Sep 03, 2026 · 12 min read
Is Typeform Tracking Your Email? How to Block It
The pixel is the small part. The link that brought you to the form, and the moment you type an email address into it, both hand over far more than an open receipt ever could.
Typeform email tracking is not one thing you can answer yes or no to, and the honest answer runs against what you would expect. Emails Typeform sends from its own shared address carry no pixel at all. Emails sent through a company's own verified domain carry one, and Typeform reports the open rate back to the sender. So the message that plainly announces itself as a Typeform is the untracked one, and the message dressed up to look like it came from the company is the tracked one.
That inversion is worth holding onto, because it is the opposite of the instinct most people apply to their inbox. But the pixel is not where your exposure actually lives. It lives in the link that carried you to the form, and in what happens the second you type your address into the email field.
Key Takeaways
- Typeform's documentation states that emails sent from its shared address
notifications@followups.typeform.io"do not include tracking pixels, which means you'll have no visibility into delivery, open, or click rates for these emails." - When a sender configures a custom verified domain, Typeform tracks the opposite way, and its own words are unambiguous: "Opens are tracked using an invisible pixel in the email body."
- Typeform states that forms "are anonymous by default", but URL parameters, previously called Hidden Fields, let the sender attach your name, email or an internal ID to the form link before it reaches you.
- Typeform's Response enrichment feature sends the email address you type to ZoomInfo and FullContact, and can return up to 19 fields you never entered, including age, gender, marital status and annual household income.
- Response enrichment is on by default for forms on Typeform's Growth Flow plan and off by default on Plus, Business and Growth Custom.
Does Typeform Track Email Opens?
Only when the sender has set up a custom email domain. Typeform's guide to tracking email performance in Automations states the condition up front: "Email metrics are only available for automations sent from a custom, verified email domain. If you don't have one set up and send emails from the Typeform domain notifications@followups.typeform.io, email metrics won't be tracked."
Where the tracking does run, Typeform describes the mechanism in a single sentence with no euphemism: "Opens are tracked using an invisible pixel in the email body." The sender then sees a delivery rate, an open rate and a click rate on each Send email step, calculated over a rolling seven day window.
Two limits are worth knowing, because they cut in your favour. The metrics are aggregate, "calculated for each Send email step as a whole (not per individual contact)", so a company using this feature sees a percentage rather than your name against a timestamp. And click rate "counts clicks on buttons only (not hyperlinked text)". Typeform even concedes the pixel's unreliability in its own troubleshooting notes: "Some email clients block tracking pixels or load them through a proxy server, so not every real open is counted." That is the vendor telling you the defence works. Our breakdown of how to detect email tracking pixels in Gmail walks through spotting one in a raw message.
Which Typeform Emails Are Untracked, and Why That Is Backwards
The unbranded ones. Typeform's documentation on email notifications to respondents lists the shared address as a set of limitations a business should want to escape, and the third item on that list is the tracking: "Email metrics will not be tracked: emails sent from notifications@followups.typeform.io do not include tracking pixels."
Read that from the recipient's chair and the incentives invert cleanly. The same page notes that shared domain messages "will always include Typeform Notifications as the sender name" and cannot be branded. So the visible signal you would use to judge a message, whether it looks like a real company sent it, points exactly the wrong way. An obvious Typeform confirmation email is the safe one. A polished branded follow up from the same platform is the one carrying the pixel.
The shared address has one quirk that cuts both ways. Typeform warns senders about a "Global opt out: if a respondent unsubscribes from the notifications@followups.typeform.io email address, they'll unsubscribe from all email communications sent from this domain." Framed as a drawback for the business, that is a useful lever for you: one unsubscribe covers every company still on the shared domain. The infrastructure behind it is Mailgun, which a DNS lookup confirms, since followups.typeform.io publishes v=spf1 include:mailgun.org ~all and points its MX records at mxa.mailgun.org.
What Does a Typeform Link Tell the Form Owner About You?
Whatever the person who built the link chose to put in it, which can include your full name and email address before you answer a single question. Typeform's page on how to identify your respondents opens with a reassurance that turns out to be conditional: "Typeforms are anonymous by default, and we don't store respondents' geolocation information, so forms can't reveal who someone is unless you've asked them or you already have their information stored elsewhere."
