Spy pixels in emails 'have become endemic'
bbc.co.uk
bbc.co.uk
This is the reason why I had to implement a tracking pixel on https://hndigest.com
Tangentially related anecdote: I also had to implement redirects instead of direct linking to the stories: At one point a URL with the .tk TLD was at the top of HN, and as soon as I sent out the first email with that story in it, my email sending service immediately flagged my account as a spammer and blocked all my sending, because the .tk domain was such a red flag. Since then I redirect all stories through my own domain, to avoid any other TLD red-flags from crippling the service.
It's difficult running a legit DIY newsletter, every party involved is super suspicious and one wrong move or mistake can end it all.
Edit: A lot of people are wondering about why I think people press the spam button instead of unsubscribe, so let me elaborate a little more. HNDigest uses double opt-in (you receive a confirmation email which you need to click on before you're subscribed), listens to all feedback loops, has an instant unsubscribe button. We never spam or send emails that weren't requested by the user. By all accounts, it's a legit newsletter and I try to be as above board as possible.
Yet 30% of all unsubscribes happen because someone has marked the email as spam. I know this because this generates a notification on the feedback loop, and then I immediately stop sending of course. These are the facts. So, assuming HNdigest is not actually spamming (which is something I do believe), 1 out of 3 people click the spam button either by accident, or to unsubscribe.
You may have had this happen before and probably thought that was just a scammy way to get you to click a link, but in fact it's completely legit.
Clearly that would be worst possible practices.
I'm subscribed to some mailinglist that I don't actually read but would be upset if they auto-unsubscribed me, because if I'm ever interested, I want it to be there.
It doesn't mention pixels anywhere, though.
It does contain the line:
> "Consider unsubscribing users who don’t read your messages."
But that's only after lots of mention of opt-in and unsubscribe options. And ultimately, you can't really know whether users read your messages or not.
Using a tracking pixel isn't perfect, but like what peter said in another comment somewhere here, it's the best we've got. If you want to implement Gmail's (and other ISPs) best practices, then you need to do tracking of engagement. Just because you don't like it, does not mean that is not considered best practice. Just because it won't be 100% perfect, does not mean it's not considered best practice.
You may disagree that it should happen, but you cannot factually say it is not a best practice.
And personally, I still think it's a bad idea to automatically unsubscribe people who are interested in your newsletter merely because they're not loading images. At the very least, make it very explicit that you're going to do this, and maybe give them the option to turn the auto-unsubscribe off.
Better email clients know to use the header, and e.g. gmail even asks about properly unsubscribing when marking a newsletter with that header as spam iirc.
Spam companies often use this to check if the email address they've targeted is real because they get callbacks from legitimate users. I've only seen one or two legitimate uses of the header as far as I can remember.
As if gmail ui wasn’t already obscure af. They could make “don’t want this anymore” button that uses unsubscribe header first and if it doesn’t work, mark it as spam automatically. Many shady practices would disappear at that same moment, but who cares when making six figures a year.
If only email could work as a modern instant messenger - no spam, reacting to explicit and well-defined user intents, allowing file transfer without limitations that render that function useless, and delivering messages in less than a second.
It is unfortunately not implemented by most email clients.
AFAIK, Gmail does as well.
The only scenario I can think of is when people didn't intentionally subscribe or were coerced into subscribing and those newsletters can go to hell and fully deserve to be marked as spam.
Yeah that's the better part of 95% of them for me.
If you're running a legit newsletter that people want I can't imagine enough people would be marking it as spam for it to actually affect your reputation.
100% of them for me because i don't want any stupid newsletters. Yes, all of them go into the spam folder.
For some business that I otherwise am a customer off i also forward their shit spam to their support and tell them to unsubscribe me, even if they have a link. For the simple reason that if they feel like they can waste my time with their shit, i'm gonna waste theirs too.
I think this is received wisdom that might have been true 20 years ago, but doesn’t stand up to scrutiny.
So for me, it does stand up to scrutiny, it still happens.
But I have scripts that count them, and when they get to five I then make the decision. Again, sometimes I continue simply to bin them, but sometimes I click the unsubscribe link. Mostly then they stop and there's no additional problem, but more than once that address has been used on other spam emails, and only after the unsubscribe.
