Email tracking is a form of digital surveillance that’s become a serious concern(new window) in recent years, with nearly 50% of all emails containing trackers.
French and Italian privacy regulators responded to growing concerns about hidden tracking with new guidance published in April 2026. The recommendations explain when companies need your consent to track email activity and what they must tell you about the information they collect.
Here’s what email trackers reveal, what the guidance means for your privacy, and how to protect your inbox without a browser extension.
- What are email trackers?
- How do email trackers work?
- How email trackers threaten your privacy
- France and Italy clarify the rules on email tracking
- How to protect yourself from email trackers (without a browser extension)
- Stop email trackers, protect your privacy
What are email trackers?
Email trackers are images and specially formatted links that companies embed in messages to collect information about your email activity. Tracking often happens without any visible indication. Retailers, newsletter publishers, and other organizations use the data to measure engagement, build profiles of your interests, and tailor the marketing you receive.
Profiling like this drives Big Tech’s advertising business, where platforms gather information about your online activity and charge advertisers to reach people with particular interests and habits.
How do email trackers work?
The information a tracker collects depends on how it’s embedded in the message and how your email app handles it. Two common methods are tracking pixels and tracking links.
Tracking pixels
An email tracking pixel, also called a spy pixel or web beacon, is usually a transparent image measuring just one pixel by one pixel, making it almost impossible to notice. The tracking happens when your email app loads the image, meaning you don’t need to click anything to trigger it.
The image is stored on a server, and companies put its web address in their emails so your email app knows where to find it. The web address usually includes a unique code tied to your email address or a particular message. When your app downloads the image, the server recognizes the code and records that the image in your email has loaded.

If your email app downloads the pixel directly from the server where it’s stored, it shares your IP address(new window) and details about the app you’re using. Your IP address reveals your approximate location, while the time of the download helps companies work out when you opened the email. If your app downloads the pixel again, companies treat that as a sign that you’ve reopened the message.
Our guide to pixel tracking explains the technique in more detail.
Tracking links
Companies create tracking links by adding information to a web address or routing you through a tracking server on the way to your destination. When you follow a link routed through a tracking server, the server records the click before forwarding you to the page you wanted to visit. The extra step usually happens too quickly to notice.
Information added to the destination address helps companies understand where website visits come from. Common tags called UTM parameters show where a visit came from, whether it arrived through email or another channel, and which campaign the link belonged to. A business can use the tags to count visits from a particular newsletter, for example.

Other tracking links include a unique code tied to an individual recipient. Following one connects your click to your email address, giving the business a record of which products, offers, or articles you selected.
Blocking external images leaves tracking links active, so stopping pixels alone doesn’t stop companies from recording your clicks. By combining data from both pixels and links, companies can build a surprisingly detailed picture of your digital life, especially when AI is involved. Data brokers can use AI to turn that information into insights that shape your life from the shadows.
How email trackers threaten your privacy
A Princeton study published in 2018(new window) found trackers in 70% of the 12,618 mailing-list emails researchers examined. In their tests, simply opening a message leaked the recipient’s email address to an outside company in nearly three out of ten cases. Across the sample, emails connected to hundreds of third parties when researchers opened them. Clicking links exposed email addresses to additional companies, including Acxiom, one of the world’s biggest data brokers, which claims to have data on 2.6 billion individuals profiled using over 10,000 traits.
Sharing your email address makes the tracking particularly intrusive because it gives companies a way to identify the person behind a browsing history. The researchers documented how tracking cookies(new window) connected email activity with records of website visits, undermining claims that the browsing data was anonymous.
Matching your email address across different services lets companies link activity on your phone and computer, while records associated with the same address provide a bridge to offline purchases. For example, advertisers can connect a store’s loyalty account to your online profile through your email address and target ads based on what you bought in person.
France and Italy clarify the rules on email tracking
Concerns about hidden email tracking have prompted privacy regulators to examine how companies monitor your inbox. European privacy rules(new window) already cover email tracking pixels, but new guidance published in France and Italy spells out when companies need your permission and what they must tell you.
France explains when companies need your permission
France’s privacy regulator, the CNIL, published its recommendations on April 14, 2026(new window). Companies must explain the tracking and get your consent before using pixels to personalize marketing or build profiles of your activity.
Some tracking is allowed without asking permission, provided it serves your interests. For example, a business can check whether you’ve stopped opening a newsletter you signed up for, provided it uses that information only to send fewer messages or stop sending them altogether. The same rule covers emails connected to a service you requested, and companies must collect only the information needed for that purpose.
The CNIL further says companies should normally keep just the date you last opened one of their emails(new window). If you open a newsletter on September 10 and another on September 20, the company should replace the earlier date with September 20, without recording the exact time. A business that needs more information must document why. Tracking strictly needed to protect account sign-ins, such as in emails containing authentication codes, is also allowed without consent.
For existing subscribers, the CNIL took a different approach. Businesses with email addresses collected before April 14, 2026, generally had until July 14 to explain their use of pixels and give subscribers an easy way to refuse. Under the CNIL’s later clarification(new window), businesses that followed this process can continue tracking unless a subscriber objects or a change requires fresh consent. Receiving the notice leaves it to you to refuse the tracking.
Italy requires a way to stop tracking without unsubscribing
Italy’s privacy regulator, the Garante, adopted its guidance on April 17, 2026(new window). Companies must tell you about tracking pixels before using them and get your permission unless the tracking qualifies for a limited exception. Examples include certain anonymous counts of email opens, tracking needed to protect account sign-ins, and legally required service communications.
Companies must also let you change your mind about tracking without forcing you to give up the emails you receive. For example, you should be able to stop pixels while continuing to receive a newsletter you enjoy. Businesses already using tracking pixels must explain the tracking and provide an easy way to refuse, separately from unsubscribing.
Organizations have until October 29, 2026, to comply, six months after the guidance’s publication in Italy’s Official Gazette(new window).
These rules are a step toward curbing abusive email tracking, but they don’t guarantee every company will follow them. Whether you live in France or Italy, or somewhere without similar protections, it’s still worth taking steps to protect your inbox rather than relying on companies to respect your privacy.
How to protect yourself from email trackers (without a browser extension)
You don’t need an email tracker extension to protect your inbox. Extensions that work inside webmail may need permission to access data on the pages you use, and some third-party email tools require access to your account. That doesn’t mean every extension is unsafe, but adding another service with access to your inbox can create unnecessary privacy and security risks.
Start with your email service’s built-in protection, then use the steps below to limit tracking through images, links, and your email address. Check protection in every email app you use: a browser extension doesn’t cover messages opened in a separate mobile or desktop app.
1. Use Proton Mail’s built-in tracking protection
The easiest way to protect your inbox from email trackers is to use Proton Mail with enhanced tracking protection. Most newsletters and marketing emails arrive without end-to-end encryption, allowing Proton to check their images for trackers before you open them. The built-in image protection works by:
- Removing known spy pixels from incoming emails
- Hiding your IP address and masking when you open an email by loading other remote images through Proton’s servers when the message arrives
- Preventing new image downloads when you reopen an email by saving a copy of the images
- Cleaning tracking links in the browser version by removing recognized UTM tags and other tracking parameters
- Removing tracking parameters from emails sent to your Gmail address when you connect your Gmail account to Proton Mail using Easy Switch
2. Use hide-my-email aliases
When you sign up for a free Proton Mail account, you also get access to hide-my-email aliases, which are powered by Proton Pass, our encrypted password manager.
Aliases create separate email addresses that forward messages to your inbox without revealing your main address. You can also reply from aliases. Giving each service its own alias prevents companies from linking your accounts through a shared email address and lets you stop unwanted messages by disabling that service’s alias.
Forwarded emails can still contain tracking pixels and links, so keep tracking protection enabled in the inbox where you read them.
3. Control how external images load
Turning off automatic image loading blocks tracking pixels, but it also hides photos and logos that load from the internet. If you choose to display the images, hidden tracking pixels can load too.
Gmail on the web
To block a Gmail tracker that uses hidden images, turn off automatic image loading:
- Open Settings ⚙ → See all settings.
- Under General, find Images.
- Select Ask before displaying external images.
- Click Save Changes.

