DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Senders know when you open emails; block the tracking pixels

Every email you open reports back to its sender: when you opened it, your rough location, and the device you used. The fix is mechanical: block remote images in your mail client, and treat every link in a marketing email as a tracked redirect. I run AliasFleet, an email-alias service on one address per site, and this guide covers both halves of the fix.

How the pixel reports you

Marketing emails are written in HTML, the same language as web pages, so they can pull images from the sender's server the moment you open them instead of carrying the images inside the message. Hidden among the logos and banners sits a transparent image, often exactly one pixel square, with a unique address per recipient. Your client fetches it. The server logs the fetch. That log line is the "open" on someone's dashboard.

The EFF once found one of these pixels in a Whitehouse.gov subscriber email, sent by a government contractor. If the White House mailing list carried one, your inbox has them by the dozen. At the BBC's request, the email service Hey analysed its own traffic and found about two-thirds of emails sent to private users contained a spy pixel; it now blocks more than 600,000 tracker attempts a day, according to ZDNet.

The pixel is only one of the standard methods. Salesforce lists three: the pixel, link wrapping (each link rewritten per subscriber so the sender's redirect server logs the click), and read receipts. Browser extensions do it too: Right Inbox, with more than 250,000 Chrome users, embeds a 1x1 invisible pixel at send time, per Gblock's breakdown. This guide takes on the first two, because they are the ones firing in your inbox right now.

What the sender actually learns

The pixel's fetch hands the sender a small file on you. The time you opened the message, down to the minute. How many times you reopened it, because each open fetches the image again. Your IP address, which maps to a rough location, the same way any website visit does. And your device type and email client, from the user agent your client announces when it fetches. PopSci's explainer sets the boundary: it reports location, device and clicked links, but it cannot read your inbox contents or your computer's files.

The open event alone has value. It proves your address is real and checked, which makes it worth more to the sender and to anyone buying lists. Senders heavy on pixels sometimes mail you more when you never open, or quietly cut you from a list you wanted to stay on. And open tracking is the default, not the exception: Mailchimp, HubSpot, Constant Contact and Klaviyo switch it on for every HTML email they send, per online-tech-tips.

The alias does the other half

Blocking the pixel stops the reporting. It does not change what the sender holds in their database: your address, which is exactly what leaks in the next breach. That is the address half of the problem, and it needs its own fix. I run AliasFleet, an email-alias service built on one address per site. Image blocking keeps the sender from learning your behaviour; the alias keeps them from holding the address you actually live in.

You give each site its own email alias instead of your real address. The sender's tracking data and their database entry both point at that one per-site address. When the site leaks it, or its tracking gets creepy, you pause that single alias and the whole channel dies while nothing else in your life changes. An alias is a persistent forwarding address you manage, not a disposable email service: you keep it for years and switch it off the moment it misbehaves. The set-up guide walks through it in about two minutes.

Stop it in Gmail

Gmail has one setting that kills pixel tracking at the source: it simply refuses to load images until you say so. The setting lives in two places, web and app, and they are independent, so change both.

On the web: click the gear icon at the top right, choose See all settings, stay on the General tab, scroll to Images, and select "Ask before displaying external images". Then scroll to the bottom and click Save Changes. The full walkthrough covers the web, Android and iPhone steps.

Gmail's Images setting with

In the app: tap the menu, open Settings, tap your account, tap Images, and choose "Ask before displaying external images". Repeat it for every account in the app.

After the change, each email shows a "Display images below" prompt at the top, and trusted senders get an "Always display images from this sender" option, so newsletters you actually want still render. Two things to know first: the setting also turns off Gmail's dynamic email, the interactive kind with live content, and it only applies inside Gmail itself, on the web and in Gmail's iOS and Android apps, never in third-party clients, as MakeUseOf confirms.

Gmail's

Gmail already weakens the pixel before you touch anything. Since 2013 it has served every email image through its own proxy servers, so senders never see your IP address or device details, only that the message was opened, as MarTech documented. One tracker's guide puts it bluntly: the proxy blunts the tracking but does not block it, because the open event still gets through. "Ask before displaying" is the setting that actually blocks it.

Stop it in Apple Mail

Apple took the stronger approach. Mail Privacy Protection, in since iOS 15 and macOS Monterey, loads all remote content through Apple's proxy servers in the background, the moment the message arrives, not when you open it. Apple's own wording on the support page: it hides your IP address so senders cannot link it to your other online activity or determine your location, and it prevents senders from seeing if you have opened the email.

From the sender's side the effect is perverse. The pixel still fires, but it fires because Apple's server fetched the image, not because you did. The sender sees an "open" they cannot trust, your real IP and device stay hidden, and the protection is on by default with no switch the sender can flip, per one 2026 analysis. A deeper technical breakdown confirms the timing: the fetch happens at receipt, so it proves nothing about whether a person ever looked.

Check it is on. On iPhone: Settings, then Apps, then Mail, then Privacy Protection, then toggle on Protect Mail Activity. The exact path varies between iOS versions; older guides show Settings > Mail > Privacy Protection, so follow whichever your phone shows. On a Mac: open Mail, go to Mail > Settings, click the Privacy tab, and check Protect Mail Activity. Macworld shows the same steps. It is usually on by default, but verify rather than assume.

What blocking does not fix

Image blocking stops open tracking. Three things it does not touch.

The links. Nearly every link in a marketing email is rewritten to pass through the sender's redirect server, so clicking logs the click, the time, and sometimes your device type. None of that changes when you block images. Treat every link from a sender you do not trust as a tracked redirect, because it almost certainly is.


Blocking images makes your opens invisible. One click undoes that invisibility for that email, and tells the sender more than any pixel ever could: not just that you opened it, but what interested you enough to act on. If the email is from a sender you do not trust, do not click through to find out what it says.

The ghost open in Apple Mail. With Mail Privacy Protection the sender still sees an "open"; the ambiguity is the whole point, they see the event but cannot tie it to you. If you want no event at all, MPP alone does not give you that. Only blocking remote content entirely does, and that turns every email into placeholder boxes.

The corporate read receipt. Plain old read receipts still exist, mostly in corporate Outlook, where they pop up a request you can decline, as Microsoft's own documentation confirms. Your company mail is a different situation anyway: admins can log activity at the server level regardless of your client settings. This guide is for your personal inbox.

Two minutes of settings and the quiet reporting stops. The pixel stays in every marketing email, firing into the void, telling the sender nothing about you.

Top comments (0)