Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 04, 2026 · 10 min read

Is SignNow Tracking Your Email? What Its Log Sees

The sender can switch on an alert for the moment you view the document, and the IP address you viewed it from lands on a history page printed into the finished PDF. One of those two things is worth defending against. The other you cannot touch.

An offer letter arrives, you open it on your phone during dinner, and the next morning the recruiter opens with "glad you had a chance to look at it." SignNow tracking is what happened in between, and it is more durable than the beacon in a newsletter. airSlate SignNow's security page states it plainly: the platform "creates and maintains a detailed document history, which shows all document activities and who performed them, including full names, email and IP addresses, and time stamps." The question worth asking is not whether that log exists. It is which half of it a blocker can reach.

Key Takeaways

  • SignNow's History log records "every modification and interaction with a document, including timestamps, actor identity, IP address, and the specific change made," per its audit history documentation.
  • SignNow's audit trail page lists view alongside upload and sign as a recorded action type, so opening the document is itself a logged event.
  • Choosing Download with History produces a PDF containing the signed document plus the log, so your IP address travels to every party who later receives the contract.
  • Senders can configure email alerts on Viewed, not only on completion, which is why the follow up arrives before you have replied.
  • SignNow's help centre notes that its compliance certifications "apply only to SignNow Corporate customers," a caveat almost no coverage of the platform mentions.

Does SignNow Know When You Open a Document?

Yes, and it can tell the sender within seconds. The event fires when you load the document on SignNow's servers, not when the email lands in your inbox, and that distinction decides everything that follows.

SignNow's notification settings documentation lets a sender pick which events raise an alert, naming "document sent, viewed, signed, declined, or completed." Viewed sits in that list as a first class trigger. Turn it on and a recruiter, a landlord or a counterparty gets a push notification the moment the document renders on your screen. The completion notification feature adds the same immediacy at the other end of the workflow, routing events to email, in app banners, mobile push or a webhook into someone's CRM.

Here is the part that gets reported backwards. Because the view event is generated by SignNow's own servers while it renders the document you asked for, it is not a pixel and blocking images does nothing to it. Two of the three major platforms in this category work the same way. Adobe is the outlier: Adobe Acrobat Sign documents an actual tracking pixel in its notification mail, where an image blocker genuinely earns its keep. DocuSign puts the event on its servers instead, and so does SignNow.

What Exactly Does the SignNow Audit Trail Record?

A per action chain of custody with your network address attached to each entry. SignNow uses two names for it, and the difference matters more than the vocabulary suggests.

History is the live view inside the sender's account. Open the More menu on a document, choose History, and the entries appear in columns. SignNow's history audit page describes the log as capturing "every modification and interaction with a document, including timestamps, actor identity, IP address, and the specific change made," across "uploads, edits, field changes, signature events, and exports." The columns include:

  • Client, recording whether the action happened in the web app or the mobile app.
  • Event, the action type. SignNow's audit trail page lists action records as "Upload, view, sign."
  • By, the email address of the person who performed it.
  • Server Time and Client Time, two clocks rather than one, which quietly reveals your device's local time and therefore your rough time zone.
  • IP address, described on the audit trail page as "Origin network address," alongside the authentication method used and a version snapshot ID.

Audit Trail is that same log made portable. Choosing Download with History generates a file where, in SignNow's own words on its document history download page, the log arrives "in the same file as the document itself" and contains the "user's name, action taken (called Event in the log), user's email, time of the action, and even their IP address." The detail sits on the last page.

A stack of signed paper contracts on a wooden desk with the last page turned face up and a pen resting across it in soft window light

Who Else Sees Your IP Address?

Everyone who is ever sent the finished contract. That is the whole SignNow story in one sentence, and it is the part the comparison articles skip.

Think about how a marketing beacon ends its life. It writes a row into a database inside one company, that company's analytics team looks at aggregate open rates, and nobody ever reads your individual line. The record is invisible and effectively inert. A SignNow audit trail does the opposite: it becomes the last page of a PDF that gets emailed to the counterparty, forwarded to their lawyer, filed with a broker and attached to a data room, then kept for as long as the agreement is enforceable. The distribution list for your network address is decided by people you will never meet, years after you signed.

Scale that up. SignNow's own marketing claims 28 million users across the platform. If even a small fraction of those signings produce a downloaded history page, the number of PDFs circulating with a private IP address printed on them runs into the tens of millions. And an IP address is not nothing: paired with a timestamp it resolves to a city, an internet provider and, if anyone ever subpoenas the provider, a household. European law has taken that seriously since the Court of Justice held in Breyer (C-582/14) that a dynamic IP address can be personal data in the hands of someone with lawful means to identify the subscriber behind it.

Does the Invitation Email Itself Track You?

We could not verify a dedicated open pixel in SignNow's invitation mail, and we are not going to claim one exists. What we can say is what the email layer generally exposes, regardless of vendor.

