Oct 04, 2026 · 12 min read
Tuta Read Receipts: Does Tuta (Tutanota) Track Your Email?
We read the open source code of Tuta Mail, the service called Tutanota until November 7, 2023. It has no read receipt feature and blocks remote images by default, but it has no image proxy and no link cleaning. Here is what that means for senders, for you, and for the Gmail account you still keep.
A Tuta read receipt doesn't exist. Tuta Mail, formerly Tutanota, never asks you to confirm that you read a message and never offers to send that confirmation. The harder question is images, the way most senders actually track opens. Tuta blocks every remote image until you decide otherwise, which is stricter than Gmail. Then one click on Show fetches those images straight from your device, with no proxy in between. We read Tuta's blog, privacy statement, transparency report and public client code. "No tracking" holds up. The catch is what happens after you click.
Key Takeaways
- Tuta's open source client, at the October 2, 2026 commit we checked, contains no code that reads, requests or sends a read receipt; the only match for "disposition-notification" is a file type table.
- Tuta blocks remote images and other external content by default and shows the banner "Automatic image loading has been blocked to protect your privacy," so a tracking pixel never fires unless you click Show.
- Tuta has no image proxy: once you click Show, or trust a sender, your own device downloads the images and the sender's server can log your IP address and the time you opened.
- Tuta does not clean tracking links; its phishing banner scores messages against reported phishing data and link text that names a different host than the real link.
- Tuta's transparency report for January to June 2026 lists 12 requests for real time content data, and Tuta released data in 6 of those cases under a German court order.
Does Tuta Have Read Receipts?
No, Tuta has no read receipts in either direction: you can't request one, and the apps never send one. Read receipts in email are Message Disposition Notifications, triggered by a Disposition-Notification-To header, and RFC 8098 leaves it to the mail program whether to honor them. Tuta's program simply ignores them.
We checked the tutao/tutanota repository at commit 63a0147, dated October 2, 2026 and versioned 361.261001.0. A search across the web client, the desktop app, the Android and iOS apps and the Rust SDK for Disposition-Notification-To, Return-Receipt-To or anything named readReceipt found a single hit: an entry mapping the message/disposition-notification file type in flat-mimes.ts. The English interface strings contain no read receipt label, button or setting.
That puts Tuta below Proton Mail, which at least offers the polite, permission based kind, as our Proton Mail read receipts investigation found. Gmail sits in the same place for personal accounts: Google's help page says read receipts "don't work with personal Gmail (@gmail.com) accounts." The real tracking tool in both inboxes is the pixel, covered in how Gmail read receipts work.
What Happens When a Tracked Email Reaches a Tuta Address?
Tuta replaces every remote image with a placeholder before the message is shown, so a tracking pixel has nothing to call home with. Tuta has done this for years: its May 20, 2019 release note already said "External images are still not being displayed by default. Instead, the user must actively click to load external images so that no accidental tracking can take place."
The net is wide. HtmlSanitizer.ts sets blockExternalContent: true as its default and swaps out any external URL found in src, srcset, poster, background and similar attributes. It also replaces CSS values containing url(, which closes the background image trick some trackers use. Only embedded images (cid: references) and inline data URLs pass through.
You then see a banner reading "Automatic image loading has been blocked to protect your privacy," with three choices:
- Show loads the images for this one message.
- Always display images for sender remembers the sender. In MailViewerViewModel.ts, that rule only takes effect when the message passes authentication, so a spoofed copy of a trusted address still arrives blocked. The button doesn't even appear on unauthenticated mail.
- Always block images for sender keeps them blocked and hides the banner.
There is no global switch to load images automatically. The sender rules live on your device: Tuta's June 11, 2024 post says the choice "is stored in the browser cache," and the code encrypts each saved address before writing it to a local database. The Android and iOS apps run the same client inside a web view, so the behavior matches across devices, though each device keeps its own list.
What Happens When You Click Show?
