Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 12, 2026 · 9 min read

Apple Mail Fakes Half of All Email Opens in 2026

Stripo's 2026 B2B benchmark study, built on roughly 15 billion emails, found that 49.29% of every tracked open is Apple Mail Privacy Protection fetching a pixel on a schedule of Apple's choosing. Half the surveillance data in the average marketing dashboard describes a server, not a person.

Email open tracking has a measurement problem that nobody in marketing wants stated plainly: about half of what it measures is not a human being. Apple broke it deliberately, for its own users, in 2021. The interesting part is not that Apple did it. The interesting part is what happened next, and what did not happen for the roughly quarter of the market that reads mail in Gmail.

Key Takeaways

  • Apple Mail Privacy Protection accounts for 49.29% of all tracked email opens in 2026, according to Stripo's B2B email open rate benchmark research covering 939 companies, 46 industries and roughly 15 billion emails.
  • The same study puts true human B2B open rates at 15% to 25% while dashboards report 35% to 55%, an inflation of 15 to 20 percentage points or more.
  • Mail Privacy Protection works by downloading remote content in the background on delivery through Apple relayed servers rather than when you read the message, and by substituting a generalized IP address for yours.
  • MPP does not stop the tracking pixel from firing. It fires on every protected message, opened or not, which is precisely why the fake open count is so high.
  • MPP does nothing for click tracking, and nothing at all for people reading mail in Gmail on the web, where no equivalent protection exists.

What Is Apple Mail Privacy Protection?

Mail Privacy Protection is a setting in Apple Mail that routes remote image requests through Apple's own infrastructure and fetches them before you ever look at the message. Apple's support documentation calls the toggle Protect Mail Activity, and describes the behaviour in two parts: your IP address is hidden from senders, and remote content is downloaded privately in the background when the message arrives instead of when you view it.

Apple's legal page on Mail Privacy Protection adds the architectural detail that matters. Requests pass through two separate relays so that no single party holds both your identity and the content you received. Apple sees who you are but not what was fetched. The content provider sees what was fetched but receives a generalized identity covering a broad region rather than your address.

One clarification, because coverage often gets it wrong: MPP applies to the Apple Mail app, not to an Apple account. Read a Gmail mailbox inside Apple Mail on an iPhone and you are protected. Read the same iCloud mailbox in Chrome and you are not.

Why Are Half of All Tracked Opens Fake?

Because a prefetch is indistinguishable from a read, and Apple prefetches everything. The pixel loads whether the message is opened, ignored, or deleted unseen. The sender's server logs an event either way, and there is no field in that log that says "a machine did this."

Scale explains the rest. Litmus's email client market share tracking, aggregated from over a billion opens, has put Apple's share of email opens above 60%, with Gmail a distant second. Apply background prefetching to the majority of a market and the open metric stops describing attention altogether.

The arithmetic is worth sitting with. Stripo's filtered figures suggest a cold outreach campaign showing a 40% open rate is really closer to 16%. Roughly six in every ten of those celebrated opens are Apple's servers doing housekeeping. A marketer optimizing subject lines against that number is tuning a signal that is majority noise.

An iPhone face down on a wooden desk beside a laptop showing an inbox, morning light across the surface

Does MPP Actually Stop Email Tracking?

Partly, and the parts it misses are the ones worth knowing about. MPP is genuinely good at three things and blind to a fourth.

  • Timing is destroyed. Because the fetch happens on delivery, the sender cannot tell that you read the message at 11:40pm, or read it four times.
  • Location is degraded. The relayed identity maps to a wide region rather than a street, so the city and coordinate fields many trackers report become useless.
  • Device fingerprinting is weakened. The request comes from Apple's proxy, so the user agent describes the proxy rather than your hardware.
  • The pixel still fires. This is the limit nobody advertises. Your device still requests a resource from a third party surveillance domain on every protected message, and the sender still learns the address is live and monitored.

Then there is click tracking, which MPP does not address in any way. When a sender rewrites every link in a message to bounce through their own analytics domain first, no proxy in the world helps you, because you are the one initiating that request from your browser with your real IP address. We covered how that rewriting works in our guide to Gmail read receipts and how to block them.

Why Did Marketers Stop Caring About Open Rate?