Do you have actual evidence that it doesn't happen? You might, as others have, be arguing that it's not worth the spammers' effort. But setting up a script triggered by an unsubscribe is pretty trivial, and emails can then be sold at a premium, accompanied by a certificate of sorts that the address is valid.
So maybe it is worth their while.
Then they will go into their email client and click the spam button on both of the emails that I sent them. The confirmation email, and also the test email.
Even though they requested these emails. Even though both emails have an unsubscribe header and link which takes them to a place where they can opt-out in perpetuity from receiving any further email from me.
I know this, because I get feedback loop emails when people do it.
This happens regularly.
They then told their email provider that the email they requested was spam.
I've considered putting up a page with a list of these peoples email addresses, but I feel like it would end up causing me more problems than it's worth.
[edit] There should be a system where I can prove to an email provider that I was in fact given permission to send to an address (for a period of time, and/or for a specific quantity of messages). If there was a standard email header where you could stick a callback URL like:
Request-Permission: url=https://www.example.com/callback period=1D count=10
Then when e.g Google receives this message, they could have some sort of UI to say "The sender of this email wants permission to send you up to 10 emails for the next 24 hours". The user when then click yes or no. If yes, Google would fire off a request to my callback URL, so both me and Google knows I have permission. Google could then skip/reduce spam filtering for those emails then too.Yes. It’s clear that you have no intention to reach them afterwards. But to them it is not so clear, and they mark these innocent letters as spam preventively, out of habit, cause other sites committed abuse in the past and they don’t want to test yet another service’s good nature. Much easier to ban you forever and forget about that, even before you did something unexpected. I know it’s unfair, and I don’t act like that, but they can and some of them do. No time on their hands to differentiate. Modern email culture is rotten to the core and popular email services only cultivate that.
Once pressed, it would replace the “spam” UI element with “unsubscribe”.
Sometimes the spam/phishing line is hard to draw (especially without clicking a link and seeing what they try to make me do) and the 'unsubscribe' link is clearly just part of it, too.
Does anyone know what 'report phishing' actually does in Fastmail? I've had to use it a lot recently, and could easily create a rule for when I've been doing it, if only 'report phishing' was an available action. That it isn't makes me wonder if there's manual review or something so they don't want so much bulk? (And in that case probably also don't/want need my tens of ~duplicates a day.)
It's worse because the next time you receive a post from a newsletter you unsubscribed from, which may be weeks after you unsubscribed, you may actually start doubting if you did unsubscribe from them. There's no way to know, and this seeds some doubt in your mind.
So the next time you want to unsubscribe from a newsletter, legit or not, you're just going to press the spam button because there's no downside to you as the reader, but there is the upside that your mail client will from now on keep out the newsletter posts no matter if the newsletter would actually have unsubscribed you or not. Basically the "mark as spam" button is a 100%-unsubscribe button, while the unsubscribe button is a 95%-unsubscribe button.
I don't believe the situation of malicious actors in newsletters is actually as bad as some HN comments make it appear. Most legit use double opt-in and have good unsubscribe policies. As usual it's the few bad ones that ruin it for everyone.
I'm not sorry if I threw anyone's metrics off, they broke the law, they spammed me, it's on them.
I've given up on unsubscribing the 'right' way. Too much bs most of the time. It's now just mark as spam and move on.
I wish I had a 95% success rate when trying to unsubscribe...
I've noticed a few times that a company I have unsubscribed from years ago will suddenly start sending me mail again. Usually I'll just re-unsubscribe and they'll go away again.
I've also had it several times that I clicked on an Unsubscribe link and the resultant page indicated I had been removed from the list but I continued to receive mail noticeably past the date indicated ("it may take up to a week for your name to be removed, as some mail is queued in advance"). Conveniently, when I followed the link with my ad blocker disabled the request succeeded (without any change in appearance), but I actually stopped receiving their spam.
I can't say anything about email newsletters, because I don't subscribe to them.
You're assuming that they willingly signed up for it and weren't added to the list because of someone selling their data to another marketer, a dark UX pattern tricking them into signing up for the newsletter when they made a purchase, etc.