Your device downloads the images directly from the sender's servers, and the tracking pixel fires as it would in any unprotected mail app. Nothing in the client routes those requests through Tuta: a search of the repository for an image proxy returned nothing, and the sanitizer simply restores the original URLs. Tuta's own January 24, 2025 explainer lists what a pixel collects at that moment, including your "device information," "IP address," and when the email "is opened."
Here is the contrast no provider page draws. Proton fetches every image through its own proxy at delivery, so marketers see each Proton address as opened instantly, a fake open. Fastmail proxies at the moment you open, as our Fastmail read receipts investigation showed, which hides your IP address but leaks your timing. Tuta sits at both extremes at once:
- Before you click: the sender sees nothing. Your message looks unopened forever, which is stronger than Proton's fake open.
- After you click: the sender gets the full open record, including your real IP address, your rough location and your browser or app. That is weaker than Proton or Fastmail.
So the protection rests on your clicks. A newsletter you trust with Always display images reports every open, from your home connection.
Does Tuta Strip Tracking Links or Warn About Them?
Tuta does not remove tracking parameters or unwrap click redirects, so a tracked link still reports your click. The repository contains no list of tracking parameters and no URL cleaner. What the client does add is rel="noopener noreferrer" on links in messages, which keeps the page you open from learning that you came from your mailbox. The destination still sees your click.
Tuta does have a dialog titled "Suspicious link," but it is not a tracking warning. In ApplicationWindow.ts, the dialog titled "Suspicious link" fires only in the desktop app and only for links that are not http or https, warning that "The link might run programs on your device." It never looks at tracking.
Phishing gets its own banner: "This email is similar to other emails that were reported for phishing." The function checkMailForPhishing in MailFacade.ts adds points when the sender, subject or a link matches hashed markers from reported phishing, and 6 points when a link's visible text names a different host than its real target. The banner needs more than 7 points, so a mismatched link alone never trips it. The host comparison also runs only when the visible text is itself a web address, so a "Shop now" button that passes through a click tracker never counts. Our guide to blocking click tracking in Gmail explains how those redirects work.
What Does a Sender See on Each Side of a Tuta Email?
A sender emailing you at Tuta sees delivery and nothing more, unless you load images or click a link. In the other direction, Tuta adds nothing to the mail you send. Its client has no open tracking or link tracking option, and the pixel tracking explainer says "Tuta does not include email information (IP address) in the emails you send."
- Someone emails your Tuta address: no receipt, no pixel load, no open signal until you act.
- You send a confidential message to a Gmail user: they get a notification email that reads "You have just received a confidential email via Tuta" with a link to the encrypted message. We found no read status for the sender anywhere in the client.
- You send a regular message to a Gmail user: it arrives as plain email, and from then on Gmail's rules apply to their inbox, not Tuta's.
Tuta protects whoever reads in Tuta. Your Gmail correspondents, and your own Gmail account, are outside that wall.
What Can Tuta Itself See?
Tuta can't read your stored messages, but it sees routing metadata and can be ordered to watch new mail. The privacy statement says "Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted." Mail server logs "are stored max. 7 days" and "contain sender and recipient email addresses and time of connection but no customer IP addresses." For abuse prevention, "IP addresses are only stored anonymized."
Journalists and activists should read the transparency report, last updated July 1, 2026. Between January 1 and June 30, 2026, Tuta received requests for inventory data in 215 cases and released it in 28. It received 30 requests for real time traffic data and released it in 26 cases under a German court order. It received 12 requests for real time content data and released it in 6.
The definitions matter. Traffic data means sender and recipient addresses, "IP address of the Tuta client" and delivery time. Tuta says "By default, we don't record IP addresses of our users," but can start recording them for one account once a court order arrives. Under real time monitoring, "Emails that are sent unencrypted are delivered in plain text if they arrive after we have received a valid German court order." Mail that arrived earlier stays encrypted. If your source writes from Gmail, a monitoring order on your Tuta account can expose those future messages.
What Did Our DNS Checks Find?
We found no tracking host and no outside email platform in Tuta's mail setup. The checks ran on October 4, 2026, using the method from our guide to detecting email tracking pixels in Gmail.