That last clause is doing all the work. The second route Typeform offers senders is the one that matters: "If you already have your respondent's information in your database you can pass the name, email, ID, or all of these via URL parameter in the URL of the typeform."
These are URL parameters, renamed from Hidden Fields, and Typeform's documentation on using them shows the format plainly. The worked example is https://tutorials.typeform.com/to/nzthWI#first_name=Fran&source=twitter, and the resulting data "will appear in your Responses", where the sender "can see each individual submission and its URL parameter data".
Note where those values sit in the documented example, after the #. Everything following a hash is a URL fragment, which your browser does not put in the HTTP request line, so the form's own JavaScript reads it in your browser and submits it alongside your answers. The consequence is the same either way: a link built for you alone is an identifier, and no email setting reaches it. Typeform is blunt about the spread too, warning senders that parameter values "can appear in browser history and address bars", "may be stored in server logs, proxy logs, and security tools", and "can be seen by other tools you connect to Typeform".
A separate feature, source tracking through URL parameters, layers the familiar UTM set on top: "source, medium, campaign, term, and content". Same structure, same result, and the identical pattern we found inSurveyMonkey's per recipient survey invitations. It is why a survey described as confidential can still be tied back to one named person.
What Happens When You Type Your Email Into a Typeform?
On many accounts it gets sent to two data brokers, and a profile comes back. This is Response enrichment, and it is the least covered part of the Typeform story by a distance. Typeform's documentation on contact enrichment names the partners without hedging: "We send the contact's email address to our enrichment partners (ZoomInfo and FullContact). If either partner returns a match, enrichment data is added to the contact."
What comes back is not a name and a company logo. Typeform's guide to response enrichment publishes the full field list. For a personal address such as a Gmail one, the B2C set runs to 19 fields, among them:
enr_person_age,enr_person_genderandenr_person_marital_statusenr_person_has_childrenandenr_person_annual_household_incomeenr_person_address_city,enr_person_address_regionandenr_person_address_countryenr_person_phone_number,enr_person_bioandenr_person_job_titleenr_person_linkedin_url,enr_person_facebook_url,enr_person_x_urlandenr_person_image_url
Set that against the pixel and the comparison answers itself. An open pixel reports one bit of information, that a message rendered. One email address typed into a form with enrichment enabled can return a photograph of you, your income bracket, whether you have children and your marital status. The form asked one question. The record holds twenty answers.
Typeform puts the match rate at "up to 92% for B2B companies and 71% for B2C companies", so this is not a rare edge case. And the default is not uniform: the enrichment toggle "is on by default if you're on the Growth Flow plan, and off by default if you're on the Plus, Business, or Growth Custom plans." Whether your address goes to ZoomInfo therefore depends on a billing decision made by a company you have never spoken to.
How Do You Block Typeform Tracking in Gmail?
Stop Gmail loading remote images, then treat the link and the email field as separate problems, because no image setting touches either. Work in this order.
- Turn off image auto loading. In Gmail on the desktop, open Settings, See all settings, and under Images choose Ask before displaying external images, then save. Google's guide to turning images on or off in Gmail covers the setting. Gmail's default proxies images through Google instead, which hides your IP address but still fires the request, so the open still counts.
- Read the raw message first. Use Show original on any form invitation. You are looking for two things: an image tag one pixel wide, and where the button actually points. Typeform form links follow the pattern
typeform.com/to/<form id>, so anything trailing that ID is a parameter carrying data about you. - Strip the parameters before you click. Copy the link rather than clicking it, delete everything from the
#or?onward, and open the bare/to/<form id>URL. The form still works. The name, email or internal ID that was riding along does not arrive. - Think before filling the email field. That field is the trigger for enrichment, not the tracking pixel. If the form does not mark it required, Typeform confirms enrichment "will not happen if a respondent skips the first email question".
- Apple Mail Privacy Protection is not a fix. Apple's Mail Privacy Protection guidance explains that remote content is downloaded in the background when the message arrives rather than when you read it. Your IP address is hidden, but an open is manufactured for a message you may never open.
Which Blocker Actually Helps Here?