I tend to agree. Also, newsletter that try to track me with invisible pixels can go to hell, too.
Or you get one of those mail saying "We are removing you from the list because you don't read our newsletter", often without offering any other confirmation signal. Basically they says "Let us track you or you are out of this list".
And this is also the result of marketing people who look at ways to increase the "good numbers", more likely to show to their bosses. They don't actually care if you read or enjoy their content, you are either one of the users who increase their opening and click rates, or you're a useless burden to them.
Seems like nothing of value would be lost?
> They don't actually care if you read or enjoy their content, you are either one of the users who increase their opening and click rates, or you're a useless burden to them.
Confirms that indeed nothing of value would be lost. It seems like a win-win situation, spam-letters you wouldn't want to read anyway eventually remove you off their spam list because they can't stalk you.
Although I will give you that the vast majority of auto-removals have been beneficial for me.
That would depend on the newsletter. Some newsletter provide lots of value for those wanting to keep up to date with minimum effort.
It could also be a newsletter you need to monitor for work purposes.
> They don't actually care if you read or enjoy their content, you are either one of the users who increase their opening and click rates, or you're a useless burden to them.
No they care more that you don't reduce their deliverability rate and that is affected by email service providers deciding if you're not opening the email you're not interested, not reading and enjoying the content and therefore and don't want the content.
A lot of value could be lost. There are one or two newsletters I get by email which I read frequently and may contain extremely valuable information (i.e. could result in a significant sale). It could easily be a pretty significant loss to the company (and me) if they stopped sending them.
Leaving people in the dark about this sort of requirement should be considered an anti-pattern.
Unspoken assumptions are always going to be wrong for some people.
When unsubscribing, users are very sensitive to any subsequent emails (just read the other comments in this thread). Sending an email to confirm their unsubscription might annoy a lot of the users, or will make them doubt that you're above board ("legit" newsletters boast about not sending any emails after unsubscribing, so this is a little red flag) - they will then flag that email as spam, and then we're back at square one.
They also get annoyed when you ask them to confirm that they still want to read the emails.
And Gmail will flag you if you keep sending the emails when they're not opening the emails.
I think there really is no good solution here.
Overeagerly classifying legitimate email that someone subscribed to as spam is no better than classifying spam as legitimate. Especially on a system like GMail where one person's incorrect classification would lead to other people not receiving their subscriptions in their normal mailbox.
But that is not how it currently works.
Is there a reliable way to tell if an account is forwarding to Gmail? That way, you could reserve your spammer tools (not judging you for using them) for gmail users, and treat the rest of your subscribers with the respect you clearly intended.
The reason "You haven't loaded images for n months" is used as a signal is that there's a cost in sending unwanted email to people, and there's often no other way to know if you're wanted or not.
I clearly expressed interest in your newsletter by confirming the double opt-in.
It's also ok if I open your newsletter only once in a while, I may be busy, or I only want to read your content when its title click something in me.
The most successful newsletters respect this and did so for so many years. They never messed up with my subscription. I will never mark them as spam because I trust them. And there is a clear unsubscribe link in every one of them that I can click if I change my mind.
This is nothing new, Permission Marketing from Seth Godin is what, more than 20 years old now?
Instead, automation looks always fun and clever, until your growth-hack goes wrong.
"We found we can increase the number of people subbing for the newsletter by skipping double opt in"
"Why are we getting so many spam flags?"
Because the increase you gained was all the people who didn't want it, cosmic brain. The people who wanted it already had it.
Newer newsletters don't have that reputation, so they are more heavily penalized for low open rate or higher spam flag rate. Thus, they need to react more quickly to users invisible actions or risk damaging their reputation. I don't think this is a growth hack, I think this is a necessary action as a new entrant in a very unforgiving space - see some stories upthread from legitimate newsletters.
While your actions are invisible to the sender, they are _not_ invisible to your email provider, and ultimately they are the ones who make reputation decisions that can destroy a newsletter.
They may well consider this email to be an annoyance, but I think that's better than making an assumption, taking an action and leaving users in the dark. Some will prefer that, but some will be confused about why your service isn't working for them.
