Earlier quoted context omitted.
> The use case that this breaks is doing click tracking on links I, personally, would be quite happy for this use case to break.
> I, personally, would be quite happy for this use case to break. Why? If you don't want to be tracked it is pretty easy to avoid. You should already only be getting/opening emails you care about. Emails you don't care about should be unsubscribed from and reported as spam. Granted that links should only be tracked in email you do care about, why do you not want those people to have the information they need to refin…
If you want to track clicks, why not use a subdomain instead of something.weird3rdparty.com? And why would the link text look like a URL? I don't see why
www.ebay.com/viewOrder
makes more sense than view your order
.> Even if it is a password reset email or a email verification email?
Why would you want to share password reset info with a third party? I get the "easy tracking" argument for newsletters (but I'm pretty sure most are not GDPR compliant), but for password reset emails? why?
> Would you be happy if the link just failed to open
Why would it? You can put a working link in the email directly - you've proven that by putting a different link in the email than the one you pretend you're linking to.