An email open is an image request, not attention.
An open counter can record a person, a privacy proxy, or neither. The useful question is not whether the number is real. It is what evidence the number can honestly support.
By Moosewave
Published · 12 min read

The short version
An open measures a request, not a reader.
Most open tracking works by placing a recipient-specific remote image in an HTML email. When that asset is requested, the sending platform records an event. That event is useful, but it cannot identify why the request happened or prove that the message received human attention.
- 01A person can read while images are blocked, producing attention without an open event.
- 02A privacy service can load remote content in the background, producing an open event without attention.
- 03A filtered click, reply, account action, or conversion is closer to intent, but each still needs provenance and context.
- 04Use opens as low-confidence telemetry. Do not let them alone renew consent, suppress a recipient, or declare a campaign successful.
See how Moosewave places these signals in context in the email analytics workspace.
What an open actually records
In the common implementation, an HTML message contains a tiny remote image with a URL tied to a message and recipient. An email client, proxy, or other system requests that URL. The tracking server receives the request and records an event with the information still visible to it, such as time and request metadata.
The event says an asset was requested. It does not say who looked at the screen, how much of the message appeared, how long it stayed visible, whether it was understood, or whether the recipient wanted the next message. Those are separate propositions that require separate evidence.
The event can be exact while the conclusion drawn from it is wrong.
Even a formal Message Disposition Notification does not solve this. The internet standard for read receipts says a “displayed” disposition does not guarantee that the content was read or understood, and a receiving client may ignore the request. A marketing pixel is less explicit still.
| Recorded fact | It can support | It cannot prove alone |
|---|---|---|
| Remote image requested | A qualifying asset request occurred | A particular person read the email |
| Link request observed | A URL was visited under the tracker’s rules | The visit was human or produced value |
| Receiving server accepted | The receiver took responsibility for delivery | The message reached the inbox |
| Conversion stored | A downstream outcome occurred | The email caused the outcome |
Definitions also vary. One platform may count one unique open per recipient, another may retain repeated loads, and denominators may exclude different failure states. Put the event definition and denominator next to every rate. A number without its counting rule is not portable.
One counter can describe three realities
Picture three copies of the same newsletter. The first is opened by a person with remote images enabled. The pixel loads and the person reads. The second sits unseen while a privacy system downloads its remote content in the background. The pixel loads without a read. The third is read carefully with remote images blocked. No pixel loads.
The open counter calls the first two equal and loses the third. That is not a software defect. It is the natural limit of observing one network request and asking it to stand in for attention.
Load + attention
Useful but incomplete
A person may have displayed the message, but the event still cannot show comprehension or intent.
Load + no attention
False inference
Background fetching can satisfy the tracker even when no person engages with the message.
No load + attention
Missing evidence
Blocked remote content can hide a genuine read from the tracking system.
The same discipline already applies elsewhere in email. The field note Delivery is a receipt, not a result separates server acceptance from placement, attention, and action. An open belongs on that ladder as one observation, not as the final rung.
Privacy infrastructure changes the witness
Apple states that Protect Mail Activity downloads remote content in the background by default, regardless of whether someone engages with the email. It also routes that content through separate relays so the sender cannot use the recipient’s IP address as a unique identifier. A resulting asset request is evidence that the protection system did its job, not evidence that a person read.
Gmail documents a different protection: it serves images through Google’s secure proxy servers. That changes which system contacts the image host and limits what request metadata can safely say about the recipient. Proxying does not make every Gmail open false. It means IP, location, and client deductions need narrower claims than many dashboards imply.
Security systems complicate clicks too. Microsoft documents URL scanning during mail flow and checks around the moment a protected user clicks. A click is generally closer to deliberate action than an image load, but raw link traffic can still include infrastructure. Where collection is permitted and necessary, classify known machine activity, retain only the minimum request evidence for the documented period, and look for a related session, reply, account event, or conversion.
This is an inference boundary, not a reason to discard measurement. The correct response to uncertain evidence is a confidence label. The webhook field note makes the same point about event delivery: keep what was observed, then derive current state without pretending the event said more than it did.
