You can strip the links and replace them with a man-in-the-middle link so that you couldn't just directly click on the link.
Anything that will wake people up and stop them from just blindly clicking on things. For a financial institution like Coinbase where a hacker could compromise the security of the entire company, it doesn't seem completely unreasonable.
As long as the employee need to be able to browse the internet any whitelisting of links seems like a waste of resources.
That might work for the first day or so, but you'll eventually tune them out and blindly click pass the warning.