So my reward for protecting my electronic privacy is to have my privacy violated through the USPS.
You think the USPS is reading your credit card statements?
It's not just tracking. I generally feel email is more useful with html on and pictures off. You automatically skip most colorful signatures , headers, legal whatever's ..., while still getting nice formatting
(Edit: I just read both Thunderbird and Protonmail do this by default, so maybe I'm not too much of a minority?)
For a while I couldn’t receive email notifications from Facebook because so many other gmail users marked them as spam, so no matter how many I unmarked, I was screaming in the wind.
Fair enough that other people don’t wanna deal with that crap, but it should still be my prerogative to receive them.
I first gave up, and later decided I didn’t care. But for a while I thought it was clever to have an immutable archive of Facebook interactions (those notifications used to include full text of posts you were tagged in or that was written on your wall as well as new messages)
And this is an example of stopping tracking worsening the user experience because the tracking improved user experience by removing people who aren't interested in the list.
> And this is an example of worsening the user experience, where the previous comment is claiming that tracking improves it. There is absolutely no benefit to the user experience with the tracking here, only downsides; it is a punishment for disabling tracking. The only actual reason to track mail opens is pay-per-view advertising, everything to do with monetization and nothing to do with improving the UX.
No it's not it's all about deliverability. Literally, they get penalties in their deliverability if they keep emailing you stuff you're not interested in.
It's not a penalty if you choose to go againist the grain and suffer the negative effects. Stop blaming others for the negative effects of your choices.
Can you please elaborate on this? Do you mean people intentionally avoid this because it leads to the advertisers marking that as "read" and therefore a live user?
Asking because I recently purged my old emails which had thousands of emails, they obviously never stopped sending even with zero interaction.
But my method was to click the unsubscribe link which I was afraid might give them more information about them and doing the opposite of what I wanted. I know some didn't even respect the unsubscribe, I took note of which ones I explicitly clicked and they're still sending spam to me.
My belief about people being weary of the unsubscribe button are elaborated on here: https://news.ycombinator.com/item?id=26164450
But I definitely don't click on unsubscribe buttons in unsolicited mail when I don't really know who it's from. It could be an attempt to identify a valid mailbox (and spam me more), or it could link to malware.
So yeah, rule number 1 of email protection should be: do not tell the scammer/spammer that you actually use this email address. In case of a doubt, click the "spam" button, block the address, but do not click "unsubscribe." Only click "unsubscribe" if you trust the sender, because once you have done it, your email address is suddenly worth a lot more, especially to bad actors.
It's a bit more complicated than that. There are many reasons why a pixel may not fire but the email is still read, and there are many ways pixels can record false positives.
Relying on email opens is really not a good measure of engagement.
Sadly, inbox placement is almost impossible to measure without email open tracking as feedback loops from gmail/hotmail/etc are just not good enough.
It's not, but it's what we have. It's a bit like how counting podcast listeners based off of downloads is a terrible system too but it's all they have to go on (I'm subbed to hundreds and don't listen to 99% of episodes).
I'm always looking for the super hidden unsubscribe button. I don't move to spam. But sometimes I get mails without even subscribing, and that is far worse.
I was frustrated at some points when I was on my early day with my news letter and AWS SES. I don't know why people spend time to register for my news letter, after reading through the archive. Yet, they chooese to mark email as spam even though we explicitly have an unsubscribe link and require double opt-in.
For AWS SES, you have to maintain spam rate at <0.1%. And AWS has their own way to pick sample set of emails.
So yeah, it's really important to manually unsubscribe people that won't read email. Don't even attempt to make a final email to ask them if they want to be remove because you risks another "mark as spam" click.
I'm surprised that people still press spam for a double opt-in mailinglist. Double opt-in is the right way to subscribe, click unsubscribe is the right way to unsubscribe.
People reporting that as spam should probably have their spam reports ranked as illegitimate.
However, plenty of mailinglists are spam. Sometimes I get newsletters in a language I don't even know. Maybe someone entered a wrong email somewhere and the list never verified that it's correct. Sometimes you subscribe to a bunch of spam if you forget to uncheck a checkbox somewhere. That stuff is not something the user explicitly asked for, and the user may have a hard time distinguishing it from spam or phishing, so I can understand reporting that as spam.
