Aug 19, 2026 · 8 min read
Is Workshop Tracking Your Work Email? How to Block It
Workshop is the internal communications platform your employer uses to email you. Its documentation says every message carries a pixel tied to you personally, and its support site walks corporate IT through switching off the security tools that would strip it out.
Nobody signs up for Workshop. It arrives because you are on the payroll. So when employees ask whether Workshop is tracking your email, the answer comes not from a privacy policy nobody reads but from the vendor's own help center, which states that each recipient gets a unique pixel used to "attribute each open event directly to the correct person." The request goes to workshop-email-tracking.com, a hostname naming neither your employer nor any brand you would recognise.
Key Takeaways
- Workshop's help center states that "Each recipient has a unique pixel," letting the platform attribute every open to a named employee.
- Workshop's GDPR page states that "By default, these IDs can be associated with individual recipients," and the anonymization setting requires emailing sales@useworkshop.com.
- workshop-email-tracking.com and workshop-email-content.com were registered on 4 April 2022 through Cloudflare, one second apart.
- Workshop tells corporate IT to set Mimecast CyberGraph "Trackers" to Disabled and to select "Disable URL Protection."
- Gmail's image proxy defeats Workshop's read duration and device analytics, which the vendor concedes, but the open event still registers.
Does Workshop Track When Employees Open Email?
Yes, and individually. Workshop's support article How Workshop tracks email analytics opens by saying it "tracks email opens using a unique invisible pixel per recipient," and under a heading reading "Each recipient has a unique pixel" explains that the attribution holds "no matter which device, browser, or app they use to read the email." A safelisting guide names two collection methods: "A 1x1 invisible pixel is placed at the bottom of an email," and "all links embedded in an email are rewritten to a redirect url."
This is the fourth internal comms tracker we have documented, after ContactMonkey, PoliteMail and Staffbase. All four use a per recipient pixel. Workshop is the only one whose support site tells your security team to stand down.
What Is workshop-email-tracking.com?
It receives the open event when you read a Workshop email. Workshop names it in its safelisting docs alongside workshop-email-content.com, with a third, wkshp.link, in the published list of Workshop URLs for shortened links.
We checked all three in August 2026. workshop-email-content.com and wkshp.link answer HTTP 200 and serve pages titled simply "Workshop," carrying a robots noindex directive. workshop-email-tracking.com answers 403 behind Cloudflare, so the exact pixel path is not something we can confirm, and not something we will guess at. WHOIS shows the two registered one second apart, at 18:36:36 and 18:36:37 UTC on 4 April 2022.
The naming is the point. Inspect a message source, find that request, and nothing in the string tells you it is your own HR department watching. Our guide to detecting email tracking pixels in Gmail covers reading them.
What Can Your Employer Actually See?
More than whether the memo arrived. Workshop's analytics documentation lists what it "can reliably record" per open: "The exact time of the request," "The IP address used," and "The email client that performed the request." Its email analytics guide adds read duration with three published buckets:
- Read, at 8 or more seconds
- Skimmed, at 3 to 8 seconds
- Glanced, at under 3 seconds
- Device type, split across desktop, mobile and tablet
- Which links you clicked, as "Recipient click data per URL"
Granularity varies: opens and clicks export per named recipient, while read time exports as a percentage rather than a per person column. Five seconds is still the whole distance between "Skimmed" and "Read" in a chart your director may open. Workshop ships a workflow on top: filter Recipients to Unopened, click "Create list from," resend to exactly those people. Nor is there an exit on your end, since its FAQ notes "unsubscribing is not an offered feature."
Why Does Workshop Ask IT to Disable Mimecast and Proofpoint?
Because modern email security strips tracking pixels, and Workshop's analytics stop working when it does. Mimecast CyberGraph removes trackers from inbound mail; Workshop's answer is a published walkthrough, CyberGraph in Mimecast, telling admins to create a bypass policy and set "Trackers" to Disabled. It signs off congratulating them on configuring "Mimecast to allow emails sent using Workshop to bypass CyberGraph tracking removal."
A companion article on URL Protection in Mimecast tells admins to select "Disable URL Protection." Further guides safelist Workshop's IPs in Proofpoint and Microsoft 365 Defender, though those are ordinary anti spam steps, and lumping them in with the CyberGraph bypass would be unfair.