- Mail routing: tuta.com, tutanota.com, tutanota.de, tuta.io and keemail.me all point their MX record at mail.tutanota.de. Each SPF record includes only spf.tutanota.de, which lists two Tuta address ranges, 185.205.69.0/24 and 81.3.6.160/28, and nothing from a third party sending service.
- Tracking hostnames: track, tracking, pixel, t, open, click, links, email, news and newsletter under tuta.com and tutanota.com returned NXDOMAIN from the domains' own authoritative nameservers. A nonsense control name returned NXDOMAIN too, which rules out a wildcard.
What This Means for Your Gmail Inbox
Tuta's blocking follows the app you read in, so it does nothing for messages you open in Gmail. Google's image help page admits that "Sometimes, senders may know whether you've opened an email that has an image." Gmail fetches images through Google's servers, which hides your IP address but still confirms the open, as we explain in the tracking pixel that learned to dodge Gmail.
Tuta offers a bridge. Its "Email migration (Beta)" feature can import a Gmail account and, in the interface's words, "will continuously synchronize your mails from your selected provider to your Tuta account." Read those copies in Tuta and the image block applies. Keep reading them at mail.google.com and it doesn't, because the original still sits in Gmail.
How Do You Block Tracking in Tuta and in Gmail?
In Tuta, the job is not undoing the defaults. Our checklist, based on the code and Tuta's content security post:
- Leave images blocked unless a message is unreadable without them.
- Prefer Show over Always display images for sender. Show is a single open; the sender rule is every open, indefinitely.
- Treat links as tracked. Tuta doesn't clean them, so type the store's address for anything that isn't urgent.
- Higher risk? Remember the 7 day mail server logs and the monitoring orders above, and ask sources to write from Tuta or another end to end encrypted service.
For mail you still read in Gmail, these are the options, checked on October 4, 2026:
| Tool | Where it works | Pixels | Links |
|---|---|---|---|
| Tuta | Tuta's web, desktop and mobile apps | All remote images blocked until you click; no proxy after | Not cleaned |
| Proton Mail | Proton's web and mobile apps | Known trackers removed; other images preloaded by proxy | Parameters cleaned on web; redirects kept |
| PixelBlock | Gmail in Chrome; 40,000 users | Blocks open tracking; last updated December 2, 2025 | Listing describes open tracking only |
| Trocker | Webmail in Chrome; 10,000 users | Blocks known trackers; version 3.4.1 from July 10, 2026 | Says it prevents "tracked links from being loaded" |
| Ugly Email | Firefox only; its Chrome listing now loads as an empty page | Firefox version 4.1.2, last updated March 6, 2024 | Not covered |
| Gblock | Gmail in desktop Chrome only | Blocklist that updates itself; flags unknown tiny images | Optional: links routed via its proxy, tracking parameters stripped |
Plainly: if every message you get lands in Tuta and you read it there, you don't need Gblock, and Tuta's block everything default catches pixels that no blocklist knows about yet. Gblock does nothing inside Tuta, the Gmail mobile app or a desktop mail client. It fits two readers. One kept a Gmail address next to Tuta and still reads it in Chrome. The other is weighing a switch to Tuta only to escape pixels; staying in Gmail with a blocker is less work, though no extension gives you Tuta's encryption. Gblock also differs from Tuta in one useful way: it blocks known pixels while letting the rest of a newsletter's images load, so you don't trade privacy for a blank email.
Next steps: how to block email tracking in Gmail, the Ugly Email vs PixelBlock vs Trocker comparison, and, if you're still choosing a provider, the best private email providers.
What We Could Not Verify
We did not open a Tuta account or send tracked test mail to one, so every behavior claim here comes from Tuta's published pages and the client code in its public repository. Tuta's server is closed source, so we can't rule out that it handles receipt headers or link checks out of sight, though nothing in the client would display either. We could not read the support FAQ entry the app links to for help on loading images; our fetches of Tuta's FAQ never returned that entry. Tuta's own newsletters went unexamined.