EmailOracle (YC W10) Tracks Your Emails and Confirms They've Been Opened
lifehacker.com
lifehacker.com
You might as well steal some of the (very clever) tricks used here: http://litmus.com/email-analytics to track whether the messages was forwarded and the time spent reading. They don't work all the time, but it's a pretty neat piece of code.
Could you tell me more about the "clever tricks" they use Eli?
Edit: I just thought of another trick: using the background-image or list-style-image CSS property to request an image from your own server. I found a chart that shows CSS support in major email services. Gmail looks like it would be the hardest to implement tracking in. In many other email clients it would be trivially easy:
http://www.campaignmonitor.com/downloads/documents-tools/Cam...
Though I think you have a much better chance of getting people to load images in a newsletter or marketing message where that's the norm versus a personal message where it might seem weird or unnecessary.
Hmm, very interesting. So they essentially make their server side script sleep for a few seconds, but not long enough that the client gives up waiting, then they send the client a redirect to the same script again. When the client stops requesting the fake image then it is safe to assume that the email is no longer being read.
That is a great idea, very innovative. I wondered how they were measuring how long the email was read.
As others have mentioned, many email clients automatically block image downloads by default. So this way of tracking, at first glance, seems pretty limited.
https://secure.grepular.com/Apple_Mail_Privacy_Hole
https://secure.grepular.com/iOS4_iPhone_Email_Privacy_Leak
https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunder...
I created a web application which crafts an email with lots of tests and sends it your address. When you open it, it tries to "call back" to my server and the web page shows you the results. If you see anything on there before hitting "Load Images" your client has a problem. You can access the app here:
Open-tracking is just one of the features we have, and not central to our entire product. Response-tracking is something that we anticipate more people want to use, and is guaranteed to work in our implementation.
Thanks for the ideas! Stay tuned for our new features that we have planned. We named ourselves EmailOracle for a reason :)
I am curious because part of my startup-in-progress will eventually include tracking of email notification reading using images, or other tricks.
Why not to use real read-recepit requests (MDN, DSN) and respect someone's rigth to disable it in their mail client?
I remember noticing an image bug in a resume a web designer sent me once. I thought it was a bit tacky.
This is also evidenced in how MS Outlook provides read-receipts for their emails, and Blackberry messages that also automatically do read-tracking.
Makers of a kitchen knives cannot really prevent customers from using the tool for nefarious purposes. We do our best to preserve the privacy of recipients and allow opting out as well.
Which everyone who is aware of it disables. I'll be blocking your service on the firewall, just good information hygiene. Thanks for announcing it here!
A few responses from people who don't like this idea might include:
- Blocking the service
- Auto-opening and auto-reading "every" email that comes into their inbox (no way to tell which one was/wasn't read)
- Being extra-careful, reading emails selectively (e.g. don't read anything after 4pm otherwise you might get stuck doing overtime)
As you might tell, I'm personally not a fan of this. But if I were a lawyer, or boss, or part of law enforcement, I might like this idea. The current implementation of "email receipts" is very broken, especially in the corporate world.
The thing is, if a company or employee ever gets burned by this, they'll block it. Most everyone I've worked with turns email receipts off in Outlook for this reason.
Don't take my cynicism to heart though. Nobody has tried this idea in this way (that I'm aware of). It's very interesting. You never know how it'll pan out unless you try. Plus this is just the opinion of some dude on the internet; not a very good indicator if it'll succeed or not. ;)
Best of luck to you and your team! :)
Unless I'm reading this wrong, the service relies on the broken misfeature of many modern email clients that diverge from the original RFCs for mail by treating HTML as something they can process. A client that only handles plain text email (with attachments as something separate to hand off to an external program) is safe from this kind of abuse.
Yes, we agree that this tool will not appeal to everyone, but it is something that a lot of enterprise users have requested and thus we have built it with them in mind.
We'd also like to emphasize that open-tracking is only 1 feature in the bundle of tools that EmailOracle will offer, but it happens to be one that we were ready to launch with.
There is no legitimate use or business-case for a read-receipt service, especially ones that use the same techniques as malware writers.