Can you give a source/reference for this? I'd like to understand it more.
I don't allow any remote content when I read emails, and I get quite a lot of regular newsletters. Why am I not being unsubscribed?
https://support.google.com/mail/answer/81126?hl=en
CTRL-F "Send email to engaged users"
Some choice quotes:
- "Consider unsubscribing users who don’t read your messages."
- "Periodically send a confirmation message to users to make sure they still want to get your messages."
Also, as someone whose mail client doesn't load external resources for privacy reasons, I'd be annoyed if you unsubscribed me because you weren't tracking my reading. However, an occasional confirmation (say, once or twice a year) as they suggest would be just fine. You could even restrict those to just those subscribers who do not trigger the tracker.
Once you're hit with a ban, it's very hard if not impossible to recover.
If you've been at HN for a while, you must have noticed that every now and then there are stories from Google users being mistakenly banned from their account for violating some rule that they don't even explain to them. These events happen to mailing lists as well, but there's even less of a recourse for mailers when this happens. Considering all this, I'd rather err on the side of caution and implement most of recommendations by Google, than increase my risk of being marked a spammer, and risk losing the whole project.
> However, an occasional confirmation (say, once or twice a year) as they suggest would be just fine. You could even restrict those to just those subscribers who do not trigger the tracker.
What is fine to you, is annoying to others. Just read the other comments on this story, where people commonly complain about receiving an email asking to reconfirm their subscription.
These slackers are the worst. Not only they cause trouble to legit email newsletters, they also affect the subscribers who want to read the email. Every time I check my gmail spam folder, I'll find at least 2-3 legit newsletters classified as spam because "It is similar to messages that were identified as spam in the past." At least gmail makes it easy to tell them apart from email marked as spam because they were deemed malicious.
Personally, I end up clicking spam on a lot of stuff - they get one chance at unsubscribe. If I get asked to log in, or it redirects to anything other than a confirmation page, then I mark it as spam and forget about it. I get too many misdirected emails to give it any more time than that (my email address is my name, many other people share that name, and a lot of them seem to think that they have that email address too).
I don't get it.
If I want to politely unsubscribe from a newsletter I have to: switch from the keyboard to the mouse, hunt for the link in the email and click it, switch contexts to the browser tab it opens, hunt for the primary action on the page, figure out whether that action will confirm the unsubscribe, or whether clicking the button will sneakily re-subscribe me, and then close the tab.
On the other hand, if I report it as spam, I just press "!" one time and (in theory) I'll never see its ilk again.
Reporting something as spam is such a clean experience that I'm trained to use it for things it wasn't meant for, like unsubscribing from a legitimate newsletter. I suspect that this is true for other users as well!
The vast majority of "newsletters" I get today are from companies that assume that I want to keep hearing from them just because I once did a one-time transaction with them. And no, it's not because I forgot to uncheck the "I want to receive blah blah blah" checkbox. I'm careful to opt out whenever there's an option for that.
I don't know about other people, but I call that stuff spam. Just because it isn't an e-mail from someone who got my address from a dump and decided to cold-mail me with their crap (or phishing or other scams), doesn't mean it's not unsolicited e-mail, i.e. spam.
Maybe things have changed over the years and I just wasn't paying attention, but I've trained myself not to press "unsubscribe" on something I didn't explicitly opt in to receive.
Spam is for any kind of email I haven't opted in to receiving. That includes mail from organizations I have never requested contact with, as well as any emails I get as a result of UX dark patterns. I try to opt out, but some of them sneak past, and I don't feel bad dinging it as spam. That's the risk you take with opt-out mailing lists.
Another is if you get signed up for multiple different streams of messages ("What's New!", "Tips to Get the Most out of X", "Company Communications", "Coupons", etc.) just by signing up for an account (and, as you point out, not actually opting in for any of them explicitly). Since Gmail does not always flag all of these different things as spam, it can be more efficient to go to the "unsubscribe" page and uncheck each of these streams yourself.
The only way that this justification makes sense to me is if you mail people that didn't explicitly subscribe to your newsletter in the first place. If that's the case, I think that the problem lies elsewhere.