Any remote image an invitation loads, including a sender's branded logo, hands the hosting server your IP address and user agent the instant your client fetches it. Any link that routes through a redirect before reaching the document records the click. SignNow supports custom sending domains and templated invitation mail with merge fields, so what actually arrives in your inbox depends heavily on how the sending company configured it. We have not been able to confirm a specific rewritten tracking host for standard SignNow invitations, so treat any article that names one without evidence with suspicion.

The bigger email risk is upstream of SignNow entirely. Signing links rarely arrive naked. A recruiter pastes one into an ATS sequence, a sales rep drops it into an outreach tool, a finance team sends it from a marketing platform, and those wrappers carry the ordinary open pixel and rewritten URL machinery. That layer is fully blockable, and it is where a Gmail blocker does real work.

What Can You Actually Block?

The email layer, completely. The document layer, not at all. Any tool that promises otherwise is selling you a feeling, and that includes ours.

  • Blockable: open pixels and remote images in the invitation, reminder and completion mail; redirect links wrapped around the signing URL by whatever tool the sender used; the location and read time those two things leak before you click anything.
  • Not blockable: the view event SignNow writes when it renders the document, because that is the same code path that shows you the document; the IP address recorded against that event; the history page bound into the final PDF.
  • Partly mitigable: a VPN changes which IP address gets written, it does not remove the field. Opening the document from your SignNow account rather than the emailed link defeats link tracking and changes nothing in the audit trail. Asking for a plain PDF to review generates no view event at all, which is the only genuinely effective move and the one nobody makes.

For the layer you can control, four extensions cover the ground. Read the rightmost column carefully.

Tool Strength Weakness Tracked links SignNow audit trail
Ugly Email Free; marks a tracked message with an eye icon before you open it Detection first rather than blocking first No No
PixelBlock Free, zero configuration, blocks open pixels in Gmail Intermittent updates; rewritten click URLs pass straight through No No
Trocker Open source, works beyond Gmail, shows where the pixel sits Heuristic coverage maintained by volunteers Marks them No
Gblock Auto updating blocklist, strips tracking links as well as pixels, stays inside Gmail Gmail and Chromium browsers only; paid after the trial Yes No

Nobody blocks the audit trail, because it is not the kind of thing an extension can reach. Our longer Ugly Email vs PixelBlock vs Trocker comparison digs into maintenance and detection rates, and the wider roundup of tracker blocker extensions covers the options that involve moving your mail somewhere else entirely.

What Do GDPR and eIDAS Say About a Signing Audit Trail?

They treat the marketing beacon and the signature record as two different legal objects, and a compliance team that conflates them will reach the wrong conclusion on both.

In October 2024 the European Data Protection Board adopted Guidelines 2/2023 on the technical scope of Article 5(3) ePrivacy Directive, pulling tracking pixels, tracking links and certain forms of IP tracking inside the consent rule most people still call the cookie rule. Embedding a beacon in an email body and reading what comes back counts as storage and access on terminal equipment. For marketing mail that means consent, and a soft opt in for the message does not silently extend to measuring the open.

A signing audit trail sits somewhere else entirely. It is not something planted on your device; it is a record of a transaction you initiated on someone else's server, retained because contract law requires it to be evidential. The EU's eIDAS Regulation (910/2014) grades electronic signatures by how strongly the signatory is identified, and the US ESIGN Act of 2000 requires an electronic record to be attributable and accurately retained. Timestamps, authentication method and IP address exist to clear those bars, so the lawful basis is normally contract performance rather than consent.

Two practical notes for anyone filing a subject access request. First, for the analytics wrapped around a signing link, the controller is almost always the company that sent the invitation, not SignNow, which is acting as a processor. Second, a caveat worth reading twice: SignNow's security and compliance help centre article lists SOC 2 Type II, HIPAA, 21 CFR Part 11, PCI DSS, GDPR, CCPA and eIDAS, then states these "apply only to SignNow Corporate customers." If you are signing something sensitive and the sender is on a cheaper tier, the assurances you looked up may not be the assurances covering your document.

What This Means for Your Inbox

Most advice about email tracking assumes the stakes are commercial: a marketer learns your open rate, you get a better timed newsletter. Signing mail breaks that assumption. When the party measuring your attention is also the party negotiating with you, hesitation becomes information, and information becomes leverage.

The split is worth internalising because it tells you where to spend effort. Everything before your click is ordinary email tracking: remote images, redirect links, open receipts, read times, approximate location. That layer is blockable, it carries most of the volume, and shutting it down costs you nothing. Everything after your click is a server side record you triggered by asking to see a document, and no extension will ever touch it. It is the same division we found in what DocuSign writes onto its certificate of completion: a blockable email layer wrapped around an unblockable document layer.

What is left after you block properly is one line on a history page: the fact that you looked, when, and from where. Whether that feels acceptable depends entirely on what you were signing and who ends up holding the file. Just make the decision knowingly, because the last page of that PDF is going to outlive the conversation that produced it.

Stop Email Tracking in Gmail

Block SignNow and 1,000+ other email trackers in Gmail

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.