Aug 23, 2026 · 9 min read
Is Cordial Tracking Your Email? Block track.cordial.io
Cordial is the enterprise messaging platform behind email from Levi's, L.L.Bean, Boot Barn, Pacsun, Virgin Voyages, and Realtor.com. Its open pixel starts the record, every link redirects through track.cordial.io, and a 30 day identity window can reach backwards to attach browsing you did before the brand knew your name.
If a promotional email from a large US retailer is in your inbox right now, cordial email tracking may well be running inside it. Cordial sends email, SMS, and mobile push for consumer brands, and it records far more than "this person opened the message." The open pixel starts the record. The redirect through track.cordial.io continues it. Then a 30 day identity window reaches back in time and staples browsing you did anonymously onto the profile holding your email address. Here is what gets logged, what the brand can switch off, and how to stop it inside Gmail.
Key Takeaways
- Cordial tracks message open and link click events for 30 days from the moment a message is sent, per its own knowledge base.
- track.cordial.io serves the redirect for every tracked link in a Cordial email and also hosts the track.v2.js listener that runs on the sending brand's website.
- Cordial's Identity+ stores 30 days of anonymous session data and, in Cordial's own words, "all previously anonymous activity will be retroactively applied to the newly known profile" once you are identified.
- Levi's, L.L.Bean, Boot Barn, Pacsun, Virgin Voyages, and Realtor.com are publicly named Cordial customers.
- A marketer can disable tracking on one link with the
data-crdl-notrackattribute, but tracking is on by default and there is no recipient side switch.
Does Cordial Track Your Email?
Yes. Cordial records opens and link clicks by default, and its documentation is explicit about the window: message open and link click events are tracked for 30 days from the time a message is sent. Opens use the ordinary mechanism, a small transparent image referenced in the message HTML that reports to Cordial's servers the moment your mail client renders it.
This is not exotic behavior. Researchers at Princeton measured the practice across a large corpus and found that 70 percent of emails embed at least one tracker, most of them the same trackers operating on the open web.
Cordial is candid about how weak the open signal is. Its own guide to email metrics states that "open rate is not a very reliable metric because some email providers like Hotmail and Yahoo automatically open emails." Which tells you where the value sits: not in the open, but in what follows the click.
What Is track.cordial.io?
track.cordial.io is Cordial's default tracking hostname, and it does two jobs at once. In your inbox it is the redirect every tracked link passes through before reaching the brand's real page. On the brand's website it is where the tracking script lives: Cordial's Embedded JavaScript Listener v2 documentation has merchants load track.v2.js from that same host.
The shared hostname is what makes the handoff work. Cordial's documentation states that if a contact arrives on the site from a tracked link, cookies will be set to identify the contact. The click is not a click count. It is the moment a message recipient becomes a recognized browser session.
The URL shape gives it away. Publicly archived Cordial click URLs take the form track.cordial.io/c/ followed by colon separated identifiers and two hash segments, encoding both the message and the recipient. That is why a Cordial link is personal to you even when the visible text reads "Shop new arrivals."
What Happens After You Click a Cordial Link?
You stop being anonymous, and so does your past. Cordial sells an identity resolution product called Identity+, and its own press release describing it is blunter than anything a privacy blog would write for it: unidentified session information "will be stored for 30 days connected to that specific anonymous user," and if Identity+ names you inside that window, "all previously anonymous activity will be retroactively applied to the newly known profile."
That inverts how most people picture tracking. The usual mental model is a line drawn forward from the moment you identify yourself. Identity+ describes a buffer instead: a month of browsing held against an anonymous identifier, waiting for one identified click to resolve it. A single link clicked in late August can attach browsing you did in late July.
The matched identifiers are broad. Cordial's identity resolution page describes connecting "online identifiers from browsers, device IDs, email addresses, and more," and the press release lists cookies, PII, and customer IDs among the ID Graph signals. Cordial claims clients see a 20 to 30 percent lift in identified contacts, meaning a quarter more named people out of the same traffic the brand already had.
Which Brands Send Email Through Cordial?
Levi's, L.L.Bean, and Boot Barn are named as customers in Cordial's own March 2026 Forrester Wave announcement, with Realtor.com, Virgin Voyages, and Pacsun cited elsewhere in its press materials: a fairly ordinary week of promotional mail for a lot of American inboxes.
In The Forrester Wave: Email Marketing Service Providers, Q1 2026, Cordial was one of three Leaders out of twelve vendors and took the highest possible score in ten criteria. Two of those ten sit in the same sentence of the release: identity resolution and consumer privacy.
