Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 01, 2026 · 13 min read

Proton Mail Read Receipts: Does Proton Track Your Email?

Proton Mail offers only the permission based read receipt, and it has blocked spy pixels by default since January 2022. Here is what that protection misses, what Proton itself can see, and what to do if part of your mail still lives in Gmail.

Proton Mail read receipts exist, but they are the polite kind. A Proton user can ask you to confirm that you read a message, and a Proton user who receives that request sees a button they are free to ignore. Nothing goes out automatically. The sharper question is what happens on the receiving end. Proton blocks tracking pixels by default, and it goes a step beyond hiding your IP address: it fetches images when a message is delivered, before you open it. We read Proton's support pages, its policies and the open source code of its web app. The protection is strong. It also has gaps the marketing leaves out.

Key Takeaways

  • Proton Mail read receipts are manual: Proton's help page says that if a recipient ignores the request "no read receipt will be sent," and no setting sends one automatically.
  • Proton Mail has blocked known tracking pixels by default since January 19, 2022, and since December 2022 it has fetched remote images at delivery, so senders see a message as opened the moment it arrives.
  • Proton's tracking link cleaning, launched July 20, 2023, runs only in the web app; in our test of its open source cleaner it stripped parameters such as utm_source but left Mailchimp and SendGrid style click redirects untouched.
  • Proton's Mail privacy policy, last modified September 14, 2026, says the company can see sender and recipient addresses, subject lines, attachment names, the sending IP address and message times.
  • Proton's transparency report lists 9,301 legal orders for Proton Mail in 2025, and Proton complied with 8,313 of them, about 89%.
Laptop on a wooden desk by a window with snowy mountains outside, showing a blurred email inbox, with a small brass padlock, a mug and an envelope beside it, illustrating Proton Mail read receipts and tracking protection

Does Proton Mail Have Read Receipts?

Yes, Proton Mail has read receipts, but only the kind that asks permission. Proton's read receipt help page documents one way to ask: in the web composer, the sender opens the three dot menu at the bottom left and picks Request read receipt.

Receiving one is just as manual: "you will see a button at the top of the email when you open it. You may accept the request or ignore it. If you ignore it, no read receipt will be sent." No setting sends receipts automatically, and the code agrees. In Proton's open source web client, requireReadReceipt in packages/shared/lib/mail/messages.ts looks for a Disposition-Notification-To header, and ExtraReadReceipt.tsx calls the receipt endpoint only from the button's click handler.

That header belongs to the Message Disposition Notification standard, and RFC 8098 says "it is strongly recommended that the user agent obtain the user's consent before sending an MDN." Proton follows it. Its rebuilt phone apps can't send a receipt at all yet: the iOS and Android pages both list "Sending read receipts" among features "not yet available in the latest version."

If a Proton user requests a receipt from your personal Gmail, nothing comes back. Google's help page says read receipts "don't work with personal Gmail (@gmail.com) accounts." Our guide to how Gmail read receipts work covers the work account exceptions.

What Happens When a Tracked Email Reaches a Proton Address?

Proton removes the tracking pixels it recognizes and fetches every other remote image itself, before you open the message. Its tracker protection page states: "We remove known email trackers whenever you receive an email that isn't end-to-end encrypted." It continues: "We also pre-load other remote images on your behalf using a proxy with a generic IP address and geolocation." Fastmail also proxies images, but it fetches them the moment you open, as our Fastmail read receipts investigation shows.

The feature arrived in two steps:

  • January 19, 2022: "enhanced tracking protection" launched on the web app, on by default, blocking known pixels and hiding IP addresses.
  • December 7, 2022: Proton began loading images "as soon as an email is delivered rather than when you open it," cached them so reopening triggers nothing, and extended the feature to iPhone and iPad.

Today the support page covers web, iOS, iPadOS and Android and says "Tracking protection is enabled by default."

So what does the sender see? A pixel on Proton's list is removed, and no request is ever made. Everything else is fetched once, at delivery, from Proton's servers. The December 2022 post spells out the result: "To marketers, all emails sent to Proton Mail addresses will always appear as though they've been opened as soon as they're delivered." That is a fake open, the side effect Apple Mail Privacy Protection also produces, and it makes open rates for Proton addresses meaningless.

On the web, a badge at the top of each message "tells you how many trackers were blocked and how many links were cleaned."

What Does Proton's Link Cleaning Actually Remove?

It removes known tracking parameters from the end of a link, and it doesn't unwrap the click redirects that email platforms rely on. The feature launched on July 20, 2023, on the web app only and on by default. Proton says it built "a blocklist of known tracking parameters using both internal and external, community-supported sources." In the web client, getUTMTrackersFromURL in packages/shared/lib/mail/trackers.ts hands each link to TidyURL.clean from @protontech/tidy-url, Proton's build of the open source tidy-url project.

