Calling it out is the best one can do without getting trapped in a cycle of low-effort premises and high-effort responses.
Although, as usual in HN, the premises come from different accounts, so both are valid. And it probably reveals valid addresses when the image URL is unique for each email.
I'm really not (honestly!) trying to invalidate anyone's point or win any argument - my post is more of a question-in-disguise: the GP post I was replying to concerns message-read tracking; whereas my post invokes the entirely separate matter of external actors being able to determine the validity or existence of a gmail address.
I'm not moving the goalposts; you guys are talking about the NFL game's goalposts; I'm talking about the FIFA world cup game goalposts.
Analogously, the issue would be out of bounds then, as the issues are distinct, and so a failure mode that discloses the existence of an email account is not a failure you can lay at the feet of any particular provider of email accounts, but is partly an implementation detail of how different email providers respond to emails to nonexistent addresses. That particular failure (disclosure of the existence of an email address) and any potential solution is considered out of the scope of the problem in the thread (disclosure of the opening of an HTML email due to loading tracking pixels).
This was a big announcement with Apple Mail Privacy Protection, included in iOS 15 (Sept. 2021). Sent marketers into a small panic.
If Gmail did so as well, should’ve been bigger news and figure they’d remind us we could disable the load remote content option.
One of the earliest (2013) mentions I could find: https://gmail.googleblog.com/2013/12/images-now-showing.html
Found in this old article about the initial launch: https://words.filippo.io/how-the-new-gmail-image-proxy-works...
Since 2013, marketers haven’t known WHERE their readers are simply from users opening an email in Gmail.
But today, marketers don’t know IF their readers even open an email if users use Apple Mail.
Partial quote from the second article: “The issue is that the single most useful piece of information a sender gets from you[/the proxy] loading the image is that/when you read the email. And this is not mitigated at all by this system [b/c] when you open an email the server will see a request. Mix that with the ubiquitous uniquely-named images … and you get read notifications.”
(I want _neither_ to leak my IP _nor_ to have “Read Receipts” enabled when I get spam or whatever.)
Edit: one marketing site describes a new category of Apple Opens (vs. Human Opens), so sounds like the feature’s effective
But you can read gmail in thunderbird or any other email client, and in that case gmail still doesn't know anything more than that your client performed a sync, which it might be doing periodically at all times and so isn't meaningful.