Sep 03, 2026 · 10 min read
Is Dynamics 365 Tracking Your Email? How to Block It
Dynamics 365 email tracking runs in two products. Customer Insights - Journeys puts an invisible pixel in marketing mail and rewrites every link through a Microsoft host. Dynamics 365 Sales does the same to the ordinary emails a salesperson types, plus attachment views. Neither is a blanket yes, because an administrator you cannot see decides whether either is switched on.
Dynamics 365 email tracking has no single answer, because it is two mechanisms in two products and the verdict turns on a configuration choice made inside the sender's organization. A transparent pixel reports the open, a rewritten link reports the click, and both are conditional on a consent record attached to your contact profile. Everything below comes from Microsoft Learn, quoted rather than paraphrased where the wording matters.
Key Takeaways
- Microsoft documents that Customer Insights - Journeys "replaces relevant hyperlinks with trackable links and adds an invisible pixel to HTML messages" to detect opens and clicks.
- As of 10 June 2026, Journeys tracking links use the host pattern
[hashed-organization-identifier].[island].[geo].prod.marketingusercontent.com, a per tenant subdomain rather than one shared brand domain. - Journeys replaces a link only when the recipient's customer profile shows consent to tracking, and Microsoft caches that consent decision for 24 hours after it changes.
- Dynamics 365 Sales email engagement generates "a uniquely named, transparent, one-pixel GIF" for individual seller emails, and stays off until an administrator turns it on.
- Interaction data appears in the Journeys interface for the last 12 months only, but Microsoft states that "all historical interaction data is still retained in the data storage".
Does Dynamics 365 Track Email Opens?
Yes, through a tracking pixel, but only when the recipient's profile shows consent to tracking and the link was not marked as non trackable by whoever built the message.
Microsoft's page on Customer Insights - Journeys link tracking mechanics lays out the sequence. When you select a link or open a message carrying the pixel, "two things happen: 1. The recipient is redirected to the original URL. 2. The application records the link click interaction." Links are replaced only when two conditions hold: "the links aren't marked as non-trackable inside the message editor" and "the recipient customer profile shows that the customer consents to tracking."
That second condition is the whole story. Opt out before the send and the system "doesn't insert a tracking pixel or tracking links". Opt out after the send but before clicking and the interaction is stored without a customer profile reference, anonymous rather than absent. Withdrawal is not instant either: consent is cached for 24 hours, so an interaction can still be filed against your name a day after you change your mind.
What Domain Do Dynamics 365 Tracking Links Use?
Current Journeys tracking links resolve under prod.marketingusercontent.com, on a subdomain built from a hash of the sending organization.
Microsoft publishes the exact shape. As of 10 June 2026, replaced links take the form https://[hashed-organization-identifier-without-dashes].[island-number-specific].[geo-specific].prod.marketingusercontent.com/api/orgs/[hashed-organization-identifier]/r/[link-identifier]. Four variable segments sit in front of the apex: two from the sender's tenant, two from the Microsoft cluster and region it runs on.
Two things most write ups get wrong. We could not verify a documented host for the open pixel itself: Microsoft describes the pixel and publishes the redirect format, but the pixel's own hostname does not appear in the public Learn pages we checked, so treat any domain quoted for it elsewhere with suspicion. And the CNAME records on Microsoft's domain authentication page are for DKIM signing and Return Path alignment, not a branded tracking domain. New instances ship with a pre authenticated sending domain ending in dyn365mktg.com that senders are told to replace with their own, so the From address tells you nothing about the tracking underneath it.
That is the opposite of Salesforce Marketing Cloud email tracking, where a fixed host like cl.s13.exct.net makes a hand written rule viable. Microsoft's per tenant hash is unguessable in advance, so only a suffix rule works.
What Does Dynamics 365 Record About You?
Opens, clicks, bounces, spam complaints, unsubscribes, the email client you read in and the device you clicked from, all attached to your contact or lead record.
Microsoft's email insights documentation lists the KPIs a marketer sees: "the open rate, click rate, click-to-open rate, number of messages marked as spam, and count of unsubscriptions for the selected message". Microsoft is candid about the device profiling: email client detection "relies on email opens", while device type, browser and operating system detection "depends on email clicks".
Contact insights is the sharp end, and Microsoft's analytics guide describes it as "complete details of email interactions for the selected contact, including a list of all messages sent to them, plus lists of all opens, clicks, bounces, and more". A marketer can search it by a profile's email address and export up to 10,000 records to a spreadsheet. Retention is the part nobody reads: the interface shows 12 months, but "all historical interaction data is still retained in the data storage", and on aggregate dashboards Microsoft states flatly that "there's no data retention policy".
Does Dynamics 365 Sales Track a Salesperson's Individual Emails?
It can, through a separate feature called email engagement, and Microsoft describes the mechanism in more detail than almost any other vendor.
The email engagement documentation says that on a followed message "the system generates a uniquely named, transparent, one-pixel GIF and adds it to the message as a linked image". Links become redirects that log the click before forwarding you. Attachments are not attached at all: the file goes to the organization's OneDrive share and arrives as a link, so downloading it is another timestamped event. The seller gets "an immediate alert when a customer opens your message for the first time".