Match the signal to the decision
There is no single replacement for open rate because teams used it to answer several different questions. Placement asks whether the message was visible. A click asks whether a link drew action. A purchase asks whether an outcome occurred. A holdout asks what the campaign caused. Choose the evidence after naming the decision.
| Signal | Best question | Important limit | Weight |
|---|---|---|---|
| Server acceptance | Did the receiver accept responsibility? | Does not reveal inbox placement | Operational |
| Observed placement | Where did controlled messages land? | A bounded observation, not every recipient mailbox | Diagnostic |
| Open event | Was a tracked asset requested? | Machine loads and blocked images | Low |
| Filtered click | Did a likely person pursue a link? | Scanners and accidental taps remain | Medium |
| Reply or account action | Did the relationship change? | Automated replies and shared accounts exist | High |
| Store-side conversion | Did the intended outcome occur? | Attribution is not causation | High |
| Unsubscribe or complaint | What audience cost did the send create? | Must be read beside reach and outcome | High and urgent |
| Randomized holdout lift | What did the campaign cause? | Needs enough volume and clean assignment | Strongest |
Read the upside and cost together. A campaign that converts and drives complaints is not simply successful. Gmail’s Postmaster Tools exposes user-reported spam, reputation, authentication, and delivery errors because receiver-side evidence matters alongside campaign analytics. Moosewave’s deliverability view keeps placement beside delivery, and the commerce layer connects message evidence to store-side outcomes.
Do not automate the proxy’s guess
A weak metric becomes dangerous when it quietly changes who receives email. An “opened” branch can treat a background fetch as interest. A “did not open” branch can punish a person who read with images blocked. Repeating that mistake across a lifecycle flow turns uncertainty into policy.
Use no-open history as one weak input, never as sole proof of inactivity. Combine filtered clicks, purchases, account use, replies, message purpose, current permission, and frequency. Let recent high-confidence activity outweigh a missing pixel, and let an unsubscribe or complaint override every engagement score immediately.
Most importantly, an open cannot renew consent. Permission is about what someone agreed to receive and the choices made since, not whether a remote file was fetched. Email consent is a state, not a timestamp explains the full decision. The audience system should preserve that state separately from engagement.
In lifecycle automations, make uncertainty visible: “no high-confidence activity in 120 days” is more honest than “did not read.” A re-engagement message can then ask a bounded question, and continued silence can lead to suppression without claiming knowledge the system never had.
A campaign report should lead to a decision
Measurement becomes clearer when the team starts with the decision rather than the dashboard. If you want to debug placement, inspect provider and seed evidence. If you want to evaluate content, use filtered actions and downstream behavior. If you want to estimate commercial effect, create a comparable holdout.
- 01
Name the decision
Write what will change if the evidence moves. A metric with no decision attached becomes decoration.
- 02
Publish the counting rule
Define unique events, repeated events, the denominator, time window, and excluded delivery states.
- 03
Keep cohorts comparable
Compare the same stream, audience, provider mix, and period before treating a trend as a creative effect.
- 04
Classify machine activity
Where tracking is permitted and necessary, retain only the minimum request evidence for a documented period and label likely privacy or security infrastructure.
- 05
Join downstream outcomes
Connect messages to replies, sessions, account events, orders, renewals, and other purpose-specific results.
- 06
Read the cost side
Put unsubscribes, complaints, suppressions, and placement beside clicks and revenue on the same report.
- 07
Use a holdout when stakes justify it
Randomly withhold a comparable group and measure the difference when causality matters more than attribution.
- 08
Preserve uncertainty
Within that minimized retention boundary, store confidence and provenance so derived state can be recomputed honestly.
Connected evidence is what makes this possible. Moosewave integrations keep source events and chronology attached rather than flattening them into one engagement badge. That allows the report to distinguish what the email platform observed from what the product or store later confirmed.
The product consequence
Moosewave enables recipient-linked open tracking only when a workspace records applicable prior consent or a documented exemption or other permission recognized in the relevant jurisdiction, plus a retention policy. Within that scope, it stores an open as an observation, not a verdict, and keeps only the message, time, source, and limited request context needed for the stated measurement purpose. Likely privacy-proxy and machine activity remain classified rather than silently counted as human engagement.
Where a jurisdiction permits a narrow deliverability use for requested-service or otherwise consented email, that use case needs less data. It can keep only the latest open date at day precision, overwrite it when a newer qualifying event arrives, and discard the prior value. If tracking is not permitted, not necessary, or turned off, the open event is not collected for campaign analytics. Uncertainty is preserved without treating indefinite raw-event retention as the default.
Campaign reports present opens as directional and keep them beside acceptance, observed placement, filtered clicks, replies, conversions, unsubscribes, and complaints. Segment and provider breakdowns prevent one list-wide average from hiding where the evidence changed. The analytics workspace makes each metric’s definition and limits visible.
Default audience and automation decisions do not treat a raw open as proof of consent or use it as the only evidence of activity. High-confidence events from connected product, support, CRM, and commerce systems can update the relationship without pretending every source means the same thing.
