Sep 15, 2026 · 9 min read
Is MoEngage Tracking Your Email? How to Block It
MoEngage names its own tracking host in its documentation, which is more than most platforms manage. Then we looked that host up and found it on the same servers as the API its mobile SDKs talk to.
MoEngage email tracking does not arrive from a domain built to look innocent. It comes from email-10.moengage.com or api-0X.moengage.com, hosts the company names in its own help pages. That candour stops being useful the moment a brand points its own subdomain at the same infrastructure, which MoEngage recommends.
Key Takeaways
- MoEngage's link branding documentation names
email-10.moengage.comas the default email domain for its DC-01 data centre andapi-0X.moengage.comfor the rest. email-10.moengage.comandapi-01.moengage.comresolved, in our own lookups, to the identical four IP addresses under a certificate issued to MoEngage Inc.- MoEngage's open tracking consent toggle is off by default, and its own table shows that when it is Disabled the pixel is Included and the consent link is Not included, in every country.
- The platform records browser, device type, operating system and email client per recipient, and inspects the user agent behind each open.
- France's CNIL published deliberation 2026-042 on 14 April 2026, requiring prior consent for email open pixels under Article 82 of the French Data Protection Act.
What Is MoEngage, and Who Sends You MoEngage Email?
MoEngage is a cross channel engagement platform that sends email, push notifications, SMS and WhatsApp for consumer brands. You never sign up for MoEngage. A company you deal with does, and MoEngage becomes the machinery behind the message.
Its reach outruns its name. TechCrunch reported in November 2025 that MoEngage raised $100 million led by Goldman Sachs Alternatives and serves over 1,350 consumer brands across 75 countries, among them SoundCloud, McAfee, Kayak, Deutsche Telekom, Flipkart and Citibank. About 25 percent of revenue comes from Europe and the Middle East, the region that just rewrote the rules on open pixels.
Does MoEngage Track Email Opens, and How?
Yes, and MoEngage describes the mechanism plainly. Its page on the consent attribute and open tracking pixel states that "an email open tracking pixel is a single-pixel, transparent image embedded in the email body. When a recipient opens the email, their mail client loads this image in the background, which reports the open back to the sender."
Clicks work by rewriting instead. MoEngage's own example: under a branded domain of yourbrand.com, a link to www.xyz.com/products/mobiles arrives as www.yourbrand.com/abc. Your destination is not in the link you hover; it resolves on a MoEngage server after the click is logged. We could not retrieve a live campaign pixel, so we name no URL path or parameter here.
Which Domains Should You Look For in the Message Source?
Start with moengage.com, read from the raw source, not the rendered email. In Gmail, click the three dot menu on the message itself and choose Show original. MoEngage documents the default email domain as email-10.moengage.com for DC-01 and api-0X.moengage.com elsewhere, with branded domains pointing at api-0x.moengage.com or, under managed SSL, <workspace>.bapi-0x.moengage.com.
The digit is geography. MoEngage's data centres page puts DC-02 in the EU, DC-03 in India, DC-05 in Singapore and DC-01 in the US, which our DNS lookups confirm through the AWS balancers behind them. The number in a wrapped link tells you which continent logged your click.
Then the finding no vendor page mentions. email-10.moengage.com and api-01.moengage.com resolved to the identical four IP addresses, both returning HTTP 404 with the body "Path doesn't exists," under a certificate naming MoEngage Inc. The email tracking endpoint and the mobile SDK endpoint are one fleet wearing two names. Our method for spotting tracking pixels in a Gmail message source applies, with one caveat: custom link branding shows you links.thatbrand.com, so finding no "moengage" string is not proof you were not tracked.
What Does the Marketer Actually See About You?
More than an open count, less than the worst case some guides imply. MoEngage's email analytics documentation describes an Email Clicked event populated with device analysis, and reporting broken down by browser, device type, operating system and email client: phone or laptop or smart TV, whether your mail sits at Gmail, Outlook, Yahoo or Apple, whether you came back for a second look, which links you followed.
All of it lands on your profile, feeding segmentation and the AI decisioning layer TechCrunch describes as choosing "which customers should receive a particular message or offer, on which channel, and at what time."
We found no documented IP address or geolocation field on the open event, so we will not claim one. The user agent is inspected, though: the Mail Privacy Protection page says MoEngage "identifies machine opens" by "analyzing the user agent from which a particular open was triggered." The field list rhymes closely with Braze's email tracking setup.
Can You Opt Out of MoEngage Open Tracking Without Unsubscribing?
Sometimes, and this is the most interesting thing about the platform. Unlike most of its category, MoEngage ships a real recipient facing opt out: a consent link in the footer, separate from unsubscribe, leading to a hosted page. Recipients who use it, the documentation says, "continue to receive your emails as normal; they just won't be tracked for opens."
