DPE-2026-0030

Open tracking in an email

A message reports back when it was opened, through a resource fetched on rendering whose address identifies the recipient.

In het NederlandsOpenen van een bericht wordt gemetenWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data webappdesktop status active
Not a vulnerabilityNothing is exploited and nothing is broken. The message does exactly what the sending platform was configured to make it do, and the objection is to that configuration.

What it is

The message body references a remote resource: a one-pixel image, a background image, a font, a stylesheet. Its address carries a value unique to the recipient. Displaying the message makes the client fetch it, which tells the measuring party the time of opening, the client, the operating system and the network the reader was on, and it repeats on every later opening. The resource is chosen so that nothing appears on screen, so the reader has no cue that anything happened.

Why it is a separate entry

Reading is not an act the reader performs towards the sender. Here it becomes one: the sender learns when a message was read, how often, from where and on which device, and from a series of those the reader's daily rhythm, time zone, holidays and whether a message was forwarded. The reader learns none of it and was asked nothing, because there is no moment in a message at which anything can be asked.

How it arises

Not to be confused with

A resource loaded by a web page is Third-party resource loading; there the fetch belongs to a page and the address is the same for everyone. What distinguishes this entry is that rendering a message triggers the fetch and that the address singles out one recipient. A visible image with an address identical for every recipient is not this entry.

How to establish it

The same mailing, received at two addresses under your control, contains remote resource references whose path or query differs between the two copies while the message is otherwise identical. The per-recipient difference in the address is the fault. An address identical in both copies is not.

method differentialQoD 95

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itShow me the raw source of the last mailing, and the same mailing as it went to a second address.
In a DPIA, verify this

Verify from the raw source of a sent message which remote addresses it contains and whether they differ per recipient, instead of accepting that the platform measures opens 'anonymously'.

As a procurement clause

Messages sent on the buyer's behalf contain no remote resource whose address differs per recipient, unless the recipient asked for the confirmation and can see it.

With a complaint, hand over

The raw source of the same mailing as received at two addresses of the complainant, with the differing addresses marked, and the date of the send.

Reproduction

Legal framing

Objections, and the answer

“We only look at aggregate open rates.”

The address fetched is unique per recipient, which is what makes the aggregate possible in the first place. Which rows are looked at is a choice made after the fact and can change tomorrow; the record is there either way.

“The recipient subscribed.”

Subscribing is agreement to receive the message, not to being observed while reading it. The two are separately askable, and a platform can send without measuring.

“We need it for deliverability.”

Deliverability is measured from bounces and complaints, which the mail protocol reports without touching the reader. Whether a message was opened adds nothing to it.

“Most clients block images anyway.”

Then the measurement fails for those readers and works for the rest. What the message was built to do is the finding, not the success rate.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0030 (Open tracking in an email)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0030
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0030/index.json
Full
DPE Catalogue. DPE-2026-0030: Open tracking in an email. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0030
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0030, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.