Sep 21, 2026 · 11 min read
Is Slack Tracking Your Email? How to Block It
Slack sends your notification digests through Amazon SES, and we found no branded pixel host anywhere in its DNS or its certificate history. The tracking that does reach your inbox as slack.com comes from two other companies entirely.
Most articles in this series end with a hostname and a 43 byte GIF. This one does not. We went looking for Slack email tracking on 21 September 2026 and found a negative result on Slack's own notification mail, a DNS trap that would have manufactured a false positive, and two other senders that reach your inbox wearing a slack.com return address while doing what Slack does not appear to do.
Key Takeaways
- Slack's notification mail goes out through Amazon SES: every IP in the
_spfextra.slack.comSPF record reverse resolves tosmtp-out.amazonses.com. - Slack has no branded tracking domain: none of 20 candidate subdomains carries a CNAME, and none of the 9,214 slack.com hostnames in certificate transparency logs contain track, click, link, pixel or beacon.
- slack.com answers every subdomain because workspaces live there, so a hostname resolving is meaningless:
zzzznope99887.slack.comreturns the same six IPs astrack.slack.com. - Slack's Privacy Policy contains no instance of pixel, beacon or clear GIF, while its Cookie Policy discloses "single-pixel gifs and web beacons" scoped to Slack's websites, not email.
- Slack's SPF record also authorizes Qualtrics and Zendesk to send as slack.com, and Qualtrics logs a per recipient Email Opened status on survey invitations.
Does Slack Put a Tracking Pixel in Its Notification Emails?
We could not find one, and we could not find the infrastructure one would need. That is weaker than a flat no, and it is the honest answer.
Start with what Slack sends. Its guide to notifications says that "by default, you'll receive email notifications when you join a Slack workspace and haven't enabled mobile notifications," and that when you are not active in Slack those alerts are "bundled and sent once every 15 minutes or once an hour, depending on your preferences."
Read the trigger condition again. The email is only generated once Slack has concluded you are away, so whatever a pixel could report, Slack knew the more interesting half before it pressed send. Every other platform in this series uses an open pixel to learn something new. Slack would be using one to confirm something it already inferred.
Why a Resolving slack.com Subdomain Proves Nothing
slack.com runs a wildcard DNS record, so every conceivable hostname under it answers, and any investigation that treats a successful lookup as evidence will produce a fabricated tracking host.
Here is the control we ran beside every candidate name. track.slack.com, click.slack.com, links.slack.com and the nonsense string zzzznope99887.slack.com all return the identical six A records, among them 18.159.197.225, and the same v=spf1 -all TXT record. There is no difference to find.
HTTP looked more promising. Over HTTPS the three suggestive names return 403 with a 75 KB Slack application shell, while the nonsense control returns 404 and a page titled "There's been a glitch." A real difference, and a tempting one to publish.
It falls apart under one more request. Asking each host for /open produced a 302 to that same host's /messages path: https://track.slack.com/messages, and so on. That is the Slack web client route. Those are claimed workspace subdomains, the same address space as yourcompany.slack.com, and the 403 means the workspace exists but you are not signed in. Not a tracking endpoint. A locked door.
Eight plausible pixel paths, including /wf/open and /ls/click, returned 404 on all three hosts, and nothing served an image/gif. Auditing a vendor yourself? Run the nonsense control first. Our guide to detecting email tracking pixels in Gmail covers the message level version of the same discipline.
Who Actually Sends Mail as slack.com?
Three separate companies, and the SPF record names all of them. slack.com publishes v=spf1 include:_spf.qualtrics.com include:mail.zendesk.com include:_spfextra.slack.com -all: an unusually short list for a company this size, and informative because of it.
