Skip to content
Guide October 1, 2026 · 6 min read · By Smailor Team

What a Tracking Pixel Learns When Your Team Opens an Email

Most marketing emails, a good share of sales emails and some phishing emails contain an image you never see: a 1x1 transparent pixel hosted on the sender's server. When your mail client displays the message, it downloads that pixel, and the download is the report.

The pixel is only the most obvious case. Any image that is not attached to the message, a logo, a banner, a product photo, works the same way. If your mail client fetches it from the sender's server, the sender gets a log line.

What the request reveals

An image request is an ordinary HTTP request. Nothing exotic is needed to read it. On their side, the sender sees:

  • That the message was opened, and when. Down to the second, every time it is opened again.
  • Your IP address. That gives a rough location (city or region) and the network you are on: home connection, office, mobile carrier, VPN.
  • Your browser or mail client. The user agent string names the software and often the operating system.
  • Which recipient opened it. The image URL usually carries a unique identifier per recipient, so the open is tied to your address, not just to the campaign.

None of this requires you to click anything. Opening the message is enough.

Why it matters more in a shared inbox

In a personal inbox, one person opens a message once or twice. In a shared inbox, the same customer email might be opened by three or four teammates over a day, from different places.

Each of those opens is a separate request. A sender who watches their logs can learn:

  • how many people on your team read their message;
  • where those people are, and whether some of them work remotely or abroad;
  • your team's working hours and how quickly the message was picked up;
  • that a message was read even if nobody replied, which is useful leverage in a negotiation, a dispute, or a sales follow-up.

For most senders this is harmless analytics. For a supplier you are negotiating with, a customer in a dispute, or someone probing your company before a phishing attempt, it is information you did not choose to give.

The usual ways to stop it

Block all remote images. Most mail clients have a setting for this. It works, but newsletters and receipts arrive as broken layouts, and people end up clicking "load images" on everything, which brings the tracking back.

Use a client that proxies images. Some large providers fetch images through their own servers, so the sender sees the provider's IP instead of yours. This hides your location and network, but the sender still learns that and when the message was opened, because the proxy fetches the image at that moment.

Strip known tracking pixels. Filters that recognise 1x1 images and known tracking domains catch a lot, but not a full-size logo served with a unique URL.

The honest summary: a proxy protects who you are and where you are; only not loading the image protects the fact that you read the message.

How Smailor handles it

In Smailor, your browser never contacts the sender's server for an image in a received email. Every remote image is fetched by Smailor's servers and shown to you from there, so the sender sees Smailor's IP address and a generic client, never yours.

Two modes are available in Settings > Preferences > Images in received emails:

  • Show (the default). Images appear normally, loaded through Smailor. The sender cannot see your IP address, location or browser, but can still see that the message was opened.
  • Ask. Nothing remote loads until you choose to load images on a given message. Until then, the sender learns nothing at all, not even that the email was opened.

A few details that make the difference in practice:

  • It is not only <img> tags. CSS backgrounds, the old background attribute on tables and web fonts are covered too. The email is displayed with a content security policy that refuses any other image, style, font or media origin, so a sender cannot slip past the rewrite with a stylesheet.
  • Each teammate chooses. The setting belongs to the person reading, not to the mailbox. One teammate can keep "Ask" while the rest of the team loads images through the proxy.
  • It is on every plan, including Free. Privacy is not a premium feature.

Outbound open tracking is a separate thing: it is off by default in Smailor, and only happens on mail you send if you switch it on.

A quick checklist for your team

  1. Find out whether your current mail client loads remote images directly or through a proxy.
  2. Decide whether "they can see we opened it" is acceptable for your support inbox. For most teams it is; for legal, finance or procurement inboxes it often is not.
  3. If you share an inbox, remember that every teammate who opens a message is a separate signal.
  4. Treat a "did you get my email?" follow-up that arrives minutes after you opened something as a reminder that the sender was probably watching.

If you want a shared inbox where the default already protects the people reading, Smailor's free plan covers up to three people on your own domain.