I fully support your third-party "who responded to me?" reporting & reminder tool, as I can see that being incredibly useful - especially to those who are not adept at scripting and/or using mailer APIs.
While I strongly dislike Outlook, their opt-in read-receipts are the best implementation that I know of as far as privacy and ease-of-use are concerned.
Good job funding this garbage, PG.
So I once and for all forbid you to include any of your tracking technology into any message that is sent or forwarded to any email address that I currently use or own, or which I will at any time in the future use or own. In addition, I also forbid you to collect, store, process or share any information related to any email sent to or recieved by me or any email account I can access, or related to any device or software I may use to access this mail. And no, I am not mad or gullible enough to tell someone so completely lacking in moral judgement as to even think about implementing a feature like that and then defending it in the way you do any information about my email adresses, to protect them against being sold to other equally dishonest email senders, or abused in other ways.
Do I have to give you all my email addresses that I want to opt-out with?
Do I have to get an "optout" cookie so that the server with the tracking pixels and whatnot knows not to track me?
I think I'd rather block this at the email client level. This way I don't have to trust anyone's optout procedures, as well as being protected from any nefarious trackers that don't care about things such as opting-out.
I would like to know if blocking images is enough to not be tracked. Do email clients have sufficient image blocking or do they let through images specified in CSS (or similar) through?
Yes, please.
That would definitely be a non-evil thing to do, and go a way towards reassuring those of us who don't like tracking that your intentions are good.
How about mandating a footer that discloses the tracking feature and has a one click opt-out link:
"The email you are reading is using EmailOracle tracking to notify the sender upon first read in order to provide you with better service. If you would like to opt-out of all tracking from EmailOracle, please [click here]. To learn more about this product [click here]"
Failing that, I reserve the right to mark your email as spam and/or report you to spamhaus.
It's just... creepy.
If you have a legal need to make sure I've received something, use registered post.
I recall spammers using precisely this technique with early html supporting email clients in the late '90s to validate email accounts.
The don't realize that this allows spammers to track whether or not the email address is live, they just think that it saves them from having to click "Show All Images".
How is an apparently viable business based on such a non-platform?
After going over the comments here, there is apparently a (well known) trick of adding images to email, then tracking hits for that image on your server, thus giving you "email analytics". Apparently this is one of the reasons that most email programs block images by default. In fact, I've long wondered why images are blocked by default, and only now found out.
Always amazes me how many things I have yet to learn!
Also, to the people who are saying images are not displayed in most of the email clients, browsers, don't forget smartphones where there is no option of blocking images.
iframes
inline css style tags with an @import option.
external css style tags
object embed tags
It also honours meta refresh tags and opens the standard web browser entire automatically just by viewing the email.
Can you please test Froyo using my app at https://secure.grepular.com/email_privacy_tester/
I'd be interested to know if all of these flaws still exist in newer versions of Android...
I really like the idea of an "expect followup with in N days" feature for GMail. It's interesting that GMail's dominance as a client for heavy email users has accidentally enabled a market of add-ons delivered as browser extensions.
It adds a link in the left panel of Gmail (under "Contacts") that lets you open up a new pane (just like the "Tasks" pane) that contains all of your emails needing follow-up.
But quickly looking through the site...who are you? DNS records show private whois...GoDaddy's Domain By Proxy service. I'm logging in by giving my Gmail or GoogleApp credentials but is this through OpenID? Is there a terms of service before I do this? If you were a known entity I'm sure I would be quite a bit more forgiving.
Also, I saw a previous comment here by Tim about no visible pricing info by Tim...why should I have to login just to see what is required for an upgrade?
I'm interested but too many reasons for hesitation has me clicking away...
Having worked with attorney's. "I didn't get the email" is common. I'd like just to have a list of the response codes from their server to prove that they accepted delivery.
Google is not finding anything; maybe it's gone now.
Um, isn't that kind of an accepted risk when giving someone something? This whole thing sounds very fishy to me, actually.
How does it work? Their about page is very very vague, and uses some double-talk to make your message seem incredibly secure (specifically, the hard-to-print FAQ entry: http://www.bigstring.com/info/faqs/answers/printed.php)
i, for one, am looking forward to incorporating this into my workflow.