.