We downloaded version 1.18.5, the one declared in packages/shared/package.json, and ran 17 sample links through it on October 1, 2026. Its rules file holds 232 rule sets, including 111 parameters it removes on any site.

  • Stripped: utm_source, utm_medium and utm_campaign; Mailchimp's mc_cid and mc_eid; HubSpot's _hsenc and _hsmi; Marketo's mkt_tok; fbclid and gclid. It also unwrapped a Facebook l.php redirect and a LinkSynergy affiliate link to their real destinations.
  • Left untouched: a Mailchimp style click link on list-manage.com and a SendGrid style /ls/click?upn= link. The rules file never mentions list-manage, sendgrid or klaviyo.

The reason is structural. A redirect link has no parameter to delete: the sender's click server logs your visit, then forwards you. Proton's own explainer describes this as "routing you through a tracking server on the way to your destination," and the 2023 post admits that when cleaning would break a link, "we default to leaving the link intact." Proton hides your opens far better than your clicks. Our guide to blocking click tracking in Gmail explains the redirect trick in detail.

What Does Proton's Tracking Protection Not Stop?

Beyond click redirects, it doesn't cover every app equally and it can't scan mail Proton is unable to read. Each limit below comes from Proton's own pages or code:

  • Phones get less. Link cleaning is labeled "Proton Mail for web," and the Android page lists a "Visible indicator for blocked email trackers" as not yet available.
  • The switch is per device. "This setting doesn't sync across your apps," the support page warns. Turning it off also disables link cleaning on the web, because the code passes the same ImageProxy setting to both.
  • Encrypted mail skips the delivery scan. Preloading "applies to emails that aren't end-to-end encrypted when you receive them." For the rest, the web client's transformRemote.ts requests images through the proxy only when the message is rendered: your IP address stays hidden, the timing doesn't.
  • The proxy can fail. The web app then shows "Tracker protection prevented some images from loading. Load them if you trust the sender." The tooltip on that Load button reads "Images will be loaded without a proxy." Click it and your browser fetches those images directly, IP address included.
  • Desktop clients are not listed. The page says nothing about Proton Mail Bridge, where Thunderbird or Outlook renders the message.

Does Proton Read or Track Your Email?

Proton can't read message bodies once they are stored, but it sees metadata. It also processes unencrypted incoming mail in memory before encrypting it. Its encryption explainer says "All messages in your Proton Mail inbox are stored with zero-access encryption," then adds a caveat: "Subject lines, recipient email addresses, and sender email addresses are encrypted, but not end-to-end encrypted."

The Proton Mail privacy policy, last modified September 14, 2026, lists what stays visible: "Due to limitations of the SMTP protocol, we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times."

Mail from outside Proton is also scanned on arrival. "Such inbound messages are scanned for spam in memory, and then encrypted and written to disk," the policy says. Tracker blocking rides on the same pass, since those emails "are already checked for spam, phishing, and malware when we receive them, so we've simply added tracking protection to these existing automated filters."

Yet Proton's May 2026 post announcing Gmail support claims "Proton doesn't scan your emails, serve you ads, use your data for AI training, or build profiles on your correspondence." The policy is the more precise document. Proton does run an automated scan; what it rules out is profiling: "User data is never used for advertising purposes." As for your own IP address, the main privacy policy says "By default, we do not keep permanent IP logs in relation with your Account," though logs "may be kept temporarily to combat abuse and fraud."

What Has Proton Handed Over Under Legal Orders?

The documented cases involve IP logs and payment records, never readable message bodies. Proton's transparency report counts 9,301 legal orders for Proton Mail in 2025. Proton contested 988 and complied with 8,313. That works out to roughly 25 orders a day and an 89% compliance rate, up from 26 orders in all of 2017.

  • IP logging, 2021. After French police arrested a climate activist, CEO Andy Yen wrote on September 6, 2021 that "Proton received a legally binding order from Swiss authorities," and quoted the company's threat model: "a law-abiding company such as Proton Mail can be legally compelled to log your IP address."
  • Payment data, 2026. 404 Media reported on March 5, 2026 that Proton "provided Swiss authorities with payment data that the FBI then used to determine who was allegedly behind an anonymous account." We covered it in Proton Mail gave the FBI data that unmasked a protester.

The policy's promise held both times: "Under no circumstances can Proton decrypt end-to-end encrypted content and disclose decrypted copies." For journalists and activists the lesson is narrower: tracker blocking hides your IP address from marketers, not from a Swiss court order. Jurisdiction is moving too, as we reported in Switzerland's surveillance law and Proton's relocation; the Mail policy places servers "exclusively located in Switzerland, Germany or Norway."

What Did Our DNS and Endpoint Checks Find?

We found no Proton tracking host and no outside email service in Proton's sending chain. The checks ran on October 1, 2026, using the method from our guide to detecting email tracking pixels in Gmail.