Now the conditions. That link appears only if the marketer switched the consent toggle on, and only for recipients whose country the marketer put on a Regulated Countries list. MoEngage's own table is blunt about the default: toggle Disabled gives "Tracking Pixel: Included, Consent Link: Not included," regardless of country.
Read the second limit carefully. If your consent changes to opted out after an email was sent, MoEngage "stops attributing opens to that recipient going forward," even "if the tracking pixel was already included in that email." The pixel in your mailbox still loads and still reaches the server; MoEngage declines to credit the open. Withdrawing consent is a bookkeeping instruction to the platform, not a brake on your mail client, which is the whole argument for blocking email tracking inside Gmail.
Why Are Regulators Treating the Open Pixel as a Consent Problem?
Because two European authorities decided within five days of each other that an open pixel accesses your device rather than measuring a campaign. The CNIL published its recommendation on tracking pixels in email on 14 April 2026, as deliberation 2026-042, qualifying pixels under Article 82 of the French Data Protection Act and requiring prior consent.
Italy's Garante followed on 17 April 2026. Its press release on the tracking pixel guidelines places pixels under Article 122 of the Privacy Code, requires "prior, free, specific and informed consent" and demands selective withdrawal, with six months from publication in the Official Gazette. Our breakdown of what Provision No. 284 requires works through the text clause by clause. Read MoEngage's consent feature against those two documents and it looks less like generosity than product management: the toggle, the country list and the granular withdrawal map almost line for line onto what the regulators asked for.
American exposure has worse arithmetic. Plaintiffs argue an unconsented email pixel is an interception under California's Invasion of Privacy Act, and California Penal Code section 637.2 sets damages at "five thousand dollars ($5,000) per violation" or treble actual damages. Per violation, in a channel measured in millions of sends, is the whole risk sentence. We tracked the filings in the 2026 CIPA email pixel wave.
What This Means for Your Inbox
None of those settings belong to you. The toggle is the marketer's, the country list is the marketer's, and whether a consent link sits in your footer was decided in a dashboard you have never seen. Gmail's image proxy softens the disclosure without cancelling it: your raw IP address stays hidden, the open still registers with a timestamp.
Consider what one open reports to a system already holding your profile. Not that you read something, but that you read it at 07:12 on a phone running iOS through Gmail, then again at lunchtime on a laptop. Repeat across a year of mail from a bank, an airline and a delivery app on the same platform, and the shape of your day becomes legible to software deciding when to message you next. Nobody has to behave badly for that; it is the intended function of a product 1,350 brands pay for.
How Do You Block MoEngage Email Tracking in Gmail?
An open is recorded only if your client fetches the image, a click only if you travel through the redirect. Three actions, ordered by cost.
- Stop images loading automatically. In Gmail open Settings, See all settings, and under Images pick "Ask before displaying external images". The pixel never fires. Real images break too, and click tracking is untouched.
- Use the consent link when a sender gives you one. Look in the footer for a tracking preference link distinct from unsubscribe. Where it exists it works and keeps your subscription intact. It will not be in most messages.
- Install a blocker that filters by host. The only approach that leaves ordinary images working while refusing the tracking request, and the only one covering pixel and link together.
MoEngage Blockers Compared
No tool catches everything. Where each lands against MoEngage:
- Apple Mail Privacy Protection. Preloads images through Apple's servers. MoEngage answered with adjusted open metrics that filter machine opens by user agent, so this countermeasure is already countered.
- Ugly Email. Flags tracked messages with an eye icon before you open them. A warning light, not a brake.
- PixelBlock. Blocks open pixels and tells you it did, but leaves rewritten links alone.
- Trocker. Works across several webmail providers and shows where the pixel sits.
- Proton Mail and HEY. Block trackers by default at the provider level, genuinely strong, but you have to move your email.
Gblock sits in the extension category, and its differences are specific rather than sweeping: it runs inside Gmail so you keep your address, its blocklist updates itself against an estate spanning six data centres, and it strips tracking links as well as pixels, the half MoEngage's redirects need. Our roundup of email tracker blocker extensions sets out the trade offs. The shared limit bites harder here, because MoEngage recommends custom link branding: point a brand subdomain at api-0x.moengage.com and the same pixel arrives from a hostname no blocklist has seen. A very good filter, not a wall.
The Practical Bottom Line
Most coverage of a platform like this reaches for outrage about volume. The more revealing fact is that MoEngage built the opt out, documented it well, and shipped it switched off. A privacy control that activates only where a regulator forced the question is a compliance feature, not a promise. And the host logging your open is the same four addresses as the host serving the mobile SDK, because inside the platform an open is just an event, the shape of a tap in an app, joining the same profile. Which leaves one place the decision is yours, the same place we reached in our wider guide to blocking email tracking in Gmail: your own mail client, in the instant before the request leaves your machine.