Then there is the line that belongs on a poster. Microsoft advises sellers: "We recommend that you always include images in your messages, like a company logo or an arresting illustration, because it motivates recipients to download them. You won't know they've opened the message if images aren't loaded." A vendor telling its customers, in writing on a public page, to bait the image load.
It is off by default. Microsoft's configuration guide has an administrator open Sales Insights settings, grant permissions and flip a toggle, and warns that "by enabling this feature, you consent to share data about your customers' email activity with other Microsoft services".
Who Decides Whether You Get Tracked?
An administrator inside the sending organization, using a setting you cannot see or verify from your inbox. The old outbound marketing module that many tenants ran this on was removed in May 2026, its data merged into real time journeys rather than deleted.
Microsoft's page on tracking consent in Customer Insights - Journeys opens with the reason it exists: "In 2026, privacy regulators issued additional guidance regarding the use of tracking pixels in email." Its recommendation is a Restrictive enforcement model on the Tracking purpose, which "ensures no tracking occurs unless the recipient explicitly opts in", exposed on forms "as its own checkbox, not pre-checked and not bundled with other consents".
That one purpose governs four things: open tracking through pixels, link click tracking, UTM parameters added to URLs, and form prefill. Microsoft is explicit that restricting it costs the sender data, warning to "expect lower identified opens, clicks, web events, journey triggers, lead scoring, and engagement-based segmentation". That is a privacy position and a revenue argument at once, which is why the setting varies tenant to tenant.
What This Means for Your Inbox
You cannot tell from outside which configuration you are on. Two emails from two Dynamics 365 customers look identical in Gmail while one files your open time against a named contact record and the other files nothing. The setting lives in someone else's tenant. The pixel request leaves your browser.
Journeys is the newsletter engine; Sales email engagement covers the ordinary one to one message a representative types after a demo call. If a company runs both, the same inbox is read at two scales: campaign analytics on one side, an instant open alert on a seller's screen on the other. The second is the uncomfortable one, because it looks like a personal email and behaves like a tracked campaign. A pixel that fires in Gmail fires in Outlook and Yahoo Mail too, so this is less a Gmail problem than an email problem Gmail gives you good tools against, as our walkthrough on detecting email tracking pixels in Gmail shows.
How Do You Block Dynamics 365 Tracking in Gmail?
Stop the image request first, then stop using the rewritten link, because they are two separate events recorded by two separate mechanisms.
- Turn off automatic image loading. In Gmail on desktop, go to Settings, General, Images, and select "Ask before displaying external images", documented on Google's image settings help page. No pixel fetch, no open recorded, in Journeys or in Sales. The cost is that no images load at all, and clicks are untouched.
- Read the raw source. Open the message, use the three dot menu and choose "Show original". Search for
marketingusercontent.cominsidehrefattributes, and for<imgtags with width and height of 1 near the closing body tag. Fifteen seconds, no tooling. - Hover before you click. Gmail shows the real destination in the status bar. A link that displays a company website but resolves to a long hashed subdomain is a redirect, and following it logs a click before you see the page.
- Do not rely on an exact hostname rule. The Journeys redirect host contains a hash of the sender's organization plus cluster and region segments, so it differs for every tenant, and the pixel's host is not publicly documented at all.
- Use a blocker that handles both events. An extension that strips the pixel and the tracking link inside Gmail covers both mechanisms without breaking the message. Gblock does this before the request leaves your browser.
- Unsubscribes and bounces are still server side. No blocker touches those. To get off a Journeys list, the preference centre is the real lever.
How Does Gblock Compare to Ugly Email, PixelBlock and Trocker?
All four block pixels. What differs is whether tracked links are handled too, how the blocklist stays current, and whether you have to leave Gmail, compared properly in our roundup of the best email tracker blocker extensions.
Ugly Email is MIT licensed, flags tracked Gmail messages with an eye icon and blocks the pixel locally. Trocker is free and open source, works across several webmail providers and marks tracked links as well as pixels. PixelBlock does straightforward pixel blocking, though its Manifest V2 lineage means you should check you are running a maintained build. Proton Mail and HEY protect inside their own clients, which is genuinely strong and irrelevant if your mail stays in Gmail.
Gblock's claim is narrow rather than better. It stays inside Gmail, strips tracking links as well as pixels, and its blocklist updates itself, which matters most against a platform like Dynamics 365 where the hostname is derived per tenant and nothing stable exists to type into a manual rule. The same applies to HubSpot email tracking, where marketing sends and one to one sales sends run through the same account.
The Honest Summary
Microsoft is not hiding this. It publishes the link format, names the pixel for what it is, and documents the consent model gating both, which makes the Customer Insights - Journeys library better documentation than most of the industry ships.
The candour does not change your position. The decision is made by someone else, cached for 24 hours after you change your mind, and invisible from the inbox where you read the message. One thing sits on your side of the wire: the image request your mail client chooses to make. Refusing it is the whole of your leverage, and against a pixel it works every time.