Magic Link Being Invalidated by Email Security

I’m currently exclusively using magic link for logging in and signing up users. We just recently partnered with a large organization that seems to have email security systems in place that are “pre-clicking” the link before it gets to the inbox of the end user, therefore invalidating the login functionality of the link since it can only be used once. Ideally, I’d set a timeframe in which the link could be used instead of only allowing the link to be clicked once but that isn’t an option with this bubble token creation. Does anyone have any ideas on how to resolve this without having the user create a password?