Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 02, 2026 · 12 min read

HEY Email Spy Tracker Blocker: How It Works vs Gmail

37signals launched HEY in June 2020 with spy pixel blocking built in. We read its documentation, its 2020 blocking code, its DNS records and its own newsletter setup to see what the blocker catches, what it misses, and whether you have to leave Gmail to get the same protection.

The HEY email spy tracker blocker has been HEY's loudest privacy pitch since 37signals launched the service in June 2020, and in 2021 HEY's traffic data gave the BBC its headline that spy pixels had become "endemic." HEY strips tracking images before a message reaches your inbox and tells you who planted them. For Gmail users the practical question is whether switching providers is the only way to stop senders from watching. It isn't. HEY's protection is real, but it works only inside HEY's own apps, it leaves a timing clue when a pixel slips through, and its own company newsletter runs on a service HEY lists as a tracker.

Key Takeaways

  • HEY says it strips known spy pixel patterns, bulk strips "everything that even smells like a spy pixel," and is "confident we'll catch 98% of all the tracking that's happening out there."
  • HEY's public spy tracker page names 49 tracking services, the same names the page showed in a Wayback Machine capture from June 18, 2020.
  • HEY's image proxy fetches images when you view an email and announces itself with the User-Agent hey.com/imageproxy, so a pixel that slips through hides your IP address but not the moment you opened the message.
  • 37signals' newsletter signup on hey.com posts to Mailchimp, a service HEY's own tracker page names, and Mailchimp enables open tracking by default; we could not confirm whether 37signals switches it off.
  • HEY costs $99 a year, has no IMAP or POP access, and works only in its own apps, so none of its blocking applies to mail you read in Gmail.
Person in a warmly lit cafe holding a smartphone that shows a minimalist email app with a small glowing shield icon, beside a coffee cup and an envelope, illustrating the HEY email spy tracker blocker

How Does the HEY Email Spy Tracker Blocker Work?

HEY removes tracking images on its servers before a message lands in your inbox, using a list of known tracker patterns plus a catch all rule for anything that looks like a pixel. Its spy tracker page describes the layers in its own words:

  • Known patterns. "We've identified all the major spy-pixel patterns, so we can strip those out directly. When we find one of those pesky pixels, we'll tell you exactly who put it in there, and from what email application it came."
  • Generic stripping. "We bulk strip everything that even smells like a spy pixel. That includes 1x1 images, trackers hidden in code, and everything else we can do to protect you."
  • Image proxy. "HEY routes all images through our own servers first, so your IP address never leaks."

You can read an early version of that logic. On April 23, 2020, before launch, HEY cofounder David Heinemeier Hansson published HEY's blocking module as a GitHub gist titled "Current list of spy pixels named'n'shamed in HEY." It is a Ruby concern called Entry::TrackerBlocking that maps 49 services to URL patterns, such as list-manage.com/track for Mailchimp and r.superhuman.com for Superhuman. Two specialized blockers follow, LitmusCssPixelBlocker and GmassPixelBlocker, then GenericSmallPixel. A code comment explains the order: the generic rule must run last, "Otherwise, it could catch pixels for some of the services we're explicitly tracking." That ordering is what lets HEY name the sender instead of just saying "tracker removed."

What Does HEY's Image Proxy Still Reveal?

It hides your IP address and location, but it fetches images when you view a message, so a pixel that survives the stripping step still tells the sender roughly when you opened it. HEY's image proxy documentation is unusually candid. It calls the service "a caching image proxy service that fetches images on behalf of HEY email users," adding: "When users view emails containing external images, the proxy fetches those images."

The same page lists details a developer will find useful:

  • Every request carries a User-Agent beginning hey.com/imageproxy, and requests come from gopher.hey.com.
  • It caches images and "Honors Cache-Control, Etag, Last-Modified, and Expires headers," so a sender's own cache headers decide whether a reopen triggers a fresh request.
  • It "Follows redirects," accepts only image/* content, blocks SVG "due to script execution risks," and "Does not send referrer information."
  • The code is "a private fork of willnorris/imageproxy," an open source Go project.

Put those together and the weakness is clear. A tracking server that receives a request with that User-Agent learns two things: the recipient reads mail in HEY, and the message was just opened. The proxy hides who and where, not when. Proton Mail chose differently. As our Proton Mail tracking investigation found, Proton loads remote images as soon as a message is delivered, so every Proton address looks opened on arrival and the open time becomes noise.

