Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 06, 2026 · 12 min read

Canary Mail Read Receipts: Does Canary Track Your Email?

Canary Mail sells itself as privacy first and blocks other senders' tracking pixels, yet its own help center says read receipts are enabled by default on Mac, iPhone and Windows. We read Canary's help pages, privacy policy and pricing, and probed its pixel servers, on October 6, 2026.

Canary Mail read receipts rely on a tracking pixel, and on most platforms they are switched on before you touch a setting. If someone writes to your Gmail address from Canary, the Canary Mail email tracking question is about you: does the sender learn when you opened the message? Usually, yes. That is an odd fit for an app whose security page promises that "Canary Mail blocks trackers automatically across every account." Both things are true at once. Canary strips the pixels other people hide in mail you receive, and it plants its own in mail you send.

Key Takeaways

  • Canary Mail's help center states "Read receipts are enabled by default in Canary Mail on macOS," and its read receipts feature page answers "Are read receipts optional?" with "Yes. Read receipts are enabled by default."
  • Canary's technical overview, updated June 2, 2026, says read receipts use "a small invisible image (tracking pixel)" loaded "from Canary's secure server," and that only "a timestamp and open status are recorded."
  • Our October 6, 2026 probe found receipts.canarymail.io and pixels.canarymail.io both return a 1x1 PNG for any filename under /track/, while a nonsense subdomain returned NXDOMAIN.
  • The same app "blocks all incoming tracking pixels from emails sent to you by default," so Canary blocks other senders' trackers while adding its own to your outgoing mail.
  • Canary's privacy policy never uses the word "recipient," and its own guide says recipients cannot tell read receipts are on because "the tracking process is completely invisible."
A smartphone on a marble café table beside a cappuccino, its email app showing a yellow accent, with a blurred figure in the background, illustrating Canary Mail read receipts and email tracking

Does Canary Mail Have Read Receipts?

Yes, on every platform Canary supports, and on most of them they start out on. Canary's guide How to Use Read Receipts on Mac and iPhone, published April 1, 2026, says "Read receipts are enabled by default in Canary Mail on macOS. No manual setup is needed when you install the app." Its comparison table marks "Enabled by default" as Yes for both Mac and iPhone. The Windows guide agrees: "By default Read receipt (Preferences > General > Composing) is enabled."

Not every Canary page tells the same story:

  • The iOS and Android guides, updated September 25, 2025, both tell you to "Toggle ON" read receipts, which implies they start off.
  • A blog post from October 10, 2025 says Canary "supports read receipts as an opt-in feature" and gives you confirmation "without making tracking the default behavior."
  • The read receipts feature page, last updated April 28, 2026, settles it in one line: "Are read receipts optional in Canary Mail? Yes. Read receipts are enabled by default in Canary Mail."

Price doesn't gate the feature much. Canary's pricing page lists "Read Receipts (Lite)" on the Free plan and full Read Receipts on Growth, billed at $36 a year, and Pro+, billed at $100 a year, with lifetime purchases for both. Canary never defines what Lite leaves out, but even free users get some form of open tracking.

How Do Canary Mail Read Receipts Work?

Canary embeds a tiny invisible image in each message you send, and when the recipient's mail app loads it, Canary's server marks the email as read. The Canary Mail read receipts technical overview, published October 22, 2025 and updated June 2, 2026, walks through it: "The invisible image is loaded from Canary's secure server. This event signals Canary that the email was opened." The sender then sees "a blue check mark" next to the message in Sent, with a timestamp, and an alert if notifications are on.

Canary says it chose a pixel because providers "ignore or block" the standard receipt request. That standard, defined in RFC 8098, puts the recipient in charge: "it is strongly recommended that the user agent obtain the user's consent before sending an MDN." A pixel skips that consent step entirely.

Canary lists what it says the system does and does not record:

  • Recorded: "The event that an email was opened" and "The timestamp of when it was opened."
  • Not recorded: "No IP addresses," "No device information," "No geolocation or network data," and "No multiple-open or forward tracking."
  • Syncing: read status moves between the sender's devices through "anonymized one-way hashes." The Canary Mail privacy policy names Google's Firebase as the place those hashes for "read-tracking" are stored.

That puts Canary ahead of Superhuman's 2019 design, which logged where recipients opened mail. One caveat for the technically minded: "not collected" is a retention promise, not a network fact. Any image request carries the reader's IP address to whatever server answers it, and in Canary's case that server is a Cloudflare edge. You have to trust that the address is discarded.

