Skip to content

What Email Trackers Actually See When You Open a Message

That newsletter knows more than you think. A plain-English tour of tracking pixels, wrapped links, and what changes the moment you block them for good.

  • 5 min read
  • By the Mail Vanish team

The one-pixel image that reports on you

Most email tracking is embarrassingly simple. The sender embeds a tiny, usually invisible image in the message - a single transparent pixel - hosted on their server with a unique ID in the URL. When your mail client loads that image, the sender's server logs the request. That single request tells them the message was opened, when it was opened, roughly where you were (from your IP address), and what device or mail client you used (from the request headers).

Because the pixel URL is unique to you, this is not aggregate analytics. It is a per-recipient read receipt you never agreed to send.

The second layer is link wrapping. That "Read more" button does not point at the article - it points at the sender's click-tracking domain, which logs your click and then redirects you onward. Combined with the open pixel, the sender gets a timeline: delivered, opened at 9:14, clicked the pricing link at 9:16. Marketing platforms score you on this ("engagement"), and those scores follow your address around the sender's ecosystem.

What the sender gets from a single open

Put together, one careless open can reveal: that your address is live and actively read (which raises its value on any list it ends up on), your approximate location, your timezone-adjusted reading habits, and your device. None of this requires JavaScript or anything exotic - just your mail client fetching remote content by default.

What blocking remote content changes

Cut the image request and the whole scheme collapses. If the pixel never loads, there is no open event, no IP, no device fingerprint - the sender sees a delivered message and silence. This is why Mail Vanish blocks remote images in every disposable inbox by default. You can load them for a specific message with one tap when you actually want the pictures; until then, nothing is fetched and nothing is reported.

Scripts are a shorter story: HTML email is sanitized on our servers and rendered in a sandboxed frame, so scripts are stripped before the message ever reaches your browser.

The address itself is the biggest tracker

Pixels report opens, but your address is the durable identifier that links your activity across every database it lands in. The most effective counter is not opening carefully - it is not handing out a permanent address in the first place. An inbox that stops existing minutes after you use it cannot be tracked next month; there is nothing left to correlate.

For relationships you keep, the same logic argues for one address per service: when each sender has a different address, no two databases can join their records on it.

Give spam a dead end.

Forge a temporary email address now - burn it with one tap the moment you're done with it.

  • No signup
  • No password
  • Nothing to clean up