Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 16, 2026 · 7 min read

Is Mailmeteor Tracking Your Email? How to Block It

Mailmeteor is the mail merge add on that markets itself on privacy and cannot read your mailbox by design. It also tracks opens and clicks on every Gmail send automatically, from a shared subdomain that never says its own name.

A mail merge landed in your inbox this morning. It looked like a personal message, it used your first name, and it came from a real person at a real company rather than a marketing platform. That is the entire point of a tool like Mailmeteor: mail sent through Gmail, from a human address, with none of the visual tells of a bulk campaign. What arrives with it is a tracking pixel that the sender did not have to switch on, because it was already on.

Key Takeaways

  • Mailmeteor's Gmail documentation states that "every email you send from Gmail will be automatically tracked for opens and clicks, no extra setup required".
  • Opens are measured with a tracking pixel hosted on Mailmeteor's servers; clicks are measured by rewriting each link into a tracked URL that redirects to the original.
  • By default the pixel is served from a shared pool of domains, giving each sender an account specific subdomain that Mailmeteor's own docs illustrate as johndoeexampleorg.mmtracking.appspot.com.
  • Mailmeteor states it generates random unique IDs per recipient, never stores the email addresses of recipients who opened or clicked, and does not store recipient IP addresses.
  • Senders can pay for a custom tracking domain such as click.example.com, which makes the pixel look like part of the sender's own brand and harder to recognise.

Does Mailmeteor Track Email Opens?

Yes, and in the Gmail integration it does so without the sender choosing to. Mailmeteor's Gmail email tracking documentation says every email sent from Gmail is automatically tracked for opens and clicks with no extra setup, and that a sender who does not want it has to disable it for that individual message.

The mechanism is unremarkable, which is why it works. Mailmeteor's support pages describe it plainly: "Mailmeteor embeds a tiny image, called a tracking pixel, in your emails. This image is hosted on Mailmeteor's servers and, when downloaded by someone, is considered as an open." Clicks work by rewriting each link so it points at Mailmeteor first, which records the click and then redirects you to where you thought you were going.

This puts Mailmeteor in the same functional bracket as GMass, Streak and Yesware: a tool that turns an ordinary Gmail message into an instrumented one while leaving it looking exactly like ordinary Gmail.

What Domain Does the Pixel Come From?

Not one with Mailmeteor's name on it. The company's custom tracking domain documentation states that "Mailmeteor uses by default a pool of domain names that are shared amongst all of our users", and gives a worked example: a sender using john@example.org gets the subdomain johndoeexampleorg.mmtracking.appspot.com.

That host is worth pausing on. appspot.com is Google App Engine's default domain, so the tracker resolves to generic Google infrastructure. Requesting the root of mmtracking.appspot.com returns an HTTP 404 served with server: Google Frontend and a x-cloud-trace-context header, consistent with an App Engine application rather than a marketing vendor's own estate.

Two consequences follow. Anything that filters by recognisable tracker names will not flag it, because the visible string is a Google domain. And the subdomain itself is derived from the sender's address, so the tracking host is effectively an identifier for who sent you the message, sitting in the HTML of an email that otherwise looks entirely personal.

An open laptop with a dark screen on a wooden desk beside a phone, a closed notebook and a black mug, with daylight coming through a curtained window

What Does the Sender Actually See?

Six states per recipient, updating in real time. Mailmeteor's tracking report documentation lists them as sent, opens, clicks, replies, bounces and unsubscribes, with a campaign status column written back into the sender's Google Sheet so the row with your name on it shows whether you opened.

Read that as a recipient rather than as a marketer and the shape of it changes. The person who mailed you can see that you opened, roughly when, and whether you followed the link, and they can see it beside your name in a spreadsheet they already had. In a cold outreach context that is the input to a follow up. In a personal or professional context, it is the reason a message you thought you had quietly ignored gets a reply asking whether you had a chance to look.

What Does Mailmeteor Store About You?

Genuinely less than most of this category, and the company's privacy documentation is specific about it rather than vague.

It states that "we generate random and unique Mailmeteor IDs for each recipients", that "Mailmeteor never stores the email addresses of recipients who opened or clicked emails", and that "Mailmeteor does not store IP address of your recipient neither". Retention is stated in numbers: email events such as opens, clicks, unsubscribes and replies are kept for 90 days, and recipient addresses and merge fields for 180 days. The add on's Google permission is limited to sending mail on the user's behalf, so it "cannot read, modify or delete your emails by design".

All of that is meaningfully better than a platform that logs your IP, resolves it to a city, and fingerprints your mail client. It also does not change your situation much. The opaque ID is opaque to Mailmeteor, not to the sender, whose spreadsheet already maps that row to your name and address. No IP logging removes the geolocation risk; it does not remove the fact that a message you opened told someone you opened it.

Is a Custom Tracking Domain Better or Worse for You?

Better for the sender, worse for you.

Mailmeteor sells a custom tracking domain as a deliverability and trust feature, with examples like click.example.com, email.example.com or telemetry.example.com. When a sender configures one, the pixel and the rewritten links stop pointing at a shared appspot subdomain and start pointing at a subdomain of the sender's own company.

From the inbox, that is the difference between a tracker you might notice and one you almost certainly will not. A link to click.acmecorp.com reads as the company's website. This is the same first party manoeuvre the whole industry has converged on, and it is why "does the domain look like a tracker" has quietly stopped being a usable test.

How Do You Block Mailmeteor Tracking?

  • Stop the pixel loading in the first place. An open is only recorded because your client fetched a remote image. Gblock removes tracking pixels from messages in Gmail before the request goes out, so the mail merge in your inbox reports nothing back regardless of which domain it was going to use.
  • Turn off automatic image loading in Gmail. Settings, General, then "Ask before displaying external images". Blunt, free, and it breaks every legitimate image too, which is why it tends not to survive a week.
  • Do not click the link in the message. Every link in a tracked Mailmeteor send is a redirect. Copy the visible destination, or search for the page instead, and the click never gets attributed.
  • Reply rather than click when you can. Replies are tracked too, but a reply is a deliberate act you already intended; a silent open is not.
  • Look at the message source when it matters. Our guide to detecting email tracking pixels in Gmail shows how to find the image and the rewritten links. An appspot.com host in an otherwise personal email is a strong indicator that a mail merge tool sent it.
  • Do not assume Apple's protection covers you. Apple Mail's approach prefetches images for everybody, which manufactures fake opens rather than preventing them. It protects the accuracy of the data more than it protects you, and it does nothing at all in Gmail on a desktop browser.

The Honest Summary

Mailmeteor is one of the more defensible tools in this series. It asks for a narrow Google permission, it does not want to read your mailbox, it does not log recipient IP addresses, it publishes actual retention periods, and it lets a sender turn tracking off with one control. Compared with a sales engagement platform that fingerprints every open, it is a different class of product.

And it still ships with tracking on for Gmail sends, still measures your opens from a domain that looks like generic Google infrastructure, and still tells the sender that you read the message. The privacy claims are about what Mailmeteor knows. The pixel is about what the sender knows, and that is the part that reaches you. Blocking the request is the only version of this that does not depend on somebody else's setting.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.