An email is meant to be read, that's it. Any other interaction a user will have with it that is still under your concern is if they follow any links - I personally object even to that. Assuming to track anything besides people visiting your website from a newsletter link is an infringement of the unspoken contract between you and your subscribers.
I consume most of my email in plain text format. Like me there are others. Your solution is not working for us.
As a sender, it's impossible to get any specifics from Google as to when it happens. You can get a generalized spam report rate from them but that's about it.
How about measuring interaction as the user doing something like logging into your site, buying a product, posting a comment on your site, sending you an e-mail -- those are actual interactions. By not counting simply opening the e-mail as interaction, you can satisfy your worries about bothering people without spying on them. You can use the lack of logins or e-mails from the user as an indication of disinterest.
The profit incentive that's built-in via collection of user data makes any "it's for the user's best interest" argument questionable.
I don't necessarily like the model, but if this is your business model, then there's nothing else that can be measured to monitor ongoing success apart from:
- how many new users signed up
- how many existing users unsubscribed (or marked as spam)
It's a tough ask getting sponsors based on those two metrics alone.
Then it's exactly your job to figure out how to accomplish this in a less user hostile way.
In my experience, that's not what happens. My most recent experience with this was when I had gotten about half way through filling out my info for a service, I was sent an email with a price list, I opened it, looked at the email and decided to wait and compare prices with another provider.
Then the emails started.
'Oh hey we noticed you never finished your registration. I assure you our prices are the lowest anywhere'
Had opened the email but never answered it.
Get another email.
'Hey this is so and so, company president or whatever...if you need any more information, about blah blah blah, don't hesitate to send an email'
So I did...I told them I don't appreciate being spammed because I hadn't finished filling out a web form and i'd like them to stop.
Surprisingly, I got an email back from president dude or whatever apologizing and promising to remove me from the email list.
Yeah...right..
A day later...another email. So I blocked them as spam. I still get spam from them.
As someone who subscribes to lots of newsletters, the "interact or we will auto-unsubscribe you" thing still annoys me.
IF you get spamfoldered by enough people the provider will just start sending to the spam folder for everyone. Your newsletter is now useless
Additionally, if I'm receiving a message from example.com, and links in the message are not targeted at example.com, but some bullshit like sendgrid with a query string that won't fit across a 4K monitor, I'm deleting it.
The other day I received an email from ft.dk, the danish Folketing. Our parliament. I mean legit dot gov stuff. It had email tracking through Sendgrid. I sent them a strongly worded email and asked them to cut American tracking companies out of our democratic process. And then I deleted the email.
All this tracking seems to have just become the new normal, and hardly anyone cares about it.
Of the major email clients, I believe Thunderbird is the only one that does so by default.
As any UI designer knows, if everything is important nothing is important, and so I just treat those as the spam they are. Which lead to a legitimately important mail getting lost, but it only caused problems for them so ironically they shot themselves in the foot with their dark patterns.
Odd thing was, I wasn't on any of their mailing lists.
Which would explain why they didn't register a tracking pixel for a long time.
Anyway, it's been like this for years and the overwhelming majority of email clients load images by default so everyone mostly works around it. I don't think it's changing any time soon.
edit: apparently they automatically cache the images on delivery, which should work. This is really a change that needs to come from the mail providers so good on them. As long as they don't try and assume what the user is interested in like Gmail does, they can drop tracking all they want.
"There's a Big Scary Problem you probably didn't know about, according to the founder of a service that solves that problem."
[Image of what it looks like when the Big Scary Problem is solved by the service.]
[Flattering image of the service founder, and a reference to the service as 'premium.']
However note the intro
"according to a messaging service that analysed its traffic at the BBC's request."
As a Hey user, this is the least salient thing about the service to me, but maybe they think it is the best way to compete with Gmail?
Can I bribe a BBC editor to get them to write about mnm & TMTP? :-)
It also prevents spy-pixels, and phishing, and provides unsubscribe (from threads, or senders, or whole sites).
mnm, an open source project to replace email & SMTP:
I'm unimpressed with Hey's ability to prevent tracking.