Which Server Hosts the Canary Mail Tracking Pixel?

Two Canary hostnames answer like a pixel server: receipts.canarymail.io and pixels.canarymail.io. Canary doesn't publish either name. We started from the Mac app Mimestream, whose tracker blocklist, as our Mimestream read receipts investigation found, contains the pattern receipts\.canarymail\.io/track/(.*).png. On October 6, 2026:

  • DNS control: a nonsense subdomain of canarymail.io returned NXDOMAIN, so there is no wildcard record and every name that resolves was set up on purpose. Both receipts and pixels resolve to the same three Cloudflare addresses.
  • The pixel: any filename under /track/ returned HTTP 200 with content type image/png. The file is a 1x1 RGBA PNG of 169 bytes; a cached repeat came back as 70 bytes after Cloudflare's image compression. Made up names such as zzqx_nonsense_99.png got the same image, and so did a path ending in .gif.
  • Path control: the root and a nonsense path outside /track/ returned 404 with a plain text "Requested URL ... not found" message. A POST to a /track/ URL returned 405.
  • Same backend: the PNG from pixels.canarymail.io was byte for byte identical to the one from receipts.canarymail.io.
  • Caching: the response carries cache-control: max-age=16070400, about 186 days, which fits Canary's claim that it does not count repeat opens.

We also looked for link tracking. The names track, links, link, click, t, open and r under canarymail.io all returned NXDOMAIN, and Canary's documentation never mentions click tracking. Certificate transparency logs list a wildcard certificate plus names such as app, web, secure and install, none of which served images. We found no sign that Canary rewrites links.

Does Canary Mail Block Trackers in Mail You Receive?

Yes, by default, and it tells you when a message was tracked. The Mac and iPhone guide says "Canary Mail also blocks all incoming tracking pixels from emails sent to you by default," and later: "When you receive an email tracked by another sender, Canary Mail blocks the tracking pixel and notifies you that the email was being tracked." The Canary security features page, updated March 20, 2026, adds that "Tracker-blocking runs by default in every inbox view."

The pricing table doesn't put tracker blocking behind any plan. Canary's FAQ is more careful than its headlines: it says Canary "blocks common email trackers," not all of them, the honest framing for any blocklist.

Side by side, the copy argues with itself. The security page warns that "Invisible pixels in marketing emails reveal when and where you opened a message." The read receipt guide says Canary's own invisible pixel reveals when, just not where. Same technique, different target.

Is Canary's Privacy First Claim Honest About Tracking?

For Canary's own users, mostly; for the people they email, the documents go quiet. Canary's privacy policy covers "the information we collect about you when you use Canary Mail." We searched both of Canary's privacy pages and found zero uses of the word "recipient." The person whose open is being recorded has usually never installed Canary, never seen its policy and never agreed to anything.

Canary's technical overview contradicts itself on disclosure. Its best practices section tells senders to "Be transparent. Inform recipients if tracking is active." Its FAQ, a few lines lower, answers "Can recipients see that I've enabled read receipts?" with "No. The tracking process is completely invisible and unobtrusive." With the feature on by default, many senders never knowingly turn it on, so they have no reason to disclose it.

Superhuman has already been through this. In July 2019 it faced a public backlash over invisible read tracking, and its founder switched read status to off by default and stopped logging location, as our Superhuman tracking investigation recounts. Canary dropped the location part. It kept the default.

One smaller mismatch: Canary's App Store listing (version 5.26.0, released September 24, 2026) declares only Data Not Linked to You, with no Identifiers category. Yet the privacy policy says AppsFlyer, its install attribution vendor, "analyzes users' IP addresses, device information, and IDFA," Apple's advertising identifier.

What Does Canary's AI Copilot Send Off Your Device?

When you use Copilot to write, summarize or reply, your email text goes to outside AI providers. The privacy policy says large models "must be hosted on server" and that Copilot "will leverage models offered by top-tier providers such as OpenAI, Anthropic, Cohere, Google and others." Canary says it has "opted out of data sharing," so that text "will not be used to train or improve 3rd party models," while personalized prioritization models are "created, trained and stored on-device."

Copilot is part of the Growth and Pro+ plans, and the pricing FAQ says "AI features are optional and can be disabled at any time." Two other server paths matter:

  • Push notifications on iOS and Android: Canary "will temporarily store your email address, credentials, sender, subject line, and first line of the message on our server," deleted once the notification is delivered. Fetch mode avoids this.
  • Hosting: "The information we collect is stored on our servers in Germany," and your information "is controlled by Cartasec Pte. Ltd."