Most coverage would call that a contradiction. It is not, and understanding why matters more than the gotcha. "Consumer privacy" in an enterprise software evaluation means consent capture, suppression handling, and data governance, and Cordial appears to do those properly. It does not mean less tracking. A platform can score top marks on privacy machinery while being built to convert anonymous browsing into a named profile. Nothing here is unlawful, and the collection happens anyway.
How Do You Tell If an Email Came Through Cordial?
Hover over any link or button and read the destination in your browser's status bar. If it points at track.cordial.io, the message came through Cordial. It is the same technique described in our guide on how to tell if your email is being tracked.
For certainty, open the message in Gmail on desktop, click the three dot menu at its top right, and choose "Show original." Search the raw output for cordial: it usually appears in the open pixel's image source and in the click redirect hostnames. Larger brands sometimes configure a branded tracking domain, so absence is not proof, but presence is.
Do not read anything into the From address, since every enterprise platform supports authenticated custom domains. Cordial joins the enterprise platforms in this series whose click redirect doubles as an identity join, alongside Braze, Iterable, Emarsys, and Bloomreach. The hostname changes. The architecture does not.
Can Marketers Turn Cordial Tracking Off?
They can, at three levels. Cordial's documentation on disabling link tracking describes a per link opt out using the data-crdl-notrack attribute, a message level toggle through the setEmailLinkTracking Smarty utility, and a separate setEmailOpensTracking utility for the open pixel.
The controls are granular. What they are not is a default. Every link is tracked unless someone marks it otherwise, so each switch means choosing measurement loss on purpose, and in practice they cover transactional links and unsubscribe flows rather than campaigns built for attribution. A brand has three documented ways to stop tracking you and no commercial reason to use them. You have none unless you install one.
Does Apple Mail Privacy Protection or Gmail Image Proxying Stop It?
Neither stops the part that matters. Apple Mail Privacy Protection fetches remote images through Apple's proxy servers, hiding your IP address and location from the sender but registering an open for essentially every message delivered. Your privacy improves; the brand's open data turns to noise. We covered that trade in Apple Mail Privacy Protection and fake email opens.
Gmail users get less. Google proxies images through its own servers, masking your raw IP while the open still registers. Neither company touches the link. Image proxying does nothing about a redirect through track.cordial.io, nothing about the cookies set when you land on the brand's site, and nothing about the 30 day retroactive join on the other side. Since Cordial itself calls the open unreliable, image proxying defends the weaker signal and ignores the stronger one.
How to Block Cordial Email Tracking in Gmail
Two separate things need stopping: the pixel that logs the open, and the redirect that identifies you on the way to the brand's site. Most tools handle the first. Fewer handle the second, and with Cordial the second is where the real collection happens.
Gblock is a Gmail extension that blocks tracking pixels before they load and strips tracking links so a click reaches the destination without the identifying redirect. Its blocklist updates automatically, which matters because enterprise platforms rotate tracking hostnames, and it works inside Gmail rather than asking you to move mailboxes.
The alternatives, honestly:
- Ugly Email and PixelBlock are free Gmail extensions that flag or block open pixels. Both do that well, but neither strips redirects from links, so the Cordial click handoff survives.
- Trocker works across several browsers, blocks pixels from multiple providers, and marks tracked links.
- Proton Mail strips trackers server side and HEY quarantines tracked messages. Both work, and both mean leaving Gmail.
- Gblock stays in Gmail and covers the pixel and the link together, the combination Cordial's architecture requires.
Our side by side of the options is in the best email tracker blocker extensions, and the method level breakdown is in how to block email tracking in Gmail. Two manual habits also help: switch Gmail to "Ask before displaying external images" under Settings, General, Images, and type a brand's domain into the address bar instead of clicking through.
Where Does Cordial Tracking Sit for Compliance?
Under GDPR, Cordial is a processor and the sending brand is the controller, so the consent obligation for the pixel and the redirect rests with the retailer. That allocation is standard across sending platforms, and it is why a top score on regulatory compliance and a tracked open sit comfortably in one product.
Europe has been tightening. France's data protection authority published a recommendation requiring explicit consent for tracking pixels in email, covered in the CNIL email tracking pixel recommendation, and Italy's Garante followed with its own rules on email tracking pixels. The retroactive 30 day join is the piece hardest to square with a consent notice, since the data was gathered before there was anyone to ask.
In the United States, where most Cordial mail is sent and received, the picture is looser: state privacy laws cover a majority of Americans, but email engagement tracking is rarely named as a category. The conclusion is the one that applies to every platform in this series. Regulation will not change what lands in your inbox this month. The blocking you control is the blocking that happens.
Sources: Disable link tracking; Embedded JavaScript Listener v2; Cordial on Identity+; Forrester Wave, Q1 2026; Englehardt et al., PETS 2018.