While their cache is large, it's not infinite. If what you're interested in is whether a customer engages with an email multiple times over a few days, you'll likely get the pixel hits to confirm it over that time period. Of course, as you imply, you wouldn't be able to collect how many times an hour a single customer has viewed an email sent to them.
You get enough good information. The IP address would be even better however.
The catch is that Gmail caches all the same images from the same servers, so email marketers get around it by serving tracking pixels with obscure, unique URLs per individual.
Geotargeting fails because it loads on GMail servers.
https://jioegijogeijesgioegeg.tracking.example.com/niowefioe.png?sdgsdbuegiu=rojpopwmrmwk
has four places to store unique information.Does Gooogle's proxy remove all of them?
It's processed in the queue and opened. Was it the user? Did it hit Inbox? Where did it got opened? When it's opened? How many times it opened?
All these information's reliability got out of the window with a single optimization. You can't know how this mail was processed and it's fate. So, your tracking pixel and URL returned something useless to you.
Edit: oh :(
https://blog.filippo.io/how-the-new-gmail-image-proxy-works-...
https://blog.filippo.io/how-the-new-gmail-image-proxy-works-...
Apple's macOS Mail.app client displays external images by default, as does their iOS app.
Perhaps they can't figure out a good solution to differentiate between benign images and tracking images; it does seem like it would be nearly impossible to do so, but I wouldn't mind a) blocking external images by default, b) per-sender/recipient settings, and c) clearly displaying "invisible" images and warning about them.
Perhaps someone has some better ideas on how to fight this scourge?
I tend to think that the only practical solution is to block them entirely, but then malicious senders will send URLs that say "click here to view message."
Maybe HTML email wasn't such a great idea.
How do you tell a unique tracking ID from PR-IMG20190312-023045-logo-MARKETING-COPY(5).png?
Yes, HTML e-mail is dumb. But even instant messaging assumes the ability to load/preview images from the web at this point, so probably no real options at this point.
Privacy defaults come down to usability vs. privacy; Apple making this so easy to toggle is fine by me as I care about privacy and tracking.
Now, it would be great if every macOS application walked you through privacy settings right after installation in the same way that I am offered a tour of the new features. Since there is no such "privacy tour", the community has discussed ways in which macOS can be hardened [1], [2].
1. https://github.com/drduh/macOS-Security-and-Privacy-Guide
Unless they're using different URLs for each image for tracking purposes. Which would become pointless if the images were downloaded immediately.
They could probably get away with applying size limits to images too, and simply have placeholder/broken images if the images are unreasonably large.
It would even work for people using normal IMAP clients if they attached the images to the email directly and switched out the href in the img tags to point at the attachment instead.
This whole thing could be a user setting which can be toggled. Defaulting to the most privacy friendly option.
Or only allow inline images.
Here's the one I use : https://protonmail.com/blog/how-big-tech-tracks-users/
And then you get button to show images if you need it.
I prefer to use gmail this way, since most of the images are usually tacky signatures, or legal disclaimers or something else I don't need.
And if there are pictures you need there is show images button.
Settings > Images > Ask before displaying external images
I just found it turned on. I forgot to disable it again after my annual OPSEC-cosplay device-wipe.
The cos in cosplay stands for costume. Roleplay! Unless you are putting on a literal white hat I suppose, that would be cool.
Larp = live action role playing. Where you act as your character, as opposed to table-top role playing, where you say what your character does.
Did you know that Hey allows you to block tracking pixels for the low price of $99/year? Now you do!
Not the kind of thing I'd expect to see from the publicly funded BBC.
See for example:
=> https://www.bbc.co.uk/news/uk-england-stoke-staffordshire-55... 2021-02-03 What3words: Stafford women rescued from flooded river after using app
=> https://www.bbc.co.uk/news/technology-49754820 2019-09-20 What3words: 'Life-saving app' divides opinion
=> https://www.bbc.co.uk/news/uk-england-49319760 2019-08-15 What3words: The app that can save your life
(Yes, that's the headline they used.)