How Well Does HEY's Blocker Actually Work?

Nobody outside 37signals has audited it, so the 98% figure is HEY's own estimate. The best public data point came from a BBC investigation published February 17, 2021, for which HEY analysed its traffic at the BBC's request. HEY found that "two-thirds of emails sent to its users' personal accounts contained a 'spy pixel', even after excluding for spam." Hansson told the BBC: "On average, every Hey customer receives 24 emails per day that attempt to spy on them," and "that's north of 600,000 spying attempts blocked every day."

The same article contains a detail HEY's marketing does not repeat: "The BBC also uses email pixels in some of its communications, although this was not picked up by Hey."

The public list has not moved much either. We compared the 49 service names on today's spy tracker page with a Wayback Machine capture from June 18, 2020: they match. HEY's internal list may be longer, and the page promises "we vow to keep them updated all the time," but the version anyone can check has stood still for six years. For comparison, the built in list in Gblock's extension names 209 trackers and senders, and Gblock adds more from a server side list it downloads.

Does HEY Offer Read Receipts or Track the Email You Send?

No, HEY offers no read receipts or open tracking to senders, and it says so directly. The spy tracker page closes with: "And of course, HEY will never embed spy trackers in emails you send either. We'll protect your privacy, but we'll also protect the privacy of anyone you email."

We found no read receipt feature on HEY's features page or among the articles in the features, FAQ and troubleshooting sections of help.hey.com; the only "receipts" in HEY's vocabulary are purchase receipts filed in the Paper Trail. That puts HEY alongside Missive, which dropped read tracking in 2020, as our Missive investigation found, and opposite Superhuman, whose read statuses rely on the very pixel pattern HEY blocks.

Does HEY's Own Marketing Email Contain Tracking Pixels?

We could not prove either way, but 37signals sends its company newsletter through Mailchimp, and Mailchimp tracks opens unless the sender turns it off. Our DNS and page checks ran on October 2, 2026:

  • hey.com: MX points to home-mx.app.hey.com, and the SPF record includes only _spf.hey.com, which lists a single 37signals IP range (204.62.114.0/23). The DKIM selector heymail holds a real key. Mail sent from HEY addresses goes out on 37signals' own servers with no outside email service.
  • 37signals.com: SPF includes _spf.basecamp.com and servers.mcsv.net, Mailchimp's sending network. The DKIM selector k1 is a CNAME to dkim.mcsv.net, Mailchimp's signing key.
  • The signup form: the "Join more than 200,000 people who get our email newsletter" box at the bottom of HEY's spy tracker page posts to basecamp.us2.list-manage.com, a Mailchimp address. The public archive for that list is titled "Basecamp Company Newsletter"; its latest issue, "Introducing Fizzy, new from 37signals," went out on December 11, 2025.

Mailchimp's open tracking help page says: "Open tracking is enabled by default except on plain-text emails," and describes "a tiny invisible graphic in the bottom of your HTML email." Archive copies of campaigns do not show tracking, so we can't tell whether 37signals disables it. The irony stands regardless: the page that lists MailChimp as a spy tracker also signs you up to a Mailchimp list. If you read that newsletter in HEY, HEY would strip the Mailchimp pixel. Read it in Gmail and nothing would. We break down Mailchimp's tracking in does Mailchimp track email opens.

Two control checks keep these findings honest. Every candidate tracking hostname we tried under 37signals.com (track, tracking, pixel, t, open, click, links, email, e, go) returned NXDOMAIN, and so did a nonsense control name. Under hey.com the same names, and the nonsense control, all returned NOERROR with no address record, a sign of a wildcard, so resolving there proves nothing. The first 50 certificate issuances for hey.com in the CertSpotter log covered 13 names, none tracking related.

What Can't HEY Do?

