Links in mails contain no figma domain and therefore get blocked by firewall

The security policy of a large company I work for blocks all figma links sent by mail. Their argument is that there is no way to know if a link is trustworthy, because it refers to the delivery provider and not to the domain it actually links to. A link in a figma mail typically starts like this:

https://u3302489.ct.sendgrid.net/ls/click?upn=5jn

They security team argues that this design choice facilitates pishing attacks and is increasingly exploited. Also see the following link:
SendGrid & Mailchimp Phishing Attacks: How Scammers Leverage Email Delivery Services To Their Advantage

Is there any way that figma mails contain the actual figma links? This problem makes countless workflows in the company inefficient.

Thank you for feedback and info on that topic!
Kind regards

5 Likes

same here! +1