The catch is that images are not displayed by default. Why would an attacker click on show images? Only if the text of the email asked them to...
EDIT: I'm wrong as pointed out by others in the replies below.
EDIT: I'm wrong as pointed out by others in the replies below.
I suppose an attacker could bypass this method by turning off images in their browser though.
His canary is a mail that has already been opened, so the attacker assumes he can look at it harmlessly.