Open the interactive Moosewave walkthrough to follow a campaign from audience choice through placement and outcomes. Better analytics does not require a perfect signal. It requires a product that tells you exactly which imperfection you are looking at.
Measurement is also a privacy choice
Tracking pixels do more than produce a chart. Depending on their implementation, they can process identifiers, times, IP-derived information, device information, or other data. The UK Information Commissioner describes tracking pixels as code, usually an image, that creates communication between a client and a server. Its guidance also explains that storage-and-access rules can apply to pixels in email.
France’s CNIL published a dedicated 2026 recommendation on tracking pixels in email. The legal result depends on the purpose, information accessed, jurisdiction, and safeguards; it is not settled merely because the email itself was permitted. Teams should minimize collection, explain it clearly, respect applicable choices, and document why each field is necessary.
This article is an operational framework, not legal advice. Verify requirements for the people and markets you serve. Privacy protections are not contamination to remove from the metric. They are recipient choices and infrastructure boundaries the measurement system must represent honestly.
Frequently asked questions
Direct answers about email open tracking, Apple Mail Privacy Protection, click reliability, inactive subscribers, benchmarks, and tracking-pixel privacy.
What counts as an email open?
Most email platforms count an open when a recipient-specific remote image is requested. The exact rules for unique opens, repeated loads, caching, and the delivered-message denominator vary by platform, so the metric definition belongs beside the number.
Are email open rates accurate?
Open rates can accurately count the image requests that meet a platform's rules. They do not accurately count people who saw, read, understood, or valued the message, because machines can load images and people can read while images remain blocked.
Does Apple Mail Privacy Protection inflate open rates?
It can create a remote-content load without recipient engagement. Apple says Protect Mail Activity downloads remote content in the background by default regardless of whether the person engages with the email, so that load cannot prove a human read.
Can someone read an email without registering an open?
Yes. A person can read with remote images blocked, use a plain-text view, or encounter a failed tracking request. That is why the absence of an open is weak evidence of the absence of attention.
Are click rates more reliable than open rates?
A filtered click is usually stronger evidence because it is closer to an intentional action, but it is not infallible. Security systems inspect and rewrite links, so join clicks to sessions, replies, account activity, or conversions and retain a machine-activity classification.
Should inactive subscribers be removed based only on no opens?
No. Combine open history with filtered clicks, purchases, account activity, replies, current permission, frequency, and the value of the relationship. A missing pixel request should not by itself erase a valid subscriber or prolong an unwanted one.
What is a good email open rate?
There is no universal benchmark that transfers cleanly between senders. Client mix, image handling, audience, message type, placement, and platform definitions all change the number. Compare a stable cohort with its own documented baseline and use stronger outcomes for success.
Do email tracking pixels require consent?
The answer depends on jurisdiction, purpose, and implementation. Tracking pixels can invoke privacy and device-storage rules in addition to the rules governing the email itself. Explain what you collect, minimize it, honor applicable choices, and obtain advice for the markets where you operate.
Sources & method
Standards, provider documentation, and privacy guidance
Official documentation establishes what the infrastructure does and what the standards can prove. The evidence hierarchy and operating model are Moosewave’s synthesis.
- UK ICO, What are storage and access technologies?. Defines tracking pixels, including pixels embedded in email, and explains the client-to-server communication they create.
- Apple, Mail Privacy Protection & Privacy. States that protected Mail downloads remote content in the background by default regardless of engagement and routes it through privacy relays.
- Google Workspace, Gmail image URL proxy. Documents that Gmail uses Google secure proxy servers to serve images in email messages.
- IETF RFC 8098, Message Disposition Notification. Says a displayed disposition does not guarantee that content was read or understood and protects a recipient’s choice not to return a notification.
- Microsoft, Safe Links in Defender for Office 365. Documents URL scanning during mail flow, rewriting, and checks around protected clicks.
- Gmail, Postmaster Tools dashboards. Defines provider-side reporting for user-reported spam, reputation, authentication, feedback loops, and delivery errors.
- CNIL, Recommendation on tracking pixels in emails. Provides current regulatory guidance on purposes, transparency, consent, exemptions, and safeguards in France.
Last reviewed 10 August 2026. Client behavior, mailbox infrastructure, and privacy requirements change; verify the current documentation for the systems and jurisdictions you operate.
Continue reading
Keep each fact on its own rung
Start with the distinction between server acceptance, placement, attention, and action, then see how current audience state changes who should receive the next message.