I don't care if you track that I clicked on your link. I care that your link doesn't appear to go to the same site your reply-to email would go.
From one of the last emails I read this evening: "we would like to inform you that there is a form on our website" [me]: The form is not on your website, only the link to it.
You're right, but it's much more simple to disallow links, people don't really understand the difference on a website, emails are another additional complication.
1. while developing -> send tokens for copy/paste if a user has chosen text-only emails
2. while administering -> institute the policy of having to ask one of the administrators, if it happens too often you have worse problems in any case
>attackers would send a spear-phishing email luring victims to a web page, where, if they used Firefox, the page would download and run an info-stealer
Anything that will wake people up and stop them from just blindly clicking on things. For a financial institution like Coinbase where a hacker could compromise the security of the entire company, it doesn't seem completely unreasonable.
As long as the employee need to be able to browse the internet any whitelisting of links seems like a waste of resources.
That might work for the first day or so, but you'll eventually tune them out and blindly click pass the warning.
Email does not benefit much from format when doing communication.
Marketing and sales is a different story.