Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 14, 2026 · 9 min read

Is EmailOctopus Tracking Your Email? How to Block It

Almost every review calls EmailOctopus a cheap front end for Amazon SES. That was true of the 2015 product, not of the platform senders use today, which changes the one thing that matters to you: the hostname your clicks travel through.

EmailOctopus tracking switches on the moment a sender creates a campaign, and the received wisdom about where it phones home is wrong. To block EmailOctopus email tracking by recognising a vendor hostname, the one to know is sptr.eocampaign1.com, not the Amazon domain named in every roundup of budget email tools. Both are correct, for two different EmailOctopus products, and the popular one covers the smaller half.

Key Takeaways

  • EmailOctopus's campaign tracking documentation states that "by default, all campaigns and automated emails have tracking enabled."
  • Click links on the main EmailOctopus platform route through sptr.eocampaign1.com, confirmed from a captured live tracking URL and a DNS chain ending at an AWS load balancer named emailocto-espsecuretrackingproxy.
  • EmailOctopus Connect, the original 2015 product, is the one built on Amazon SES, and its documented default tracking domain is awstrack.me.
  • A campaign report names the contacts who opened, who clicked which link, when, and how often, all exportable.
  • EmailOctopus offers no recipient facing control, and its privacy policy states: "we do not have any relationship with Contacts."

Does EmailOctopus Track Email Opens and Clicks?

Yes to both, and it is the default. EmailOctopus's campaign tracking page opens with the sentence that settles it: "By default, all campaigns and automated emails have tracking enabled." Automated matters there: welcome sequences and drip series carry the same instrumentation, without anyone deciding again.

Senders can switch it off, and the same page does something few vendors do: it suggests they consider it. "If you're not actively using your metrics, we would go as far as to recommend this approach." A tracking company telling customers to track less. Notice the shape of it though: the toggle lives in the sender's account, and the default points the other way.

What Domain Serves the EmailOctopus Tracking Pixel and Links?

On the main platform, sptr.eocampaign1.com. That appears in no EmailOctopus documentation, so here is how we established it rather than asking for trust.

A publicly archived URL scan captured a live tracking link shaped like https://sptr.eocampaign1.com/f/a/<token>~~/<token>~/<token>, redirecting to an EmailOctopus unsubscribe page. Then the DNS. On 14 August 2026 that host resolved as a CNAME to stp.eoidentity.com, itself a CNAME to an AWS load balancer in eu-west-1 named emailocto-espsecuretrackingproxy. The infrastructure describes itself. One limit: we verified the click redirect host, not an open pixel URL, so treat that hostname serving the pixel as a strong indication rather than a confirmed fact.

EmailOctopus's domain verification guide adds a second hostname, saying mail from unverified free addresses is "routed through one of our own domains," making the envelope sender something like youremail.gmail.com@send.eocampaign1.com. It also sets the ceiling on hostname blocking: once a sender verifies their domain, "all links within the email will be tracked using your own domain." We unpack those mechanics in our guide to email link wrapping and click tracking.

A laptop showing an email inbox on a wooden desk in low warm lamplight, beside reading glasses, a notebook and a ceramic mug

Why "EmailOctopus Runs on Amazon SES" Is Now Misleading

Because it describes a different product from the one most people use. EmailOctopus's own comparison page draws the line: Connect "integrates with Amazon Simple Email Service (SES)... So your emails are actually being sent through Amazon," and it is "the 'original' product we set up in 2015." The main platform sends through EmailOctopus's own arrangements.

That split yields two different tracking hostnames, and only one is documented. EmailOctopus's custom action and tracking domain article covers Connect only, and it is unusually explicit. The tracking domain is where "every link will be redirected" and is also used "for the transparent image used to tracking opens." Its default is "a domain belonging to Amazon Web Services, and will be something like 'https://awstrack.me'." That is standard Amazon SES behaviour, so our breakdown of what Amazon SES tracking records applies to Connect mail unchanged.

Hence the consequence. Block awstrack.me on the strength of the review sites and you have covered the legacy product, while mail from the platform EmailOctopus actively sells goes through a host with no Amazon branding in it. As for what sits behind that host, EmailOctopus's privacy policy names the upstream providers in one line: "Our ESPs are SendGrid and SparkPost." That policy is dated 25 June 2020, so read it as evidence rather than a live inventory.

What Does the Sender Actually See About You?

Your address against every action, not a percentage. EmailOctopus's report guide lists what a campaign report holds: opened, clicked, who clicked which link, unsubscribed, bounced, complained, did not open, did not click. Read the last two again. Not opening is a recorded, filterable state. Silence is data.

The link level view goes finer. EmailOctopus's instructions for checking clicks tell senders they can see "the email address of each of the contacts who clicked the link, along with the fields assigned to them, the time the contact clicked the link and the total number of clicks," then add: "you can export that data by clicking on the Export button." One button, and your behaviour leaves the platform as a spreadsheet outliving your subscription.

