We do not open the link directly and we do not perform direct HTTP/TLS/DNS fetches against the target from our infrastructure. What may happen is a lookup against existing feeds, blocklists and reports from third parties, without active scan submission.