Email Links Marked as Unsafe Due to Tracking URL Certificate Error(Agent511)
This article explains why Agent511 email templates may trigger a browser certificate error (NET::ERR_CERT_COMMON_NAME_INVALID) when recipients click tracked links, and provides step-by-step instructions to reproduce and resolve the issue. Intended for internal support agents.
| Category Email Deliverability | Product Agent511 | Reference Ticket #24729 |
Overview
Agent511 appends click-tracking parameters to outbound email links, routing recipients through track.comed.com before reaching the intended destination. In certain cases, this redirect triggers a browser security warning, specifically the NET::ERR_CERT_COMMON_NAME_INVALID error, and prevents recipients from accessing the linked content.
Investigation identified two contributing factors: (1) SendGrid was inconsistently generating HTTP rather than HTTPS tracking links, and (2) the Exelon corporate network firewall or proxy was further blocking track.comed.com for specific users. The SendGrid-side issue has been resolved; the network-side issue requires action from the customer's internal IT team.
Screenshot 1: Browser displaying 'Your connection isn't private' error (NET::ERR_CERT_COMMON_NAME_INVALID) on track.comed.com
ℹ Important Note
This issue is network-specific. Users on personal devices or off the Exelon corporate network are able to open tracked links without errors.
The browser certificate warning does not indicate a security breach in Agent511 or SendGrid — it is caused by an HTTP vs. HTTPS mismatch and/or a corporate network security policy blocking track.comed.com.
Prerequisites
Before you begin, ensure you have the following:
- Access to the Agent511 Production UI at https://exelon.reach-pc.com/reachui/app/#app/notifications
- Login credentials with sufficient permissions to view and test notification templates.
- The template ID and ticket reference reported by the customer (e.g., Template 1899, Ticket #24729).
- A personal or non-corporate email address to receive test emails during verification.
Step-by-Step Instructions
Follow these steps to reproduce and verify the issue for a reported template:
-
Log in to the Agent511 UI (Production): Navigate to https://exelon.reach-pc.com/reachui/app/#app/notifications. Once logged in, click on the Notifications tab in the top navigation bar.
Screenshot 2: Agent511 production UI — Notifications tab selected (highlighted in red)
-
Navigate to Confirmations > Default: On the left side panel, expand Notifications, then expand Confirmations, and select Default to reveal the full list of notification templates.
Default expanded" style="border:1px solid #D2E9FC; border-radius:6px; max-width:100%; display:block;" /
Screenshot 3: Left panel showing Confirmations Default expanded
-
Locate the reported template: Scroll down to find the template reported by the customer (e.g., Solar Ready Premise 45-Day Reminder (1899)). Expand it, then click English > Email and select Email-Draft to begin testing.
Email Email-Draft highlighted" style="border:1px solid #D2E9FC; border-radius:6px; max-width:100%; display:block;" /
Screenshot 4: Template expanded — English Email Email-Draft highlighted
-
Select the live template version for testing: The right panel displays available template versions. Select the version marked with the ℹ symbol — this indicates it is currently used as the live template.
Screenshot 5: Template version list — Select button on the current live version
Screenshot 6: Tooltip confirming 'This template is currently used as live template'
-
Click “Test Draft”: Scroll to the bottom of the page. Four action buttons are displayed: Test Draft, Save Draft, Reset, and Make It Live. Click the Test Draft button.
Screenshot 7: Template editor — Test Draft button at the bottom highlighted
-
Enter a test email address and send: A popup will appear with a preview of the email template and a Test Email field at the bottom. Enter a personal, non-Exelon email address (e.g., venukoneti23@gmail.com), then click Send.
Screenshot 8: TestDraft popup — test email address entered, Send button visible
-
Verify receipt of the test email: Confirm the test email was received in the inbox. The subject line should read “Solar Interconnection Agreement - Transfer of Ownership”, sent from no-reply@comed.com.
Screenshot 9: Test email received in Gmail inbox — subject line and sender confirmed
-
Verify the tracked links in the email: Open the email and identify the two tracked links: ComEd.com/OwnershipChange and ComEd.com/SolarFAQ. Click each link and note whether it opens correctly or displays a certificate error. Errors persisting only on the corporate network should be escalated to customer IT.