Canary Mail vs Spark, Proton Mail and Mimestream

Canary is the only app in this group whose own pages say its read tracking starts on. The other rows come from our Spark Mail read receipts investigation, our Proton Mail read receipts investigation and the Mimestream piece above.

App Read tracking for senders Incoming pixels
Canary Mail Tracking pixel, enabled by default; Lite on Free, full on Growth and Pro+ Blocked by default, with a notice that the message was tracked
Spark Read Statuses on Pro and Enterprise, using tracking pixels Blocks 1x1 tracking pixels by default
Proton Mail Manual receipt requests the recipient can ignore Blocks known pixels by default since January 19, 2022
Mimestream None documented Blocks common trackers on a best effort basis, including Canary's

Canary and Spark share a model: block everyone else's pixels, sell your own. Spark keeps its pixel behind a paid plan; Canary ships it switched on.

What This Means for Your Gmail Inbox

If a Canary user emails your Gmail address and Gmail loads the images, assume the sender sees a blue check and the time you opened it. Gmail fetches images through its own proxy, and Google's Gmail image help page says "Senders can't use image loading to get information about your computer or location." The same page concedes: "Sometimes, senders may know whether you've opened an email that has an image."

Canary's list of reasons a receipt might fail is telling. It names blocked images, plain text mode and "Privacy-focused clients (e.g., Apple Mail Privacy Protection)," which load images through a proxy and so prevent "accurate tracking." Gmail isn't on the list. Apple preloads images whether or not you read the message, as we explain in Apple Mail fakes half of all email opens. Gmail's proxy hides your IP address but still fetches the image when you open the message, which is why it leaks the open, as covered in the tracking pixel that learned to dodge Gmail.

How Do You Block Canary Mail Tracking in Gmail?

Stop the pixel from loading. Canary's own FAQ says that if the recipient blocks images, "The read receipt won't trigger, and the message will remain marked as 'Not yet read.'" Steps for a Gmail reader, using Google's help page:

  1. Turn off automatic images. In Gmail on a computer, click Settings, then See all settings, scroll to Images, choose "Ask before displaying external images," and click Save Changes.
  2. Load images only when you need them. Clicking "Display images below" fires the pixel, so skip it for anyone you don't want reporting your reads.
  3. Add a pixel blocker if you want images on. Options we checked on October 6, 2026 are listed below.
  • Trocker (10,000 users, version 3.4.1, updated July 10, 2026) blocks known trackers in webmail.
  • PixelBlock (40,000 users, updated December 2, 2025) is a Gmail extension that blocks open tracking.
  • Ugly Email survives as a Firefox add on with 2,047 average daily users and a last update on March 6, 2024; our Airmail read receipts investigation found no Chrome Web Store listing.
  • Gblock works in Gmail on desktop Chrome only. It blocks images from a tracker list that updates from Gblock's servers, flags unknown images of 150 bytes or less, and strips tracking parameters such as utm_source from links.

No extension list is complete, and none of these runs inside the Gmail phone app, where the image setting is your main defense. More detail is in how to block email tracking in Gmail and our roundup of email tracker Chrome extensions.

If You Use Canary Mail Yourself

  1. Turn read receipts off. On Mac and iPhone, Settings, General, Read Receipts; on Windows, Preferences, General, Composing; on Android, Settings, Composing, Read Receipts. Canary's pages disagree on the exact menu, so check Composing too.
  2. Leave incoming tracker blocking on. It is the part of Canary that protects you.
  3. Use Fetch instead of Push on iPhone and Android if you'd rather not send subject lines and first lines through Canary's server.
  4. Skip Copilot for sensitive threads, since its text goes to outside AI providers, and switch off "Help improve Canary" to stop diagnostics.

What We Could Not Verify

We did not install Canary or send tracked mail from it, so a few questions stay open. We don't know which of the two pixel hosts current builds use, what the /track/ filename encodes, or whether Canary blocks its own pixel when one Canary user writes to another. Canary doesn't say what Read Receipts Lite on the free plan leaves out. Its claim that IP addresses aren't collected can't be checked from outside, and the pixel sits behind Cloudflare, whose logging Canary's privacy policy never mentions.

Stop Email Tracking in Gmail

Canary Mail read receipts are on by default, so anyone emailing you from Canary can see when you opened their message. Gblock blocks known spy pixels inside Gmail on desktop Chrome and strips tracking parameters from links, so the trackers it knows stop reporting your Gmail opens.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.