The dashboard is not the story. The trade is: a vendor asks the security team to switch off a control that protects employees, so the comms team can keep a metric.
Does Gmail Change Anything?
It blocks part of it, and Workshop says so in writing. Google routes remote images through a caching proxy that its admin documentation says "protects your users and domain against image-based security vulnerabilities." Workshop concedes the result twice: "Due to technical limitations with the way Gmail processes images, we are unable to provide time read analytics for users of Gmail," and the same sentence again for device type.
That is a partial win. Read duration and device type die at the proxy; the open event does not, because Google fetches the image and Workshop logs the request with your name attached. Workshop's fix is to have your Google admin defeat the proxy, via Apps, Gmail, End User Access and "Image URL proxy allowlist." Google attaches a warning that Workshop's cheerful walkthrough never repeats: "Consult with your security team before configuring the Image URL proxy allowlist setting." A domain wide security exemption, traded for a read duration chart.
Is Employee Email Tracking Legal?
It depends on where you work, and what follows is context rather than legal advice. In the EU, Article 88 of the GDPR lets member states set their own rules for employee data. Consent is weak at work because the employer holds the power, so employers lean on legitimate interest, and the EDPB's Guidelines 1/2024 require a documented balancing test.
Germany is sharpest. Section 87(1) no. 6 of the Works Constitution Act gives works councils co determination rights over technical equipment capable of monitoring employee behaviour, and a dashboard attributing opens to named staff meets that description. The United States has no equivalent, and employer monitoring of company email is broadly permitted.
Workshop does offer a real control, and it deserves credit. Its GDPR page describes an optional setting that anonymizes opens, clicks and survey responses, and the unopeners docs state the trade off honestly: with it on, "features like targeting unopeners aren't available." But it is off by default, and enabling it means emailing sales@useworkshop.com. Across all 179 articles in Workshop's help center, we found no control letting a sender turn open tracking off for one email.
How Do You Block Workshop Email Tracking?
On the recipient side, because every toggle Workshop ships belongs to the sender. The honest caveat first: on a managed laptop and a company Google Workspace account, IT may have locked extension installs, and adding one could sit awkwardly against acceptable use policy. Check first. Nothing below changes what your employer's mail server or device management software sees.
- Stop images loading automatically. In Gmail open Settings, See all settings, General, Images, and select "Ask before displaying external images," per Google's image settings guide. This kills the open event outright, at the cost of legitimate images too.
- Strip the pixel, keep the pictures. A blocker extension removes known beacons before the message renders and rewrites tracking links to their true destinations. Gblock does this inside Gmail against an auto updating blocklist, which matters because vendors rotate domains.
- Do not follow rewritten links. Click tracking survives image blocking, because you make that request on purpose. Hover, read the real destination, and where the content also lives on your intranet go there instead.
Which Blocker Should You Actually Use?
Judge them on what they do. Ugly Email flags tracked messages with a visible icon. PixelBlock is deliberately minimal. Trocker covers Gmail and other webmail, with some link unwrapping. Proton Mail and HEY block remote content at the server by default, the strongest protection here, though both mean changing provider. See our roundup of email tracker blockers.
Gblock's differences are narrow: the blocklist updates automatically rather than depending on a maintainer's spare time, it strips tracking links rather than pixels alone, and it runs inside Gmail without changing how your mail looks. It will not stop a click you choose to make, does nothing in Outlook desktop, and is no defence against device monitoring. Blocking a mandated tool's pixel is a personal privacy measure, not a way around policy. You still have to read the memo.
What This Means for Your Inbox
Marketers spent a decade arguing over whether an email open counts as personal data. Internal communications skipped the argument, because recipients never had an unsubscribe link, and because "engagement" sounds friendlier signed off by the People team. The plumbing matches the trackers in our Gmail tracking detection guide. Only the sender changed.
The exposure builds slowly. One newsletter tells your employer very little. Fifty across a year produce a record of when you sit at your desk, which evenings you check work mail, and which internal job postings you opened. Nobody set out to build that profile; the dashboard assembles it anyway. Block the beacon and your employer still learns the message was delivered. They stop learning that you gave it four seconds.