=> https://www.bbc.co.uk/news/technology-47705912 2019-03-26 Three-unique-words 'map' used to rescue mother and child
=> https://www.bbc.co.uk/news/technology-40935774 2017-08-30 TEDGlobal: Three words that give people an address
=> https://www.bbc.co.uk/news/business-32444811 2015-04-29 Giving everyone in the world an address
If I had the time or energy, I'd complain about all of the above.
(It's mutt.)
But Apple Mail, iOS Mail, Gmail, and Outlook alone are probably 80% to 90% of recipients.
Or perhaps users could be required to click remote media to view it. Most users won’t care, so they won’t click it.
The way to solve it is for the email provider to download the images for you, not when you open the email, but as soon as they receive it, and then display the images from their local cache. That way your IP never hits the pixel's home server, and you can see the email as it was intended to be seen.
IIRC, Facebook were using audio tags at one point for email tracking.
In a certain way, for people who are now very accustomed to read receipts, it's a way of adding a modern feature to a legacy product.
I actually wrote about the issue the industry has with tracking on my blog a while ago, and have spoken on a panel and a podcast on the subject too.
There was some great discussion on the blog past when I posted it here https://news.ycombinator.com/item?id=21024926
HTML emails already use only a subset of HTML, so I don't understand why it wasn't trimmed down more to only allow images as data URLs or encoded in Base64.
[0] https://www.litmus.com/blog/qa-with-mailcharts-on-email-file...
Images in email have been around since 1992 (RFC341 Multipurpose Internet Mail Extensions https://tools.ietf.org/html/rfc1341 ) and I don't remember when downloadable images got added to "text/richtext" but the concept of downloadable content is already there in section 7.
I'd say tracking pixels are regularly found in the area of email.
yeah. webmails open images by default so companies like these are charging top dollar for the priveldge
I hope some data processing agency will look into these tracking companies. Without an optional opt-in at sign-up, emails should never include these pixels.
The reason is pragmatic, by the way. HTML mails take longer to read, and I really don't need some crappy graphics or web design when scanning through my inbox.
https://github.com/apparition47/MailTrackerBlocker/blob/main...
https://gist.github.com/dhh/360f4dc7ddbce786f8e82b97cdad9d20
https://gist.github.com/leggett/8c2ab9735037cb66c218fdbe898d...
> if and when an email is opened how many times it is opened
Can someone explain to me how these work? Do you load remote content from a server so it knows that the email was opened? Does it re-download this image every time it is opened?
Some email services will cache the images for a period of time but in many cases it will perform a fresh request each time the email is opened.
Why didn't they interview anyone from the large email providers to get their opinion and learn what they are doing to protect users? Hey.com is a tiny blip in the email universe.
On the one hand, that's pretty courteous, on the other hand kinda unnerving.
This is exactly how it works. The image itself doesn't need to be different. Normally it's a 1x1 transparent gif.
Which makes me wonder why they don't just embed normal images that the user would see, but add something to the href that the server can interpret as a unique id. Either way, email clients that block images will break the technique.
In addition, I think enforcing plain text emails would disable any client side tracking events.
EDIT: Well it looks like that setting in Thundebird prevents any remote connections. Not just pixels, so that be good enough. However emails often have a text back up that is going to be better formatted then a hampered html email.
EDIT: To prefer plain text in Thunderbird it is View -> Message Body As -> Plain Text
It's kinda like suggesting moving to fix a leaky pipe.
But the pressure from Hey is persuading some companies to stop doing it https://twitter.com/dhh/status/1359437390763483141?s=20
So it's not avoiding the root cause entirely
1. Helps to prune users who never open emails thus giving you a smaller more engaged list.
2. Helps to see if the content they are sending to users is leading to engagement so they can send better emails next time.
Yes, yes I know. Why even send emails in the first place.
All email marketing is not evil.
But legitimate marketers have businesses to run in the real world and without these little pixels they would be sending un-targeted and mostly useless marketing messages to legitimate subscribers.
How you casually mention spying in to someone else's home and watching their actions as if it's perfectly normal is really creepy.
There's nothing 'legitimate' about those marketers, they're exactly the problem.
What you are suggesting does not fit in the medium of email, independent of the legitimacy or intentions of the sender.
All open rate tells you is that your subject line was click-baity but the user have no interest in your content