Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 29, 2026 · 9 min read

Does Gong Track Your Email Opens? How to Block It

Gong Engage counts opens with an invisible pixel and reroutes every link through its own domain. That is the smaller half of the problem. Here is the other half.

A rep emailed you last Tuesday. You read it, decided not to reply, and moved on. On their screen an icon lit up the moment the message rendered in your reading pane. So does Gong track your email opens? Yes. Gong Engage counts them with an invisible pixel and rewrites every link before the email reaches you. But that pixel is the smaller half of the story. Gong is also reading the rep's own mailbox, which means the reply you eventually send does not stay between the two of you.

Key Takeaways

  • Gong's help center states the mechanism without hedging: "We track whenever an email is opened using an invisible tracking pixel."
  • Gong rewrites outbound links through its own infrastructure, and an unbranded tracked link resolves to us-6653.email-composer-webhooks.gong.io.
  • Gong ingests the sending rep's mailbox, taking metadata first and then, in Gong's words, "the full body is ingested" once a matching company domain exists in the CRM.
  • Gong collapses repeat opens: multiple opens of the same email within one hour, or within the same thread, count once.
  • France's CNIL recommendation on email pixels applied from 14 April 2026, with a 14 July 2026 deadline for addresses collected earlier.
An empty desk in an open plan sales office at dusk, a headset resting beside a closed laptop, rows of monitors blurred in the background

Does Gong Track Your Email Opens?

Yes, when the message was sent through Gong Engage or the Gong browser extension and the sending company left open tracking switched on.

Gong's explanation of how email tracking works is refreshingly direct: "Each time the pixel is loaded to the recipient's mail server, we count this as an email open." Same 1x1 beacon every sales platform uses. Load it once and a timestamp lands on your contact record.

Clicks work differently, and worse for you. Gong "replaces link URLs with a custom tracking URL, then redirects the person clicking the link to the intended URL." Gong's branded URL documentation prints an unbranded tracked link verbatim: https://us-6653.email-composer-webhooks.gong.io/email-tracking/clicked. Companies paying for branding swap that for something like tracking.yourcompany.com, and Gong is explicit that nothing else changes: it "still handles routing and counting link clicks." The branded option is cosmetic, and it removes your best clue.

Two honest limits. Gong says flatly it "cannot determine who opened an email," so on a five person thread the rep sees an open, not your name. And admins can switch tracking off: Gong's compliance settings expose "Track email opens" and "Track email link clicks" as allowed or not allowed, with custom policies for "stricter rules for GDPR in Europe." Whether that toggle is flipped is the sender's decision, and nothing in the email tells you.

What Does Gong Actually Capture From Your Inbox?

Nothing from your inbox. Everything from theirs, and that is the part most coverage of Gong misses.

Gong's core product is not a pixel. It is a revenue intelligence platform that connects to the rep's Google Workspace or Microsoft 365 mailbox and imports the correspondence to score deals. Per Gong's email FAQ, "initially, we ingest just the metadata. Once the email is deemed to be relevant to customers (i.e. a company domain record exists in your CRM), the full body is ingested."

Read that filter from your side. If your employer's domain sits in their CRM, and it does or they would not be selling to you, your reply text is not incidental to the ingestion rule. It is the trigger for it. Gong adds that "authorized Gong users have access to the emails under the relevant account," so your message lands on your company's timeline inside their platform, readable by the rep's manager and anyone else granted access.

That is the structural difference between Gong and its neighbors. With Salesloft, the exposure ran one direction: they send instrumented mail, you leak open and click signals back. Gong runs that pipe and a second one pointing inward. The sequencer measures your behavior; the ingestion engine keeps your words. Most vendors do one. Gong does both, and the second is the one no extension can touch.

Why Is Gong's Open Data Wrong So Often?

Because a pixel records that a machine fetched an image, and plenty of those machines have no human behind them. Gong lists the failure modes itself: mailbox scanning that "will likely simulate the opening," CC'd colleagues, and forwarding, since "the forwarded email will still contain the tracking pixel." Apple's Mail Privacy Protection preloads remote content for everyone regardless of whether anything was opened.

Gong's deduplication rule then cuts the other way. Repeat opens within the same hour, or within the same thread, count once — so reread a proposal six times on a Tuesday afternoon and the rep may see three. The number they use to gauge your interest is inflated by scanners and deflated by design at the same time.

How Do You Know If a Gong Sequence Emailed You?

Read the raw source and look for two tells: a remote image with no reason to exist, and links that route somewhere before their stated destination. In Gmail, open the message, click the three dots menu at the top right, and choose "Show original."