Screenshot 10: Email body — both tracked links highlighted (ComEd.com/OwnershipChange and ComEd.com/SolarFAQ)
Screenshot 11: URL 1 — ComEd.com/OwnershipChange opened successfully (Distributed Generation Facility Assessment PDF)
Screenshot 12: URL 2 — ComEd.com/SolarFAQ opened successfully (My Green Power Connection FAQs page)
Troubleshooting & Common Issues
If you encounter issues while following the steps above, refer to this table for quick solutions.
| Symptom / Error Message | Root Cause | How to Fix It |
|---|---|---|
| NET::ERR_CERT_COMMON_NAME_INVALID when clicking tracked email links | SendGrid was generating HTTP tracking links instead of HTTPS. Since track.comed.com enforces HSTS, HTTP links are rejected by the browser. | Raise a ticket with SendGrid to investigate the HTTP/HTTPS tracking inconsistency and update link-tracking settings to enforce HTTPS. |
| Error persists for specific users on Exelon corporate network even after SendGrid fix | Corporate firewall, proxy, or network security policy is blocking or interfering with track.comed.com for certain users. | Advise the customer to raise an internal IT ticket to whitelist track.comed.com. Resolution is dependent on their IT team reviewing firewall and proxy rules. |
| Links open correctly for users on personal devices or off-network | The tracking link itself is functioning correctly after the SendGrid fix. The issue is network-specific. | Confirm that on-network vs. off-network testing reproduces the behavior, and escalate to customer IT accordingly. |
Guidelines
What to Avoid
- ✕Do not advise customers to clear their SSL state as a permanent fix, this is a temporary workaround and will not resolve underlying firewall or proxy issues.
- ✕Do not close the ticket as resolved until the customer confirms that tracked links open successfully from their corporate network, or an IT ticket has been raised and acknowledged.
- ✕Do not modify the live template (Make It Live) during investigation always test using Email-Draft to avoid impacting production emails.
Frequently Asked Questions (FAQs)
Q: Why is Agent511 adding tracking code to email links?
A: Agent511 uses SendGrid's click-tracking feature to record when recipients interact with links in outbound emails. This is standard for email analytics and is enabled for all OPCOs.
Q: Can the tracking be removed from a specific template?
A: Tracking can be disabled at the template or account level, but this requires coordination with the Agent511 product team. Raise an internal request if a customer requires tracking to be removed for compliance or security reasons.
Q: What if the issue persists after SendGrid settings are updated?
A: If the error continues for users on a specific corporate network, the issue is likely caused by a corporate firewall or proxy. Advise the customer to raise an internal IT ticket to whitelist track.comed.com and associated tracking domains.
Q: Who do I contact if the issue persists after all troubleshooting steps?
A: Escalate the Zendesk ticket internally and include the troubleshooting findings, test results, and confirmation of whether the SendGrid fix was applied. Reference the original ticket #24729 for context.
References & Related Tickets
For internal team use: Reference past Jira or Zendesk tickets related to this article.
- ZD-24729 Customer ticket reported by Meni Bougiotopoulos — email links in Template 1899 marked unsafe due to tracking URL certificate error.
- SendGrid Settings updated to enforce HTTPS for click-tracking links — HTTP/HTTPS inconsistency resolved.
Affected Components
| Component | Detail |
|---|---|
| Template 1899 | Solar Ready Premise 45-Day Reminder (12/05/24 Version – NEM) |
| Agent511 | Email link tracking feature — enabled for all OPCOs |
| SendGrid | Email delivery vendor — HTTP/HTTPS link tracking inconsistency (resolved via settings update) |
| track.comed.com | Tracking redirect domain — HSTS enforced; HTTP links cause cert error |
| Exelon corporate network | Firewall/proxy potentially blocking track.comed.com for certain users (customer IT action required) |
Agent511 Knowledge Base · Confidential · For internal support use only
Comments
0 comments
Please sign in to leave a comment.