HEY can't protect any inbox except its own, and its public pages make no promise about tracked links. The limits, each from HEY's own documentation:

  • It replaces Gmail rather than sitting on top of it. HEY's help center answers "Do I need Gmail, Outlook, Apple, etc. to use HEY?" with: "No. HEY is an email provider, it's not an app you use to check your existing Gmail, Outlook, Yahoo, etc." (source)
  • No IMAP or POP. "HEY doesn't support IMAP or POP," so it can't check your other accounts (source), and HEY says "off-the-shelf 3rd party email apps won't work with HEY" (source).
  • Gmail forwarding keeps a copy in Gmail. HEY's moving from Gmail guide says "Gmail will keep a copy of every email it forwards into HEY." Opening that copy in Gmail gets no HEY protection.
  • Links are not part of the pitch. The spy tracker page talks only about pixels and images, and the proxy page says it "Never follows links." HEY doesn't claim to clean click tracking redirects or strip parameters like utm_source, the gap our guide to email open tracking vs click tracking explains. We could not test it without an account.
  • Price. HEY's pricing page lists HEY for You at $99 a year, billed annually only, with a 30 day trial and no card required. HEY for Domains, for your own domain, costs $12 per user per month ($10 for the first user), with no free trial. HEY for Families costs $179 a year in total and adds up to four more people.

What This Means for Your Gmail Inbox

Spy pixel protection follows the app you read in, not the address a message was sent to. Gmail's own proxy hides your IP address, but Google's image help page concedes: "Sometimes, senders may know whether you've opened an email that has an image." In practice they know far more often than "sometimes," for reasons we lay out in the tracking pixel that learned to dodge Gmail.

So you can move to HEY and forward Gmail into it, or stay in Gmail and add a blocker. HEY's privacy goes beyond pixels: its no data extraction page says HEY "only accesses the data we need to in order to run an email service." No extension changes what Google can read. But if spy pixels are your main complaint, you don't have to change providers to deal with them.

How Do You Block Spy Trackers Without Leaving Gmail?

Use a Gmail extension on desktop, or set Gmail to ask before displaying external images. The main options, checked on October 2, 2026:

Tool Where it works Pixels Links
HEY HEY's own apps; $99 a year 49 named services plus generic 1x1 stripping; images proxied when viewed Not covered on its tracker or proxy pages
Proton Mail Proton's web and mobile apps Known trackers removed; other images preloaded at delivery Parameters cleaned on web; redirects kept
PixelBlock Gmail in Chrome; 40,000 users Blocks open tracking; last updated December 2, 2025 Listing describes open tracking only
Trocker Webmail in Chrome; 10,000 users Blocks tracking images; version 3.4.1 from July 10, 2026 Says it prevents "tracked links from being loaded"
Ugly Email No longer available on the Chrome Web Store None None
Gblock Gmail in desktop Chrome only Blocklist that updates itself; flags unknown tiny images Optional: links routed via its proxy, tracking parameters stripped

The fair comparison between HEY and Gblock comes down to four differences:

  • Where the blocking happens. HEY strips pixels on its servers. Gblock turns its list into Chrome declarativeNetRequest rules scoped to images requested by mail.google.com, so a matching pixel never loads in your browser.
  • Unknown pixels. HEY strips any 1x1 image up front. Gblock blocks only what is on its list; when an unlisted image of 150 bytes or less loads, it flags it and reports it so the list can grow. HEY is stricter on first sight.
  • The list. Gblock combines its 209 built in entries with a list it downloads from Gblock's server, so new trackers can be added without an extension update. HEY's public list has not changed since 2020.
  • Links. With click tracking protection switched on, available on trial and paid plans, Gblock rewrites links to pass through its proxy, which follows the redirect chain on Gblock's servers and strips parameters such as utm_source, mc_eid and _hsenc before you land. The sender's click server still records a visit, but from the proxy, not your browser.

Gblock's limits, plainly: it does nothing in the Gmail mobile app, in desktop mail apps, or inside HEY. If you read every message in HEY, you don't need it. For setup, see how to block email tracking in Gmail, our roundup of email tracker Chrome extensions, and the Gmail privacy extension comparison, which weighs HEY and Proton against the extension route.

What We Could Not Verify

We did not open a HEY account or send tracked test mail to one, so every claim about HEY's behavior comes from its published pages, its 2020 code and the BBC's reporting. HEY's current blocking code is private, so we can't say how far it has moved from the 2020 gist, how it handles click tracking links, or what exact label it shows next to a blocked tracker. We did not see a delivered copy of the 37signals newsletter, so whether it carries Mailchimp's open pixel remains open. The 98% catch rate and the 2021 traffic figures are HEY's numbers, not independent measurements.

Stop Email Tracking in Gmail

The HEY email spy tracker blocker only protects mail you read inside HEY. Gblock blocks spy trackers inside Gmail on desktop Chrome, with a blocklist that updates itself and optional tracking link protection, so you can keep your Gmail address and still stop senders from watching.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.