You rejected every cookie banner. You blocked third-party cookies. It changed almost nothing, because the tracking that actually follows you around the internet does not live in your browser. It lives in your inbox: your email address is the identifier ad platforms use to recognize you across websites, apps, and devices.
Email tracking is the practice of using your address itself, not the content of your emails, to connect your activity. It works through tracking pixels in messages, hashed email uploads to ad platforms, and data brokers that stitch records together. None of these mechanisms need cookies, which is why cookie blocking barely dents them.
How email tracking works
Three mechanisms do most of the damage. Understanding each one points directly at the fix.
How does a tracking pixel track email opens?
A tracking pixel is a tiny, invisible image embedded in a marketing email, unique to each recipient. When your mail client loads the image, the sender's server records the request: your IP address, device, and the exact open time. You never have to click anything. Simply opening the email completes the tracking event and confirms your address is active.
The pixel URL carries an identifier tied to you, so the open is not anonymous. It is logged against your subscriber record, which is how senders know exactly who opened what and when. Some senders also use pixels to verify that an address is live before selling or sharing the list further.
What is a hashed email upload?
A hashed email upload is how advertisers match you without handing over your raw address. They scramble your email with a one-way hash and upload it to Meta or Google as a custom audience. The platform hashes its own database the same way and matches them. Scrambled matches scrambled, and a store you visited once can target you for years.
Meta documents this flow openly: customer lists are hashed before upload and matched against platform users for custom audiences. The cryptography is real, but the privacy outcome is not meaningfully different from sharing the address. A match is a match.
This is also why unsubscribing from a store's emails does not stop their ads. The mailing list and the ad audience are two different systems. You can leave one and stay trapped in the other indefinitely.
How do data brokers use your email address?
Data brokers buy, scrape, and stitch personal records together, using your email address as the thread. A purchase here, a newsletter signup there, a public record somewhere else: one string ties them into a single profile, which is then sold to advertisers and other buyers. Opt-out services file removals on your behalf, but the underlying trade continues.
The broker does not need your permission to hold this profile in most jurisdictions. They assemble it from sources you never interacted with directly, which is why the profile often knows things you never told any single company.
Why your email beats every cookie
A tracker needs one stable string that identifies the same person in many places. Cookies are terrible at this now: they expire, they get blocked, Safari and Firefox restrict them by default, and they are different on every device you own.
Your email has none of these problems. It is unique to you, it is identical everywhere, and you have probably had it for a decade. In database terms it is a join key: the column that lets you combine two tables. Your email is the column companies use to combine everything they know about you. That is the entire trick. They do not need to follow you around the web when every site hands them the same ID.
Why doesn't deleting cookies stop email tracking?
Cookie blocking governs what happens inside your browser. Hashed email uploads and data-broker matching happen on company servers, where your browser settings cannot reach. You can run the strictest browser available and still get matched, because the match used an address you typed into a form years ago.
How to spot tracking in your own inbox
You do not need any tools for this. In Gmail, open any marketing email, click the three-dot menu, and choose "Show original." Search the raw source for image tags with width="1" or height="1", or image URLs containing words like "track" or "pixel." That is the tracking pixel, sitting in plain sight once you know where to look.
Then hover over any link without clicking it. If the address routes through a redirect domain you do not recognize, or carries a long tail of parameters after the real URL, your click is being logged and tied to your profile before you ever arrive.
Pick a newsletter you actually like and inspect one email. Seeing your own trusted sender's tracking pixel changes how you read every email after it.
How to stop email tracking
There is no single switch, but there is a practical stack, in order of effort.
Turn off automatic image loading. Every major mail client has the setting, it takes thirty seconds, and pixel tracking dies immediately. Apple Mail now blocks remote images by default.
Stop reusing one address everywhere. This is the structural fix. Give each site its own email alias and there is no single string connecting them. When one starts getting spam or turns up in a breach, you know exactly which site leaked it, and you kill just that one. Compare that with a single shared address: when the spam starts, you have no idea which of the hundred sites you gave it to is responsible, so there is nothing to do except filter and endure.
That is the workflow AliasFleet is built around: one email alias per site, tracker blocking on the way in, and a one-click kill switch when an alias leaks, plus leak detection that tells you when an alias shows up somewhere it should not. See the AliasFleet documentation for setup guides, including custom domains and the API.
The alias idea is not ours alone. SimpleLogin, Firefox Relay, and DuckDuckGo's Email Protection all do versions of it, and any of them beats reusing one address. What we built differently is the combination: aliases plus the kill switch plus tracker blocking plus leak detection, organized around breach containment instead of just inbox hygiene. The free tier covers 10 aliases, enough to feel the difference before paying.
File data-broker opt-outs. Removal services automate the paperwork. It is whack-a-mole and the data creeps back, but it raises the cost of profiling you.
One thing I will not claim: aliases contain the future, not the past. If ad platforms have spent years joining your real address to your identity, new aliases do not un-join that profile. They do not help while you are logged into an account either, and they do not stop fingerprinting. What they buy is containment going forward: every new signup is one fewer place your real address gets typed, hashed, uploaded, and sold. I would rather tell you that than sell you a fantasy.
References
- Meta, "Customer list formatting guidelines for custom audiences" (documents hashing of customer data before upload and matching): https://www.facebook.com/business/help/2082575038703844?locale=en_US
- Meta for Developers, "Custom Audience" (API reference for hashed audience data, including SHA-256 email hashing): https://developers.facebook.com/documentation/ads-commerce/gateway-products/signals-gateway/custom-audience




Top comments (0)