The third include settles where Slack's own mail comes from. _spfextra.slack.com lists seven IPv4 ranges and no further includes, and every address we reverse resolved lands on Amazon's mail infrastructure: 54.240.37.230 answers to a37-230.smtp-out.amazonses.com, 76.223.142.180 to c142-180.smtp-out.amazonses.com, and 23.249.223.4 to d223-4.smtp-out.us-west-2.amazonses.com. Slack sends through Amazon SES, across at least two AWS regions.
SES tracking is documented and its fingerprints are specific. AWS states that to capture open events, SES "adds a 1 pixel by 1 pixel transparent GIF image in each email sent through SES which includes a unique file name for each email", and serves it from a regional host shaped like r.us-east-1.awstrack.me unless the sender configures a custom domain. That custom domain requires, in AWS's words, "a new CNAME record to your subdomain's DNS settings that redirects requests to the SES tracking domain."
So we checked for the CNAME. Twenty candidate names under slack.com (r, track, tracking, t, click, clicks, link, links, email, e, em, mail, go, url, awstrack, ses, notifications, notify, marketing, mkt) returned no CNAME at all. Then Slack's certificate transparency history: 9,214 unique hostnames, no *.slack.com wildcard certificate to hide behind, and not one name containing track, click, link, email, pixel, beacon or awstrack. See our Amazon SES tracking explainer for what the default awstrack.me hosts do when a sender does switch tracking on.
What Does Slack Say About Pixels in Its Own Policies?
Slack discloses single pixel images and confines the disclosure to its websites. The Slack Cookie Policy answers its own question directly: "Does Slack use cookies? Yes. Slack uses cookies and similar technologies like single-pixel gifs and web beacons." It then places them on "the domains operated by Slack and its corporate affiliates," adds that "beacons, pixels, and tags help us market more effectively," and says third party cookies "are limited to our Websites and are not used in our Services."
Email is never mentioned in that document. We searched the full text: the word appears once on the page, in the site navigation.
The Slack Privacy Policy is the more interesting absence: across the whole document there is no occurrence of pixel, beacon or clear GIF. It confirms Slack does "send marketing emails and other communications" about "new product features, promotional communications or other news," and that Slack receives third party data including "how well an online marketing or email campaign performed" - campaign measurement implied somewhere in the stack, location unstated. Gumroad, by contrast, names "pixel tags (which are also known as web beacons and clear GIFs)" in "our HTML formatted emails" outright. Slack makes no such statement in either direction.
Which slack.com Emails Do Carry Tracking?
The two Slack did not build. Its SPF record authorizes Qualtrics and Zendesk to send with a slack.com return address, and both have documented open tracking behaviour that Slack's notification mail does not.
Qualtrics, for surveys. A "how are we doing" research invitation from Slack goes out on Qualtrics infrastructure, and Qualtrics distributions log a per recipient Email Opened status against your contact record. The sender sees your individual result, not a campaign percentage. We took that apart in our Qualtrics tracking breakdown.
Zendesk, for support. The include:mail.zendesk.com entry means Slack's support replies are delivered by Zendesk, and this is the benign half: Zendesk Support has no native open tracking on agent replies, while Zendesk Sell tracks every open and click. Our Zendesk tracking article separates the two.
The lesson generalises. A brand's SPF record lists everyone allowed to wear its name in your inbox, so "does this company track me" is the wrong question when three organisations share the envelope. The right one is which of them sent the message in front of you.
Slack Fetches Every Link Anyone Pastes Into It
Not email, but the same mechanism pointed the other way. Post a link in a channel and Slack's servers go and load it. The company documents the crawler at api.slack.com/robots, as Slackbot-LinkExpanding 1.0, which retrieves page metadata for the unfurl preview and fetches referenced media files too. Responses cache globally for roughly 30 minutes.
Paste a tracked marketing link into a channel and Slack's fetch registers a hit on the sender's analytics before a colleague clicks it. Paste a one time link from a password reset and the unfurl may consume it. The request leaks Slack's data centre address rather than yours, but the event still fires, which is worth knowing before you forward a suspicious email into a security channel.
