SubscribeGo ProYour plan Settings

You cannot see a tracking pixel by looking at the message, because it is an image one pixel square or hidden altogether. You can see it in the message's source: an <img> tag with a width and height of 1 or 0, or display:none, whose address is on a mail-sending company's server and ends in a long string that identifies you. Paste the source into UNBEACON, or drop the saved .eml file on it, and it lists every one it finds and gives you a copy with them taken out. Nothing is uploaded, and nothing in the message is loaded while it looks.

What a pixel reports

The picture is irrelevant. What matters is that your mail program has to ask the sender's server for it, and the address it asks for contains an identifier issued to you alone. When the request arrives, the server records:

  • That you opened it, and when, and again each time you open it if the image is fetched afresh.
  • The IP address it was fetched from, which places you roughly, and says whether you were at home, at work or on a phone network.
  • What you read it in, from the request's user agent.

Because the identifier is yours, forwarding a message with its pixel still in it means the next person's opens are logged against you.

Seeing the source

  • Gmail on the web: open the message, the three-dot menu at the top right of it, then Show original. The same menu has Download message, which saves it as an .eml file.
  • Apple Mail on a Mac: View → Message → Raw Source, or File → Save As with the format set to Raw Message Source.
  • Other programs have the same thing under a name like View source, View message source or Save as .eml.

The source is not easy to read. The HTML is usually encoded as quoted-printable, so every = in it appears as =3D and long lines are broken with a trailing =, which is why searching the raw text for width="1" finds nothing. UNBEACON decodes that first.

What one looks like

This is the open pixel from a newsletter-shaped message we built to test with, in the form a Mailchimp campaign uses:

<img src="https://riversidebooks.us21.list-manage.com/track/open.php?u=5a1b2c3d4e&amp;id=77aa12&amp;e=f3c9d1a2b4" height="1" width="1" alt="">

Three things give it away: the size, the host (a mailing service, not the shop), and the path and parameters, where /track/open says what it is for and e= is the recipient. The same message carried an ordinary logo from the mailing service's image host and a 600-pixel banner called opening-hours.png. UNBEACON found one tracker in it, removed that tag and nothing else, and left a comment where it had been. It did the same when the HTML was quoted-printable encoded, as a real sent message is.

What it looks for, in full:

  • An image two pixels or smaller in either direction, by attribute or inline style, or an off-site image hidden with display:none.
  • An image on a known bulk-mail or tracking host (about fifty of them), or on a host whose first label is track., open., click. or similar.
  • Tracking parameters in the image address, such as utm_, mc_eid or _hsenc, or a path that is simply /open.
  • The same things in a CSS background-image, which fetches from the network exactly as an image tag does.

What this cannot tell you

Any remote image can be a tracker. A sender who gives every recipient a different address for the logo, on their own domain, at full size, has built a pixel that looks exactly like a logo, and nothing that reads the message can tell the difference from the outside. So a clean result means no recognisable tracker, not no tracking. The only complete defence is not loading remote images at all.

Links are the other half. Almost every link in a marketing email is a redirect through the sender's server, so a click is reported whatever you do about images. SANILINK strips the tracking parameters from a link before you follow it, and UNSUB finds the real unsubscribe address.

What stops it

  1. Stop loading remote images by default. In Gmail: Settings → See all settings → General → Images → Ask before displaying external images. Nothing loads until you choose to show images for that message.
  2. Know what your mail app already does. Gmail fetches images through Google's own servers, so the sender sees Google rather than your IP address, but still learns that the message was opened. Apple Mail's Protect Mail Activity fetches remote content privately in the background whether or not you read the message, so the sender's open report stops meaning anything.
  3. Clean a copy before you forward it. This is what UNBEACON is for. Your own mailbox copy is untouched, and if your mail program has already shown the images, that open has already been reported. The clean copy stops the next reader being logged under your name.

Pixels are not only in newsletters. Add-ons that tell a salesperson when you have opened their email, and a good many sales and recruitment platforms, put one in a message typed by a person to one person. It is the same tag, and it is found the same way.

To see where a message really came from, HEADERPROOF reads its authentication results; MAILBOX takes the whole message apart, including everything it would load.

Questions people ask about How to tell if an email has a tracking pixel

How can I tell if an email has a tracking pixel?

Look at the message source rather than the message: in Gmail, Show original; in Apple Mail, View, Message, Raw Source. A pixel is an image tag one pixel square or hidden, on a mail-sending service's server, with a long identifier in its address. UNBEACON reads the source or a saved .eml and lists every one it recognises, without loading anything.

What does an email tracking pixel tell the sender?

That the message was opened and when, the IP address it was opened from, which places you roughly, and what mail program you used. Because the image address carries an identifier issued to you, all of it is recorded against your name.

Does Gmail block tracking pixels?

Not by default. Gmail fetches images through Google's own servers, which hides your IP address from the sender, but the sender still learns the message was opened. Setting Images to Ask before displaying external images stops anything loading until you choose to show it.

Does Apple Mail Privacy Protection stop email tracking?

It stops open tracking from meaning anything. With Protect Mail Activity on, Apple Mail fetches remote content privately in the background whether or not you read the message, so the sender sees an open either way and your IP address is hidden. It does nothing about tracked links.

Can a tracking pixel be hidden in a normal-looking image?

Yes. Any remote image whose address is unique to you works as a tracker, including a full-size logo on the sender's own domain. Nothing reading the message can tell that apart from an ordinary logo, so a clean result means no recognisable tracker, not certainly none. Blocking remote images is the only complete defence.

Does forwarding an email forward the tracking pixel?

Yes, and with your identifier in it, so the next person's opens are recorded as yours. Removing the pixels from a copy before forwarding it is what UNBEACON is for.

Are there tracking pixels in personal emails, not just newsletters?

Often. Sales and recruitment platforms, and add-ons that tell the sender when you have read their email, put a pixel into messages written by one person to another. It is found the same way as in a newsletter.

Do links in emails track you too?

Usually. A marketing email's links are mostly redirects through the sender's server, so the click is recorded whatever you do about images. SANILINK takes the tracking out of a link before you follow it.

Related tools

More on this

All 9 guides under “Keeping who you are out of it”.

A letter, now and then

An occasional letter when there is something worth reading: the new guides and what changed in the tools. Never more than once a month and nothing else, and you can leave at any time on the unsubscribe page.