  • Mail routing: proton.me, protonmail.com and pm.me all point their MX records at mail.protonmail.ch and mailsec.protonmail.ch. Their SPF records include only _spf.protonmail.ch, with no include for an outside email service provider.
  • Tracking hostnames: track, tracking, pixel, t, open, click, links and email under both proton.me and protonmail.com returned NXDOMAIN. So did a nonsense control name, which rules out a wildcard record.
  • Image proxy: the code names the path core/v4/images. Without a login, that path on mail.proton.me answered 401 "Invalid access token," while a nonsense path beside it answered 404 "Path not found." The proxy serves signed in sessions only.

What This Means for Your Gmail Inbox

Proton's protection follows the app you read in, not the address a message was sent to. Open a newsletter in Gmail and you get Gmail's rules, where Google's image help page concedes: "Sometimes, senders may know whether you've opened an email that has an image." We explain why in the tracking pixel that learned to dodge Gmail.

Many Proton users keep a Gmail account for old logins, and Proton offers two ways to pull it in. Gmail forwarding, announced in May 2023, sends Gmail mail to your Proton inbox, and "We also remove trackers from these forwarded emails." Since May 28, 2026 you can also connect Gmail inside Proton Mail and send from that address. Proton is candid about the limit: "Google is still reading every email received by your Gmail account."

Keep reading that account in Gmail itself and none of Proton's blocking applies.

How Do You Check Proton's Settings and Block Tracking Elsewhere?

Open Email privacy in Proton's settings and confirm the defaults below, then treat links with care:

  1. Block email tracking. Web: Settings, All settings, Proton Mail, Email privacy. Android or iOS: Settings, then Privacy and security. Check every device, because the switch doesn't sync.
  2. Auto show remote images. Leave it on. Proton says "When email tracking protection is on, it's safe to automatically load remote images."
  3. Confirm link URLs. Link confirmation is "enabled by default" under Messages and composing. Read the hostname it shows; if it isn't the site you expected, open that site directly.
  4. Read receipts. Ignore the Send read receipt button unless you want the sender to know.
  5. Higher risk? Proton's 2021 post calls its onion site "highly recommended for users with heightened privacy needs," and the privacy policy notes "Anonymous cash or Bitcoin payments and donations are accepted."

Outside Proton, these are the options, checked on October 1, 2026:

Tool Where it works Pixels Links
Proton Mail Proton's web and mobile apps Known trackers removed; the rest preloaded by proxy Parameters cleaned on web; redirects kept
HEY HEY's own mail service Says it will "catch 98% of all the tracking"; images routed through its servers Not covered on its tracker page
Apple Mail Privacy Protection Apple's Mail app Hides IP address and whether you opened "does not extend to links"
PixelBlock Gmail in Chrome; 40,000 users Blocks open tracking; listing last updated December 2, 2025 Listing describes open tracking only
Trocker Webmail in Chrome; 10,000 users Blocks tracking images; version 3.4.1 from July 10, 2026 Tries to bypass click tracked links, or warns you
Ugly Email Gone: the Chrome Web Store listing its own site links to no longer loads None None
Gblock Gmail in desktop Chrome only Blocklist that updates itself; flags unknown tiny images Routed via its proxy, tracking parameters stripped

Plainly: if you read all your mail in Proton, you don't need Gblock. It does nothing inside Proton, the Gmail mobile app or a desktop client, and Proton's parameter list is longer than ours. Gblock fits two readers. One keeps a Gmail account next to Proton and reads it in Chrome. The other is weighing a provider switch only to escape tracking pixels; staying in Gmail with a blocker is less work, though no extension gives you Proton's encryption. Proton's explainer also raises a fair point: extensions "may need permission to access data on the pages you use." That applies to every Gmail extension, ours included.

Next steps: how to block email tracking in Gmail, our roundup of email tracker Chrome extensions, and the Ugly Email vs PixelBlock vs Trocker comparison. Choosing a provider? Start with the best private email providers. For another app that refuses to track, see our Missive investigation. For a provider that blocks every image but uses no proxy, see our Tuta read receipts investigation.

What We Could Not Verify

We did not send tracked test mail to a Proton account; every claim here comes from Proton's documentation and published code, plus the link cleaner we ran ourselves. Proton's server side is closed, so its list of "known email trackers" can't be inspected, and it may clean links in ways the client code doesn't show. Whether the mobile apps can request a read receipt is undocumented. Bridge is the biggest gap: a search of the proton-bridge repository for "Disposition-Notification" returned nothing, so we can't say how receipts or pixels behave when a desktop client renders Proton mail. Proton's own marketing emails went unexamined too.

Stop Email Tracking in Gmail

Proton Mail blocks tracking pixels for mail you read in Proton, but the Gmail account you kept still loads them. Gblock adds tracking protection inside Gmail on desktop Chrome: it blocks known spy pixels and strips tracking parameters from links, so staying in Gmail doesn't mean being watched.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.