How Gmail’s Image Caching Affects Open Tracking
blog.mailchimp.com
blog.mailchimp.com
* Loading images is now enabled by default rather than disabled by default, meaning that a larger portion of emails will be tracked, because it's more likely tracking images will be loaded.
* Images are now loaded through a proxy, which means that all tracking images will no longer provide information like cookies, IP associated with the account, etc - the only information they'll provide is "this specific email was viewed by someone, somewhere."
There is still an option to disable loading images by default. Toggling that option still results in images being loaded through a proxy, so the second item above still applies.
As far as privacy goes, the potential level of privacy has increased (the proxy now allows you to load images if you desire without leaking IP etc.). The average level of privacy from the change is a mixed bag - more basic tracking (open tracking) will occur due to the change of default, but with the trade off that more advanced tracking (e.g. tracking IPs, setting cookies for correlation with non-email site visits a.k.a. remarketing) will no longer be possible.
There is no net change to how hard it is to verify whether an address is a valid GMail address - that's already possible by simply talking to a Google mail server.
> There is no net change to how hard it is to verify whether an address is a valid GMail address - that's already possible by simply talking to a Google mail server.
Thank you.
I read through an unhealthy number of comments on the various threads about this (my train was delayed, and I'd finished the book I brought). Very few people actually seemed to get the key takeaways (your last two paragraphs) correct.
Here's a nice technical blog post from someone who actually knows what they're talking about: emailexpert.org/gmail-breaks-email-marketing-again/
No, if you know who you are mailing, you can add their ID to the link of your tracking image, so you know exactly who opened the mail.
<img src="www.tracking.com/image.gif?user_id&other_tracking_info" >
Google could prefetch those images. Even if the initial tests seem to indicate against this, they can change this on a whim, or they could prefetch with a delay, or they could prefetch only a percentage of those images, depending on ever-changing heuristics. The only useful info advertisers would get from this is that the email was sent to a Gmail account.
Even if they don't prefetch, they can detect duplicates, especially from links coming from domains known to generate tracking pixels and there's nobody else that could do this better than Google. They can also get rid of images that aren't visible to the user (e.g. transparent or white or light gray pixels, or images that are too small to be a part of the content). Tricks like generating images with unique content only work for images with actual content to show.
And it significantly raises the cost of email campaigns too, just as with spam. I don't have spam hitting my Inbox these days and that's not because spam has become impossible. Light spam (e.g. promotions from companies you've got a relationship with) have been moved in the Promotions tab. And I can't remember the last time I've seen real spam hitting my Inbox.
All in all, I'm happy that they are introducing this feature. It's better for regular folks or for me - you know, the kind of people that always click Show Images, because promotional messages are hard to read otherwise (on purpose).
I do hope they provide the option to turn it off. Google is pretty bad at providing choices these days.
Now, they can detect duplicates, but only after they have gotten the contents. Unless I am mistaken on anything. (highly possible.)
Such instances can be detected (e.g. if you see 100 emails with the same HTML, but with image URLs that are slightly different). Google can then prefetch those images or it can re-enable the optin for displaying just for those emails.
If I were to do email tracking, I would just filter the GMail accounts out of the statistics, because you can't be sure of when GMail's proxy loads those images and what you're interested in is the conversion rate (not in the total number of people that opened their emails, you only care about totals for emails sent and clicks). But a service like MailChimp is not interested in doing this, because MailChimp is a third-party that's interested in showing big numbers to their customers.
And putting these numbers aside, the privacy issues related to IP tracking, or the security issues are gone. So I think this is good.
For myself, no need to filter them out without evidence. Keep a few controlled accounts to periodically try and see what the delay is. And get extra suspicious if all images are opened at once on a mass send out.
It's probably an improvement, but not all the way there. For actual privacy, what GMail needs to do (and I realize this is slightly unfeasible due to the amount of email they receive) is instantly open and cache every single email to every single email address (including non-existent addresses).
Before, however, if you never clicked on "show images" then spammers knew nothing at all.
Granted, it's one step further to know if you're getting past the spam filter. But I feel like that's testable using your own accounts.
openssl s_client -connect smtp.gmail.com:465 -crlf
220 mx.google.com ESMTP u17sm2709629qeb.4 - gsmtp
helo
250 mx.google.com at your service
auth login
334 VXNlcm5hbWU6
< BASE_64 USERNAME>
334 UGFzc3dvcmQ6
< BASE_64 PASSWORD>
235 2.7.0 Accepted
MAIL FROM: <my_email>
250 2.1.0 OK u17sm2709629qeb.4 - gsmtp
rcpt to: <my_email>
250 2.1.5 OK u17sm2709629qeb.4 - gsmtp
rcpt to: <emaildne39g39jd9j9jfsdk@gmail.com>
250 2.1.5 OK u17sm2709629qeb.4 - gsmtp
I get an OK with BS emails too... MAIL FROM:<tedu@tedunangst.com>
250 2.1.0 OK g15si484689qej.92 - gsmtp
RCPT TO:<tedunangst1233141@gmail.com>
550-5.1.1 The email account that you tried to reach does not exist. Please try
550-5.1.1 double-checking the recipient's email address for typos or
550-5.1.1 unnecessary spaces. Learn more at
550 5.1.1 http://support.google.com/mail/bin/answer.py?answer=6596 g15si484689qej.92 - gsmtpThat information is worth orders of magnitude less than it used to be, especially for Google hosted email as their spam protection is near-perfect. My email address is available in the clear in a number of archived mailing lists among other places, and I'm not getting any spam at all.
Each e-mail has a unique image URL; Google has to make a request for each individual mail even if they're caching images.
Nothing stops Gmail from doing the loading on their side (to hide UA, IP, etc.) but only when you ask for it.
What's Google's motivation for this? Do they do emails that need to be tracked? Are they doing this for themselves to avoid having to special-case their own emails?
Wouldn't it be better to work on a standardized way to embed images in email, so that recipients can get nicely-rendered emails without exposing themselves to action tracking?
Possibly, to get you to use more of their advertising services, which is in-line with lots of their recent changes (like removing all organic shopping results in favor of paid listings, and adding e-mail ads to Gmail's promotion tab).
Prior to this change, a dozen or so of Google's competitors offered e-mail remarketing. That's where you insert an image into your marketing mails to set a cookie in the recipient's browser when they open the mail, then you can later advertise to that person across the web. For example, you could show banners on the NY Times site advertising your Black Friday sales only to people that opened your Black Friday sale preview e-mail.
With Google proxying images, regardless of cache/deduplication policy, only Google can sell e-mail remarketing to Gmail users now. They already sell web remarketing through AdWords/DoubleClick. That means companies advertising with Google's competitors will have to move money to Google.
We have that already, it's part of MIME. The external images are used only for tracking, potential bandwidth savings, and incompetence.
Oh, and I don't use the web frontend to gmail as it really got confusing. Where is my inbox that shows all the mails I got and not only some categories?
And I've dropped gmail for fastmail since gmail stopped being good a few years back.
So yeah. You may be an outlier, but there are lots of outliers out there :)
If so, then anyone can include an invisible image and always know when I open the email.. whereas before they had no way of doing this.
This is not a risk if Google proxies the image -- they'll proxy a 404, because Gmail's servers don't have privileged, cookied access to apps on your internal network, dev boxes, etc.
Thus someone could get a remote shell on your box running as the rails account, not just access to an internal application.
What's bad about that?
Not to mention you can do it anyway - just try to send an email to an address and see if they accept it, if they do then send the server a reset command so it discards the email.