Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 05, 2026 · 12 min read

Mimestream Read Receipts: Does Mimestream Track Your Email?

The native Gmail app for Mac has blocked known trackers since June 2020 and sends no read receipts. We read its docs, its 2020 to 2026 release notes, its privacy policy and the tracker list inside version 1.10.8 on October 5, 2026.

Mimestream read receipts don't exist: the Mac app neither asks for them nor sends them, and it offers its own users no way to track opens. On incoming mail, Mimestream email tracking protection is real but limited. It blocks a fixed list of known tracking pixels and can hold back every remote image until you click. What it doesn't document is the safety net Gmail's own website gives you, an image proxy that hides your IP address. Read your Gmail in Mimestream, load the images, and you're relying on the blocklist alone.

Key Takeaways

  • Mimestream documents no read receipt or open tracking feature, and the 1.10.8 app binary contains no Disposition-Notification-To header, the field that requests a standard read receipt.
  • Mimestream version 0.6.6, released June 29, 2020, added "Prevent tracking when viewing messages," which its help center says "blocks common trackers" on a "best-effort basis."
  • Version 1.10.8 ships 78 tracker URL patterns, by our count, enforced through Apple's WebKit content blocker; they include patterns for four rival email apps, Superhuman, Shortwave, Canary Mail and Mailspring.
  • Google's Gmail API reference describes a message as "The entire email message in an RFC 2822 formatted and base64url encoded string," and neither Google nor Mimestream documents an image proxy for API clients.
  • Mimestream's privacy policy, updated September 21, 2026, says its apps "do not transmit your email account credentials or your email account data to any hosted services we run."
MacBook on a wooden desk by a window showing a native Mac email app with a sidebar, message list and reading pane, next to a coffee cup and a plant, illustrating Mimestream read receipts and email tracking

Does Mimestream Have Read Receipts?

No, Mimestream has no read receipts in either direction and no open tracking for its own users. We checked four places on October 5, 2026:

  • Help center: the Mimestream user guide lists more than 50 articles, from Aliases to Writing Tools. None covers read receipts, read statuses or open tracking.
  • Release notes: the only match for "receipt" in the full release history, which runs from version 0.3.0 in January 2020 to 1.10.8 on September 4, 2026, is a bug fix for "Slow receipt of new email."
  • Roadmap: no feature card on the public roadmap mentions read receipts.
  • The app: the text strings in the 1.10.8 binary contain no Disposition-Notification-To, the header a client adds to ask for a receipt.

Standard read receipts follow RFC 8098, which says "it is strongly recommended that the user agent obtain the user's consent before sending an MDN." Mimestream sidesteps the question by not sending any. That puts it apart from Gmail clients that sell read tracking. Superhuman's read status and Spark's Read Statuses both rely on hidden pixels, as we found in is Superhuman tracking your email and Spark Mail read receipts. Gmail itself offers receipts only on work and school accounts, as covered in how Gmail read receipts work.

Does Mimestream Block Tracking Pixels?

Yes, Mimestream blocks known tracking pixels, and it says plainly that the blocker can miss some. Its viewing settings page has a Privacy section with two switches under Mimestream, Settings, Viewing:

  • Prevent remote images from loading automatically "blocks remote images from loading automatically in the viewing pane. You can click Load Images button to load them manually."
  • Prevent tracking when viewing messages "blocks common trackers that may notify the sender when you view their message."

The caveat: "Tracking blocker is on a best-effort basis, but is not a guarantee that all trackers will be blocked. If you wish to have a full guarantee, choose 'Prevent remote images from loading automatically' and manually load images for messages where you're willing to risk a tracking image being loaded." The page doesn't say which switches a new install starts with.

The release notes show six years of steady work:

  • 0.3.0, January 23, 2020: "Add preference to control remote image loading."
  • 0.6.6, June 29, 2020: "Prevent tracking when viewing messages" ships.
  • 0.30.5, November 14, 2021: fixed a leak where, "With remote image loading disabled, replying still loads the images in the compose window."
  • 1.3.8, August 12, 2024: "Updated list of blocked trackers."
  • 1.10.0, May 27, 2026: "Tracking prevention improved to pass all emailprivacytester.com tests." The 1.10 announcement, posted July 14, 2026, says it "Blocks additional techniques senders use to learn when and how you read a message."

Email Privacy Tester, run by Mike Cardwell, sends test emails "specially crafted to use a variety of techniques, to attempt to send information back to this server when read." The site calls any test that fires before you load remote images a "privacy bug." After you press Load Images, a pixel the blocklist doesn't know will fire.

One request is still open. A roadmap card titled "Option to always load images for a sender," created July 9, 2023 and carrying 59 votes, notes that "it can be tiresome to repeatedly load images." No release note mentions it shipping, so blocking images remains all or nothing.