Because they replaced it, quickly and without much complaint, with metrics MPP cannot touch. Stripo's report anchors B2B performance on a click to open rate of 6.81% rather than raw opens, and the wider industry has moved the same direction: clicks, replies, downstream conversions, session behaviour after the click.

Here is the reading most coverage skips. Apple did not reduce the amount of surveillance in email. It made one specific technique unreliable, and the industry migrated to techniques that are strictly more invasive. An open tells a sender that a message was rendered. A tracked click hands over your IP address, your real user agent, a browser session that persists onto the destination site, and whatever the landing page's own analytics stack chooses to collect. Trading opens for clicks is not a privacy win. It is a privacy downgrade that happens to look like progress on a marketing dashboard.

Regulators have been less easily satisfied. France's data protection authority went after the pixel itself on consent grounds rather than accuracy grounds, and we wrote up the CNIL email tracking pixel recommendation and its deadline when it landed. The legal question is whether your device was instructed to phone home without your permission. Whether the resulting number was accurate is beside the point.

What This Means for Your Gmail Inbox

If you read mail in Gmail on the web, none of the above protects you. Gmail does proxy remote images through Google's own servers, which strips some device detail, but it caches per recipient and fetches when you open the message. The timing signal survives. That is the difference between a proxy built to obscure you and a proxy built to serve images faster, and we went into the mechanics in our breakdown of how tracking pixels dodge the Gmail proxy.

So the practical situation in 2026 is a two tier inbox. Apple Mail users got a real, default on, architectural defence handed to them by their mail client vendor. Gmail users got an image cache and a settings toggle that breaks every photograph in every message. Nobody in either group got protection from tracked links.

There is an encouraging conclusion buried in the Stripo numbers, though. Open tracking is not an inevitable feature of how email works. One vendor intervened on behalf of its users and rendered the technique statistically worthless across half the market. Tracking pixels are defeatable, and Apple proved it at planetary scale.

How Do You Block Email Open Tracking in Gmail?

You have five realistic options, and each involves a tradeoff worth naming out loud.

  • Switch to Apple Mail and turn on MPP. Strong on timing and location, on by default, free. Costs you Gmail's interface, does nothing about link tracking, and the pixel still fires.
  • Turn off automatic image loading in Gmail. Under Settings, choose Ask before displaying external images. Nothing loads until you approve it, which is total protection against pixels and a genuinely irritating way to read mail.
  • Move to a privacy first mail provider. Proton Mail blocks remote content by default and HEY strips trackers and reports what it caught. Both mean a new address and, for most people, moving away from Gmail entirely.
  • Add a blocker extension. Ugly Email marks tracked messages with an eye icon before you open them. PixelBlock blocks open pixels but leaves rewritten links intact. Our comparison of Ugly Email, PixelBlock and Trocker covers where each stops short.
  • Audit what is actually watching you. Gmail's Show original view exposes the raw source, and our walkthrough on detecting tracking pixels in Gmail shows what to search for. Excellent for investigating one sender, useless as a daily routine.

Gblock sits in the extension category with three differences worth stating precisely. It runs inside Gmail, so you keep the client you already use rather than migrating your mail life to get privacy. Its blocklist updates automatically, so newly identified tracker domains are covered without you maintaining a list. And it strips tracking links as well as pixels, which is the gap MPP leaves wide open.

What it will not claim: no domain based blocker catches everything, and a sender who serves its pixel from a custom subdomain of its own website defeats domain matching by design. If you want the honest field comparison across the category, our roundup of the best email tracker blocker extensions lays out the limits alongside the strengths.

The Precedent Apple Set

A 49.29% figure is a strange kind of monument. It represents the largest successful act of collective resistance to email surveillance ever recorded, and it appears in the industry's own research as a data quality complaint rather than an achievement. The marketing press treats it as noise to be filtered. Read it the other way and it is a headline: half of email open tracking has already stopped working, and it stopped because one client vendor decided its users should not be counted without consent.

The lesson is not that the problem got solved. Senders adapted within a quarter and kept measuring. The lesson is that the pixel is a request your own software chooses whether to make, and software that answers to you can simply decline. Apple's users have that. Gmail's users have to install it.

Stop Email Tracking in Gmail

Half of all tracked email opens in 2026 are Apple servers, not people. Gmail gives you no equivalent protection. Gblock blocks open tracking pixels and strips tracking links inside Gmail automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.