How to Block Slack Email Tracking in Gmail
Our finding is a negative one, so treat these as checks you can run yourself rather than instructions to take on faith. Blocking Slack email tracking is, in practice, blocking every sender at once: the thing you switch off is the same remote image load in all of them.
- Read the raw message. Open a Slack notification in Gmail, click the three dot menu beside Reply, choose Show original, and search the source for
awstrack.me,<imgandheight="1". Do not stop at width one: iContact's pixel turned out to be two by two. - Check the return path, not the display name. The same view shows whether the message came via amazonses.com, Qualtrics or Zendesk. Three answers, three tracking stories.
- Turn off automatic image loading. In Gmail, Settings, General, select "Ask before displaying external images." Free and total, and it breaks every legitimate image too.
- Know what Gmail's proxy does not do. Google routes remote images through its own servers, hiding your IP address and rough location from the sender. It does not stop the request: the open is still recorded, with Google's address attached, as documented in Gmail's own image settings help.
- Install a blocker for the general case. An extension stops the pixel request outright while leaving the images you wanted alone, which is the difference from step 3.
One footnote. Apple's Mail Privacy Protection preloads remote content whether or not a person read anything, degrading open data without deleting the record. Full walkthrough in how to block email tracking in Gmail.
How Do the Blocking Options Compare?
Honestly, weaknesses included.
- Ugly Email. Open source, marks detected trackers with an eye icon before you open anything. The visible warning is its best feature; its hand curated blocklist is slower to pick up new hosts.
- PixelBlock. Blocks pixel loads in Gmail and flags caught messages with a red eye. Stops the open, leaves rewritten click tracking links untouched.
- Trocker. Marks pixels, warns before a tracked link resolves, and supports several webmail clients beyond Gmail.
- Proton Mail and HEY. Both block remote images and strip spy pixels by default, and both do it well. Identical price: you move your mail off Gmail.
- Gblock. Stays inside Gmail, blocks the pixel, and strips tracking redirects out of links so a click is not reported on the way through. The blocklist updates automatically, which matters against rotating vendor hosts, and
awstrack.meis already on it.
No extension protects a page you then load in your browser, and none stop Slack knowing you were away, which it reads from your client connection and not your inbox. We ranked the tools pointed the other way in email tracker Chrome extensions.
What This Means for Your Inbox
A clean result is worth more than another confirmed pixel, because it shows the method works. Fifty odd platforms in, the probes that found branded hosts on Gumroad and Qualtrics found nothing on Slack. The test discriminates, so when it says no, that is information.
It also shows how easily the audit goes wrong. Query track.slack.com, watch it resolve, note a 403 where a random string gives 404, publish, and you have invented a host that does not exist. One nonsense subdomain separated that story from this one.
None of it changes what you should do with your inbox. Slack is one sender among hundreds, and the ones beside it, two of them mailing as slack.com, do track. Because the pixel arrives with the ordinary remote images in HTML mail, blocking it at the Gmail layer covers every sender in one move, and costs you nothing when a sender like Slack turns out to be clean.
What We Could Not Verify
We did not dissect a live Slack notification email, so we cannot state from a message body that Slack's digests contain no pixel. What we can state is that Slack operates no branded tracking domain, so if SES event publishing were switched on for open events, the pixel would load from an awstrack.me regional host, not from anything wearing Slack's name. Step 1 above tests that prediction on your own mail in a minute.
We could not verify a tracking pixel hostname for Slack, and we will not name one we did not find. Nor could we confirm whether Slack's marketing mail behaves differently from workspace notification mail: both must travel through the same three authorized senders under a -all policy, but shared infrastructure is not shared configuration, and Slack says nothing either way. email.slack.com, the one plausible sending subdomain, resolves to EC2 instances and answers HTTPS with a 301 to an error page on slackhq.com.
Slack Connect and workspace invitations were equally beyond outside inspection. Same SES ranges, same prediction, unproven.