A large enough proportion of opens either does not trigger an image retrieval or triggers one but the user won't read the message anyway, so open rates have always been approximate. The time of day, the news, the weather all distorts the data so much anyway that the only sensible use of the data is trends, so it'd take some effort to distort the data enough for it to be useless.
Your best suggestion I think would be to rate limit it, with the caveat that if you want to immediately deliver messages you'd need to also open on demand, and e-mail opens are extremely spiky so you might struggle to smooth out the opens entirely, but it might be enough to make it useless enough for people to ignore the data.
You need but one image, to craft an arbitrary number of unique urls using a querystring.
In theory one could also use all permutations of uppercase/lowercase letters in the path to the image. Most webservers are case insensitive so all will yield the same result but I believe the http standard considers the path to be case sensitive so all those urls would be unique.
Well, that is going to be a problem for the mailer. I'm totally fine with banning dynamic parameter dependent images.
> Good luck explaining to your customers what happens when someone finds a way to effectively poison your non-unique image cache with something offensive.
I would say it is the email marketer fault for using unsupported parameterized images. I cannot image a legit use for that, and many evil spammy ones.
The problem is this would not just happen to e-mail from email marketers, but also between regular users, and it would take just one particularly nasty exploit of cache poisoning of urls to some site with user-generated content before you suddenly have the press asking you why some innocent picture sent by someone underage to someone else underage was replaced by your site by hardcore porn - or worse.
I've run a webmail provider. I've seen the amount of abusive bullshit spammers and scammers do whether for profit or for fun or to get back at someone. It used to be my job to find these kind of issues before bad guys did, and one thing we learned very quickly was that every little thing like this would instantly have people probing it for ways to abuse it to cause grief for someone else. Or for us.
If you were going to ban images parameterized by URL parameters (and that would not ban parameterized images, just reduce the number of sites that could be attacked), the only viable choice is not load them at all. Just stripping the parameters would be an absolute disaster and wildly irresponsible.
It's not worse than allowing a randomly selected subset of HTML in the emails, and nobody is saying it is an "absolute disaster" or saying that google or Microsoft are "wildly irresponsible". The mailers and people will get used to it. As they always do.
Actually a provider could cache the hotlinked resource and remove almost completely the reflection.