How Does Mimestream's Tracker Blocker Work Under the Hood?

Mimestream hands a list of tracker URL patterns to WebKit, Apple's browser engine, which refuses to load any matching image. We downloaded the 1.10.8 disk image named in Mimestream's update feed on October 5, 2026 and read its files without running the app. A comment in the bundled ThreadContentView.js file spells out the design:

// Trackers are actually blocked by WebKit's WKContentRuleList, set up in
// WKUserContentController.add(WKContentRuleList). This scan is simply to find
// images that match the blocker patterns, so that the blocked tracker icon can
// be displayed.

Apple's WKContentRuleList documentation calls it "A compiled list of rules to apply to web content" and says these lists "use the same syntax as content blocker extensions in Safari." With a block rule, WebKit stops the matching image from loading. When the scan finds a match, the message header shows an icon whose tooltip reads "This message contains trackers that were prevented from loading."

We pulled 78 distinct patterns from the main binary, next to the WebKit rule keys url-filter and block. A sample:

  • Newsletter platforms: list-manage\.com/track (Mailchimp), mjt\.lu/oo (Mailjet), pstmrk\.it/open (Postmark), openrate\.aweber\.com.
  • Sales tools: t\.hubspotemail, t\.yesware\.com, mailtrack\.io/trace, track\.mixmax\.com, mailfoogae\.appspot\.com (Streak).
  • Other email apps: r\.superhuman\.com, t\.shortwave\.com/v1/(.*)\.gif, receipts\.canarymail\.io/track/(.*).png, getmailspring\.com/open, share\.polymail\.io/v.

Mimestream competes for the same Mac and Gmail power users as Superhuman, Shortwave, Canary and Mailspring, and it blocks pixels served from their domains. Superhuman offers senders a read status, and our Shortwave read receipts investigation found Shortwave offers Read Statuses on every paid plan while blocking spy trackers for its own readers. Canary does the same, and turns read receipts on by default, as our Canary Mail read receipts investigation found. Mailspring is a harder case: our Mailspring read receipts investigation found it moved its pixel to a new /o/ path in February 2026 so that older blocklist patterns miss it.

The same script carries a second check behind a setting named enablePossibleTrackerDetection. It flags any image whose width or height is set to 0 or 1 pixel and shows the text "Possible trackers were detected in this message." We couldn't tell from the files whether that setting is on for regular users. The list itself is compiled into the app, so it changes only when you install an update.

Does Gmail's Image Proxy Protect You in Mimestream?

We found nothing showing that it does. Google's image proxy admin page says "When your users open email messages, Gmail uses Google's secure proxy servers to serve images," and its image help page promises "Senders can't use image loading to get information about your computer or location." Mimestream doesn't read mail through Gmail's website. Its security and privacy overview says it makes "direct connections from the user's device to Google APIs," and shows log lines for a messages.get call with format: "full".

Google's Gmail API reference describes the message it returns as "The entire email message in an RFC 2822 formatted and base64url encoded string," and its parsed payload as "The parsed email structure in the message parts." The page never mentions proxying or rewriting images. In the 1.10.8 binary, the only googleusercontent.com string is Mimestream's own Google sign in client ID.

We didn't capture network traffic, so treat this as unconfirmed. But if WebKit fetches a remote image straight from the sender's server, the sender's log gets your IP address, your approximate location from that IP, and the exact second you opened. Even Google's proxy still reports the open, as explained in the tracking pixel that learned to dodge Gmail.

Does Mimestream Itself Track You?

We found no sign that Mimestream collects your mail, though it does run a few servers of its own. The Mimestream privacy policy, last updated September 21, 2026, says "All sensitive Google user data received from Google APIs is encrypted in transit using TLS, and is only stored locally on your own device." What does reach Mimestream:

  • Licensing: the app sends "the App version, operating system version, device identifier, and device name," plus each account's email address and an OIDC identity token, which "does not allow access to the account's content." The security overview adds that activation sends "Hashes of Account Email Addresses."
  • Private Push: new mail alerts, on by default on macOS 26 and later since version 1.10. Per the Private Push overview, the service stores your email address, an Apple push token and a device identifier, and "does not have OAuth access tokens" for your account.
  • Diagnostics: "Logs are stored on device, and not automatically sent to Mimestream." The software update check is listed with "Data Shared: None."

The subprocessor list names eight vendors: Amazon Web Services, Render, Cloudflare, Google, Missive, ProductBoard, SurveyKing and Paddle. None is an analytics company.

