Earlier quoted context omitted.
It’s possible that the emailed link contains extra query params which are logged. Checking for the existence of these query params in requests would enable them to verify that reset requests to date were clicked from email rather than using this method.
Also, the referrer header may be different too? Although it's likely nobody thought to log it.
- directly navigating to a URL after doing a copy-paste
- opening a link from an email