Named honestly, with the form link as the column where nothing wins. Our roundup of the best email tracker blocker extensions goes deeper on each.
| Option | Stops the open pixel | Handles tracking links | Strips form URL parameters |
|---|---|---|---|
| Gmail, ask before displaying external images | Yes | No | No |
| Apple Mail Privacy Protection | No, it prefetches instead | No | No |
| Ugly Email | Flags rather than blocks | No | No |
| PixelBlock | Yes, inside Gmail | No | No |
| Trocker | Yes, list driven | Warns on wrapped links | No |
| Proton Mail or HEY | Yes, off by default | Partly | No, and it means moving your mailbox |
| Gblock | Yes, inside Gmail | Yes, it strips tracking redirects | No, that one is manual |
Where Gblock fits, stated without inflation. It blocks tracking pixels from loading and strips tracking redirects out of links before you click them, and its blocklist updates on its own rather than waiting on a new extension release. It runs inside Gmail, so you keep your address and your provider. What it does not do is rewrite a form URL that was built to identify you, or reach into Typeform's enrichment call. Those two stay manual, and any tool claiming otherwise is overselling. Our full ordering lives in the guide to blocking email tracking in Gmail.
What Compliance Teams Should Check Before Enabling Enrichment
Typeform has already written your risk assessment for you, which is unusual and worth quoting. Its page on Response Enrichment privacy considerations states that "activating the Response enrichment feature shares respondent email addresses with third-party providers" and that "some privacy laws, including the GDPR, require you to provide notice and obtain specific consent from your respondents when sharing data with a third party."
The suggested remedies are thin, and knowing that is the useful part. Typeform proposes writing the disclosure into the email question's description text and leaving the question optional, or branching between two email questions with a consent choice in front. Neither produces the freely given, specific, informed consent record a regulator will look for, and Typeform closes the page by noting it "does not, and is not intended to, constitute legal advice". Fields like enr_person_marital_status and enr_person_annual_household_income are not the kind of thing a description line under a text box covers.
One more item belongs on the checklist. Per Typeform's overview of what happens to your data, its main servers sit in Virginia, with EU hosting reserved for Enterprise and Growth Custom customers. If your transfer assessment assumed EU residency, check your plan tier.
What This Means for Your Inbox
Typeform links reach you constantly without announcing themselves: NPS prompts after a support ticket, event feedback, job application forms, waitlist signups, employee pulse surveys. Each one arrives as an ordinary email with a button. The tracking question people ask about that button is almost always the wrong one.
Most coverage of survey platforms fixates on the open pixel because it is the familiar villain. On Typeform the pixel is genuinely the smallest exposure in the chain, and on the default sending address it does not exist at all. The real sequence runs: a link that may already name you, a form field that ships your address to two data brokers, and a response row that ends up holding demographic detail you never volunteered. If the enrichment pattern works this way at Typeform, assume it works the same way at every form and survey product selling lead qualification, because they are buying from the same brokers.
A workable habit, in four steps:
- Set Gmail to Ask before displaying external images, and add a blocker that also rewrites tracking redirects, since opens and clicks are two separate techniques needing different countermeasures. That closes the pixel layer for every sender, not just Typeform.
- Before clicking any form button, copy the link and cut everything after the form ID. Ninety percent of the identification problem is solved with a keystroke.
- Treat the email field as the real decision point. It is optional more often than it looks, and skipping it stops enrichment.
- If a form is described as anonymous, ask whether URL parameters and Response enrichment are switched on. Both are one click for the organiser to check.
Sources: Typeform: Track email performance in Automations; Typeform: Send email notifications to respondents; Typeform: Using URL parameters (formerly Hidden Fields); Typeform: How to identify your respondents; Typeform: Response enrichment with Typeform; Typeform: Contact enrichment; Typeform: Response Enrichment privacy considerations; Typeform: Source tracking through URL parameters; Typeform: What happens to my data?; Google: Turn images on or off in Gmail; Apple: Use Mail Privacy Protection on iPhone. Typeform documentation was read on 3 September 2026. The Mailgun finding comes from a direct DNS lookup of the SPF and MX records for followups.typeform.io. Typeform does not publish the hostname or path of the open tracking pixel used on custom domain automation emails, so it is described here by the behaviour Typeform documents rather than by a URL this article cannot verify.