So in short, if you have all mails set to display as plain text rather than HTML, there's no problem?
There are two ways to mitigate this attack
- Don't use HTML mails. Or if you really need to read them use a proper MIME parser and disallow any access to external links.
- Use authenticated encryption.