Gmail will now show the email’s text, but external images won’t load unless you click the Display images below option in the email. However, allowing the images also lets any hidden tracking pixels load.
Classic Outlook for Windows
To block hidden tracking pixels in classic Outlook, keep automatic image downloads turned off and check for exceptions that allow images to load:
- Open File → Options.
- Select Trust Center → Trust Center Settings.
- Open Automatic Download.
- Make sure Don’t download pictures automatically in HTML e-mail messages or RSS items is selected.
- Clear any exceptions underneath that allow images to download automatically.
Outlook will now keep external images blocked until you click the information bar at the top of the message and select Download Pictures. Allowing the images also lets any hidden tracking pixels load.
Apple Mail on iPhone
Apple Mail protects your reading activity while still displaying images. With Protect Mail Activity enabled, the app downloads images, including hidden tracking pixels, even if you never open the message, so companies can’t use those downloads to tell whether you’ve read it.
- Open Settings → Apps → Mail.
- Select Privacy Protection.
- Turn on Protect Mail Activity.
- Go back to Settings → Wi-Fi.
- Tap the information button beside your network.
- Make sure Limit IP Address Tracking is turned on.
4. Review tracking notices and preferences
When a company sends a tracking notice, look for an option to refuse pixels or withdraw consent. Check the tracking preferences as well as the unsubscribe option, since stopping tracking and stopping the emails are separate choices.
Unsubscribe from mailing lists you no longer want; Proton Mail makes this easier with one-click unsubscribe. For suspicious messages, use your email app’s spam controls instead of following links in the message.
5. Open websites directly
For routine tasks such as checking an order or signing in to an account, open the company’s app or visit its website directly to avoid the tracking link in the email. If you copy and paste a link, remove unnecessary tracking parameters, often found after a question mark (?) in the URL. Be careful not to remove parameters needed for the link to work.
6. Use a VPN alongside email protection
When your device downloads a tracking pixel directly through a VPN connection(new window), the tracking server sees the VPN’s IP address instead of yours. The pixel’s identifying code still lets the company associate the request with your email address or message, so a VPN complements email tracking protection without replacing it.
Stop email trackers, protect your privacy
Email trackers turn everyday inbox activity into data that companies use to build profiles and target advertising. French and Italian guidance clarifies when companies need your consent, but receiving a tracking notice doesn’t stop the collection.
You don’t need to wait for companies to change their practices to protect your inbox. Proton Mail’s enhanced tracking protection blocks known tracking pixels and hides your IP address automatically, without a browser extension. Opening websites directly instead of following email tracking links gives companies less information about your activity.
Moving to a more private email is straightforward, too. Easy Switch helps you import your emails, contacts, and calendars from services such as Gmail. By choosing Proton Mail, you also support our work to build an internet where privacy is the default.