What we could not find matters too. The documented API response for a clicked report returns the contact object and an occurred_at timestamp, with no IP address or device field, so we will not claim EmailOctopus hands geolocation to senders. The redirect necessarily sees your IP address and user agent, but seen by the proxy and given to the sender are different things.

Can You Opt Out of EmailOctopus Tracking?

No. There is no recipient facing control, no preference page, no header you can set. EmailOctopus's privacy policy is candid about why: "We do not have any relationship with Contacts." Your only documented exit is unsubscribing, itself a tracked click on the way out.

In Europe the obligation has a defined shape. The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive concluded that a tracking pixel instructs your device to send information to a remote server, bringing it inside the consent requirement. That duty sits with the newsletter, and nothing in the message reveals which senders took it seriously.

How Do You Tell If an EmailOctopus Message Is Tracking You?

Read the raw source, where the hostnames are written down whether or not anyone meant you to see them.

  • In Gmail on desktop, click the three dot menu at the top right of the message pane and choose Show original.
  • Press Ctrl+F or Cmd+F and search for eocampaign. Hits inside href attributes are wrapped click links; a hit inside an img tag is the open pixel.
  • Search for awstrack too. A hit means the sender is on Connect, running through Amazon SES.
  • Nothing found? A verified sender wraps links on their own subdomain, so the giveaway is a link host differing from the destination on every link.

Our guide to detecting tracking pixels in Gmail covers the same method elsewhere. It settles one sender well, and nobody sustains it daily, which is the argument for automating it.

How Do You Block EmailOctopus Tracking in Gmail?

An open event exists only if your client fetches the image, so the contest is over that one request. Three approaches, costs included.

Turn off automatic image loading. In Gmail, open Settings, See all settings, and under Images choose "Ask before displaying external images". Nothing loads until you approve it, which defeats every open pixel whatever host serves it. Gmail's default proxy is no substitute: it serves images through Google and hides your IP address, but still fetches them, so the open fires anyway. The cost is that logos and receipts stop rendering, and most people revert within a fortnight.

Do not click the links. Blunt, and decisive against the half that matters most, since the redirect reveals your network and browser in real time. Copy the destination from the source view instead.

Run a blocker extension inside Gmail. The only option that keeps images working while refusing the tracking request, because it filters by host rather than blocking everything, and the only one here that touches the click side.

EmailOctopus Tracker Blockers Compared

No blocker catches everything, and against a verified sender domain the differences narrow:

  • Apple Mail Privacy Protection. Not a blocker. Apple's feature hides your IP address but fires the pixel on delivery for mail you never read, which is why EmailOctopus's guidance on MPP tells marketers to "shift your focus to other metrics, such as click-through rates."
  • Ugly Email. Flags tracked messages with an eye icon in the Gmail list. An early warning system, not a stripper.
  • PixelBlock. Blocks open pixels and reports what it blocked, but leaves rewritten links alone. A real gap here, where every link routes through the redirect.
  • Trocker. Works across several webmail providers and shows where the pixel sits.
  • Proton Mail and HEY. Both block remote content by default. Strong, but you are changing provider rather than filtering the account you have.

Gblock sits in the extension category, and its differences are specific rather than sweeping. It runs inside Gmail, so you keep the account you already use. Its blocklist updates automatically, which matters against a vendor whose tracking hostnames are undocumented and numbered. And it strips tracking links as well as pixels, the half EmailOctopus's redirect depends on. The ceiling is structural: any tool matching known hostnames is weaker against a sender wrapping links on their own verified subdomain. An excellent filter, not a wall. Our roundup of email tracker blocker extensions maps where each option runs out.

What This Means for Your Inbox

EmailOctopus is a small British company selling cheap newsletter software, and its documentation is more forthcoming than that of competitors ten times its size. It suggests switching tracking off. It names its upstream providers. It also ships tracking on by default, publishes no hostname for its own proxy, and offers you no control.

That gap is the whole subject, and it is not a story about a villain. It is a story about defaults, and what "on unless someone opts out" means when the someone is never asked. It is also why the open rate is a fiction from both directions: senders inflate it with Apple's preloaded pixel fetches, while recipients are measured by a number marketers have stopped trusting.

So the stance for an EmailOctopus heavy inbox is neither alarm nor complacency. Assume tracking unless the raw source says otherwise, treat the click as the expensive action, and put your filtering where the decision is genuinely yours: your own client, before the request leaves your machine.

Stop Email Tracking in Gmail

EmailOctopus tracking is on by default, and its click links travel through sptr.eocampaign1.com or a subdomain the sender verified themselves, so there is nothing in the message you would recognise by eye. Gblock blocks marketing platform tracking pixels and strips tracking links inside Gmail automatically, with a blocklist that updates itself.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.