Our DNS checks on October 5, 2026, using the 1.1.1.1 resolver, found no tracking host:

  • Control: a nonsense subdomain of mimestream.com returned NXDOMAIN, so the zone has no wildcard and a miss means the name doesn't exist.
  • Misses: track, click, pixel, open, email, news, newsletter, list, t, e, go and api all returned NXDOMAIN.
  • Hits: accounts, push and links point to Render; download and cdn to Amazon CloudFront; mail to Google. The root of links.mimestream.com redirects to Mimestream's deep links help page, which says "links.mimestream.com does not have access to your account or your message's content."
  • Mail: MX records point to Google Workspace, and the SPF record includes only _spf.google.com and amazonses.com, which fits the policy's note that AWS sends the mailing list.

We never received a Mimestream newsletter, so we can't say whether it carries a pixel.

Mimestream vs Gmail, Fastmail, Superhuman and Spark

Mimestream is the only one of the five that offers no read tracking at all and blocks named trackers, but it gives up the IP masking Gmail's website and Fastmail document. Rows for the others come from our Fastmail read receipts investigation and the Superhuman and Spark pieces linked above. Spark's Read Statuses page says "Spark blocks 1x1 tracking pixels by default."

Client Read tracking for senders Incoming pixels Hides your IP when images load
Mimestream None 78 known patterns blocked; can block all images Not documented
Gmail web Receipts on work accounts only Proxied; senders "may know" you opened Yes
Fastmail Requests only; never answers No tracker list; can block all images Yes, proxy fetches at open
Superhuman Read status pixel Not covered here Not covered here
Spark Read Statuses on the Pro plan Blocks 1x1 pixels by default Not covered here

What This Means for Your Gmail Inbox

Mimestream is a window onto the same Gmail account, so its protection covers only what you open in Mimestream. Its FAQ says "Your email remains on the Gmail servers," and it says "Mimestream currently requires macOS 12 or newer" and "We do not have an iOS version, but we are actively working on it." Open that newsletter in Gmail on your phone or at mail.google.com and Mimestream's blocklist does nothing. Google's proxy loads the pixel, and the sender logs the open.

The trade runs both ways. On your Mac, Mimestream's 78 patterns stop known trackers that Gmail's proxy would let report an open. For a pixel it doesn't know, Gmail's website hides your IP address, and Mimestream documents nothing that does the same.

How Do You Block Email Tracking in Mimestream and Gmail?

Turn on both privacy switches, then cover the places Mimestream can't reach. Per the viewing settings page:

  1. Turn on Prevent remote images from loading automatically under Mimestream, Settings, Viewing. This is Mimestream's own "full guarantee."
  2. Keep Prevent tracking when viewing messages on, so known pixels stay blocked even after you click Load Images.
  3. Load images only for senders you trust. An unknown pixel that loads can reach the sender straight from your Mac.
  4. Install updates. The tracker list ships inside the app, so an old version carries an old list.
  5. Check links before you click. Mimestream shows each link's destination in a status bar but documents no tracking link cleaning.

For the Gmail you read in a browser, these are the extension options, checked October 5, 2026. None of them works inside Mimestream, a native app:

  • Trocker (10,000 users, version 3.4.1, updated July 10, 2026) "keeps you safe in all webmails by blocking known trackers in the background," with extra features in Gmail, Yahoo and Outlook.com.
  • PixelBlock (40,000 users, version 2025.12.01, updated December 2, 2025) is "a Gmail extension that blocks people from tracking when you open their emails."
  • Ugly Email no longer turns up in a Chrome Web Store search. Its Firefox add on remains, last updated March 6, 2024, with 2,069 average daily users.
  • Gblock works in Gmail on desktop Chrome. Its blocklist updates from Gblock's servers without a new release, it flags unknown images of 150 bytes or less, and it strips tracking parameters such as utm_source from links.

To be plain: Gblock does nothing inside Mimestream. If Mimestream is the only place you read mail, its two switches cover most of the risk. Gblock fits the times you open the same inbox at mail.google.com. More in how to block email tracking in Gmail, our roundup of email tracker Chrome extensions, and blocking click tracking in Gmail.

What We Could Not Verify

We did not run Mimestream or send it tracked mail. That leaves three open questions: whether loaded images go straight from your Mac to the sender, which privacy switches a fresh install starts with, and whether possible tracker detection is on by default. Our count of 78 patterns comes from text strings extracted from the binary, so it could miss rules stored in another form.

Stop Email Tracking in Gmail

Mimestream blocks known tracking pixels, but only inside its Mac app, and Gmail on the web or your phone still lets them report your opens. Gblock blocks known spy pixels in Gmail on desktop Chrome, updates its blocklist automatically and strips tracking parameters from links, so the trackers it knows stop reporting your Gmail opens.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.