  • Search for the vendor host. An unbranded Gong deployment leaves gong.io in the link targets, often on a subdomain containing email-composer-webhooks. That is a confirmed hit.
  • Check every image tag. Look for <img with a width and height of 1. A picture nobody can see is a beacon.
  • Compare link text against the href. If the anchor names one domain and the URL points at a different one first, that hop exists to be counted.

Our walkthrough on detecting email tracking pixels in Gmail goes deeper. Be realistic about the ceiling, though: a branded tracking domain defeats the first test entirely, and manual inspection only works on mail you already suspect. Nobody reads raw source on forty emails a morning.

Why Email Users Should Care

The consent story here has a hole in the middle, and it is not the one people argue about. The rep signed an employment contract and knows the platform is running. You signed nothing. Your reply, including the pricing pushback and the offhand line about your budget cycle, is ingested, attached to an account record, and made queryable by strangers.

European regulators moved on the pixel half of this in 2026. France's CNIL published its recommendation on email tracking pixels on 14 April, grounding it in Article 82 of the French Data Protection Act: pixels, like cookies, need prior consent unless strictly necessary to deliver the communication. Italy's Garante followed on 17 April. Per Covington's analysis, controllers must demonstrate consent at all times, and the grace period for previously collected addresses ran out on 14 July 2026.

Here is the uncomfortable read for compliance staff at a Gong customer. The guidance covers the pixel, which is the easy part to switch off, and Gong ships an admin toggle for exactly that. It says far less about the ingestion pipeline, where a rep's connected mailbox pulls in third party correspondence under a legitimate interest argument the third party was never told about. Disabling open tracking to satisfy the CNIL while still ingesting full message bodies would be technically responsive and substantively backwards.

How Do You Block Gong Email Tracking in Gmail?

Three approaches work, and they trade off against each other.

1. Stop Gmail loading remote images. Click the gear icon, choose "See all settings," stay on the General tab, scroll to Images, select "Ask before displaying external images," and save. Nothing remote loads until you approve it, so Gong's pixel never fires. Per Google's documentation, it is all or nothing: every newsletter and embedded logo now sits behind a prompt, and most people quietly switch it back within a fortnight.

2. Know what that does not fix. Blocking images does nothing to click tracking. Gong's rewritten links live in the href, so the redirect fires the moment you click anything. Gmail's image proxy is not protection either: it hides your IP, but Google still fetches the pixel for you and the open is still logged.

3. Strip the tracking before it renders. An extension working inside Gmail can remove tracking pixels before the message draws and clean tracked links, so the images you actually want still load. Gblock works this way: it blocks known tracking pixel requests from sales platforms, strips known tracking parameters out of links, and pulls an updated blocklist rather than shipping a frozen one. It runs inside Gmail, so your address stays put.

Other options are real. Ugly Email flags tracked messages with an eye icon but leans on a community maintained list that lags new vendors. PixelBlock is free, handles pixels only, and updates rarely. Trocker is open source and marks tracked links too, though its heuristics misfire on unusual senders. Proton Mail and HEY block remote tracking at the server, which is stronger and also means a new address. Our comparison of ways to block email tracking in Gmail and our roundup of email tracker Chrome extensions weigh the tradeoffs.

Now the part no vendor in this category says plainly. None of this stops the ingestion. A blocker in your browser kills the pixel and neutralises the rewritten link because both execute on your machine. Gong's mailbox import runs on the rep's account, on Gong's servers, outside your reach. Press send and your reply lands in their mailbox; Gong takes it from there. No extension changes that, and anyone implying otherwise is selling you something.

What Can You Do Beyond Blocking?

Two things, and the first is free: write vendor replies knowing a committee will read them. The renewal date, the internal politics, the frustration with your current provider — assume all of it is indexed under your company name. That is not paranoia, it is the documented design of the product.

The second is legal. Under GDPR, Gong is the processor and the selling company is the controller, so an access or erasure request goes to that company, not to Gong. Gong's data processing addendum commits it to assisting with access, rectification, deletion, and objection requests. Ask what correspondence of yours sits in their revenue platform. The answer, and how long it takes to produce, tells you plenty.

The Bottom Line

Gong tracks opens with a pixel, tracks clicks by rewriting your links, and ingests the rep's mailbox to score the deal you are part of. Two of those three you can shut down from your own browser in about ninety seconds, and the counter on the other end stops moving. The third is not yours to control. Block what you can reach, and write the rest as though a room full of strangers will read it, because Gong's own documentation says they can.

Sources: Gong, How does email tracking work?, Gong, FAQs: emails, Gong, Set up branded URLs, Gong, Configure compliance settings, Gong, Engage Analytics, Gong, Data Processing Addendum, Covington, CNIL Publishes Recommendation on Email Tracking Pixels, Google, Display images in Gmail, and Apple, Mail Privacy Protection.

Stop Email Tracking in Gmail

Block sales tracking pixels in your Gmail inbox

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.