Skip to main content
LiMP VPN
All posts

Email Tracking Pixels: Who Spies and How to Stop It 2026

Email Tracking Pixels: Who Spies and How to Stop It 2026

In short: a tracking pixel is an invisible 1×1 image embedded in an HTML email. When your mail client auto-loads images, the pixel calls the sender's server and reports on you: that the email was opened, when, how many times, from which IP address (and therefore which city and internet provider) and on which device. Turning off automatic image loading in your mail app removes the tracking. A VPN covers a separate but important part — it hides your real IP and city, so even if an image does load, the sender sees the VPN server's address, not your home one.

What a tracking pixel is

A tracking pixel (also called a web beacon or spy pixel) is a tiny image, usually transparent or white, one pixel in size. It is inserted into the email body with an ordinary image tag, but the image link points not to a neutral file but to the sender's server script. That link is unique for every recipient.

The pixel doesn't «hack» anything — it relies on the normal behavior of email. Any HTML email can contain images, and mail clients load them by default. The pixel simply disguises itself as a harmless picture: you never see it, but the moment it loads, your browser or app makes a request to a third-party server. That request is the «email opened» signal.

Crucially, the pixel fires not when the email is delivered, but when it is opened — more precisely, when images load. If images don't load, the pixel stays silent and the sender has no idea whether you read the message.

What the sender actually learns

When the pixel loads, the sender's server records a whole set of data. Individually each item looks minor, but together they build an accurate profile of your behavior and approximate location.

  • The fact and time of opening. The sender sees that you opened the email and the exact date and time, down to the second.
  • The number and repeats of opens. Opened twice, forwarded, came back a week later — each is logged as a separate hit.
  • Your IP address. It reveals your city, internet provider, and sometimes the connection type (mobile or home). It won't give your street address, but «city plus provider» is already a lot.
  • Device and mail client. The request's technical header shows the device type, operating system and the app you opened the email in.

For a marketer this is campaign analytics. For a scammer or someone watching you personally, it confirms that the address is «live», that you read mail at certain times, and that you are in a specific city.

What the pixel reveals and how to close it

Different data is closed by different tools. The key move is one — don't let the image load; a VPN backs it up in case images do load (for example in someone else's client or by accident).

What is revealedWhat the sender seesHow to close it
Fact of openingEmail read, date and timeDisable automatic image loading
Repeat opensHow often you returned to the emailDisable automatic image loading
IP address → city, providerYour approximate locationVPN (masks IP and city)
Device, OS, clientWhat you read mail onImage blocking + plain-text mode

As you can see, blocking images closes most of it, while hiding your IP address removes the geography — the thing the sender should be the last to know.

Who plants tracking pixels and why

Pixels are far more common than people assume — many newsletters have them on by default.

  • Marketing and newsletters. Stores, services and news emails count opens to measure performance. This is a legal practice, but you are usually never asked about it.
  • Sales and business correspondence. There are extensions that embed a pixel into an ordinary person-to-person email so the sender can see whether and when their message was read. Often the recipient has no idea.
  • Scammers and phishing. In spam and phishing emails a pixel confirms that the address is active and that you read mail. A «live» address is worth more and attracts more targeted attacks.
  • Watching a specific person. Someone who wants to know where you are and when you are online can send an email with a pixel to track your city and daily routine by IP.

That is why a tracking pixel is not only about annoying ads but about real privacy: it turns an ordinary email into a sensor of your presence.

Does a VPN help against tracking pixels

Let's be honest, without overstating. A VPN is not a pixel «off switch» and by itself does not stop an image from loading. If you open an email with automatic image loading enabled, the pixel still fires and the sender learns the email was read.

But a VPN closes the most sensitive part — your geography. The pixel determines location by IP address. With a VPN on, the VPN server's address goes out, so the sender sees the server's city, not your real one. Your home IP, provider and true city stay hidden. This matters most when the email comes from a stranger or looks like phishing: you don't want a single click to reveal what city you are in.

So the working setup is a combination: image blocking removes the fact of opening, and the VPN insures your geography in case images load and protects the rest of your connection too. For more on what a VPN does and does not cover, read «what a VPN protects against and what it does not». If you need a reliable service with IP masking on iPhone and Android, see the LiMP VPN plans — from just over a dollar a month.

How to disable image loading in your mail app

The main tool against pixels is to stop your mail app from automatically loading external images. Then emails arrive as text, and images (including a hidden pixel) load only when you explicitly tap to allow them.

Gmail

In the web version open «Settings» → the «General» tab → the «Images» section and choose «Ask before displaying external images». In the Gmail mobile app: «Settings» → pick your account → «Images» → «Ask before displaying». After this the pixel won't load until you allow images in a specific email.

Outlook

In Outlook settings find the external-content security section and enable blocking of automatic image downloads from the internet. In classic versions this is the «Don't download pictures automatically» option. You can still load images manually for trusted emails.

Apple Mail (iPhone, iPad, Mac)

Apple has a dedicated «Mail Privacy Protection»: enable it in the Mail app settings. It loads remote content through Apple's proxy and hides your IP, so the sender gets no reliable open or location data. Alternatively you can fully disable loading of remote images.

Mobile and third-party clients

Most mail apps have an image-loading toggle — look for it in the privacy or message-display settings. On a computer, detector extensions additionally flag pixel-laden emails before you even open them.

Checklist: how to close down email tracking

  • Disable automatic loading of external images in every mail client you use.
  • Turn on «ask before displaying images» and load images only in emails you trust.
  • On iPhone and Mac, enable «Mail Privacy Protection».
  • Don't load images in suspicious, spam and phishing emails — doing so confirms the address is «live».
  • Install a tracking-pixel detector extension in your browser if you read mail on the web.
  • Keep a VPN on so an accidentally loaded image doesn't leak your city and provider.
  • Use a separate address for newsletters and sign-ups, kept apart from personal and work mail.
  • Periodically check whether your address has leaked into third-party databases and harden the mailbox itself.

Email hygiene is tied to overall account safety: it's worth also reading how to protect your email from hacking, and how hidden tracking works across apps and services in general.

Frequently asked questions

Can a tracking pixel reveal my exact home address?

No. An IP address gives «city and provider» level detail, not a street and house number. But combined with other data (activity times, device) it is still sensitive. A VPN removes even that geography by swapping your IP for the server's.

Can the sender see that I forwarded the email?

If you forward the email with its images and the new recipient loads them, the pixel fires again with their data. The pixel doesn't directly show the act of forwarding, but repeat and «foreign» opens can give it away.

Does Apple Mail fully protect against pixels?

«Mail Privacy Protection» hides your IP and preloads content through a proxy, so open data becomes unreliable. That is strong geographic protection, but don't rely on it alone — disabling automatic image loading removes the signal more thoroughly.

Can a VPN block a pixel on its own?

An ordinary VPN doesn't stop an image from loading — it hides your IP and city. To keep the pixel from firing at all you need image blocking. Some VPNs additionally filter tracker domains at the DNS level, which helps.

Is a pixel dangerous in spam and phishing?

Yes. By loading an image in a spam email you confirm the address is active and that you read it — after which attacks increase. In suspicious emails, don't load images and don't follow links.

How can I tell an email contains a tracking pixel?

Visually you can't — it's invisible. Browser detector extensions that flag such emails help, as does the very fact that an email asks to load «external content».

Should I disable all images in email?

A reasonable compromise is «ask before displaying». You are protected from pixels by default but can load images in emails from trusted senders when you actually need to.

Email Tracking Pixels: Who Spies and How to Stop It 2026