Open Rates Didn’t Die. They Just Entered Witness Protection

Источник: Transactional Email API Service For Developers | Mailgun

Open Rates Didn’t Die. They Just Entered Witness Protection

Source: Transactional Email API Service For Developers | Mailgun

Open rates aren't dead, they just have a new, more honest name: pixel loads. Here's what a tracked "open" can and can't tell you about whether a human actually read your email, and how to use the metric without over-trusting it. The post Open Rates Didn’t Die. They Just Entered Witness…

•Updated: October 5, 2026

October 5, 2026

It feels like every day, the email industry suffers another loss. If email itself has managed to escape the guillotine, open rates are next on the chopping block.

Apple Mail Privacy Protection killed them. Bots killed them. Image caching killed them. Security scanners, inbox previews, privacy proxies, and increasingly complicated reporting methodologies all took turns in the hot seat.

And yet, open rates stubbornly remain in our dashboards, segmentation strategies, reports, and conversations about campaign performance.

Table of contents

Not dead yet…

So maybe open rates aren’t dead. Maybe they just need a new identity. One that better suits them, and us. Because an “open” is not a teeny eyewitness inside the inbox confirming that a human saw, read, enjoyed, or even consciously noticed an email. It’s only a record that a tracking pixel (usually a small, invisible image embedded in the message) was requested.

Deliverability expert Laura Atkins calls these “pixel loads,” which is both less glamorous and more accurate. A pixel load is an observable event. An open is the story we tell about what that event means.

The event does contain some useful information! Unfortunately, calling it an “open” sounds much more certain than the underlying evidence deserves.

What an “open” actually tells us

When open tracking is enabled, the sender or email service provider inserts a unique 1 x 1 pixel into the message. When something requests that image, the ESP records an event.

That something might be:

  • an email client displaying the message for a recipient;
  • an image proxy acting on the recipient’s behalf;
  • a privacy service retrieving images automatically;
  • a security system inspecting the message;
  • a cache refreshing or retrieving the image again;
  • or another automated process somewhere between the sender and the screen.

Meanwhile, a highly engaged recipient might read every word with images disabled and never trigger the pixel at all, for example if they’ve chosen not to load images or are reading in an environment that blocks remote images, including some spam-folder views. That means a tracked “open” does not prove human attention, and the absence of one does not prove human disinterest. The distortion confusingly swings both ways, and you probably won’t ever know which way that is with any certainty.

Google’s Image Proxy secured the witness

Apple Mail Privacy Protection (MPP) shoulders most of the accusations about unreliable open metrics, partly because its automated image retrieval created such visible inflation when it was released. But Apple is only one culprit in a much larger caper.

Gmail has served external email images through Google’s own infrastructure since 2013. Instead of requesting an image directly from the sender’s server, Gmail routes the request through its image proxy. Google describes this as a safety and privacy feature: senders cannot use image loading to learn about the recipient’s computer or location, set cookies, or deliver known malicious software through the image. Google also acknowledges that senders may still be able to tell when an image-bearing message has been opened.

In other words, the proxy does not necessarily eliminate the observable event, but it does restrict what the event can reveal.

The sender may see Google’s infrastructure instead of the recipient’s IP address, device, browser, or location. Caching and repeated requests can further alter the number and timing of recorded events. The pixel still reports something, but some of the identifying details have safely entered WitSec.

The difference matters because an image request originating from Google is not automatically a “machine open” in the way marketers commonly use that phrase to mean “a human did not open this”. The proxy may be retrieving the image because a recipient displayed the message, and other Google systems may retrieve images automatically. From the sender’s perspective, those events can look similar even though the behavior behind them is different.

Trying to sort every event into a perfect “human” or “machine” bucket creates false confidence of its own, and probably doesn’t solve much, either.

Stop trying to identify the human. They are entitled to privacy.

The industry spends an inordinate amount of energy trying to identify every Apple relay, Google server, corporate security scanner, and privacy tool contributing nonhuman interaction (NHI) so that we can recover the mythical “real human open rate.”

But the human-versus-machine distinction is not always clean, nor should it be.

A machine may retrieve an image on behalf of a person who displayed the email. A privacy service may retrieve it before the person makes any decision at all. A security scanner may inspect a link because a real person received the message. A person may read the entire email without loading its images. The same recipient can generate several requests. Or none!

Published guidance from the Messaging Malware Mobile Anti-Abuse Working Group (M3AAWG) about NHI stops short of saying “The harder you hunt for the bot, the harder the bot will hide”, but it does explain a little about what’s going on behind the scenes.

Security systems intentionally conceal their scanning patterns so malicious senders cannot circumvent them. Some will simulate behavior designed to be indistinguishable from natural human interaction. As those protections grow more sophisticated, identifying every automated event becomes less reliable, and removing them all without also discarding legitimate activity may be impossible. The ambiguity is not merely a measurement flaw waiting for marketers to solve. It is, at least partly, the protective system working as intended.

So before attempting to reverse-engineer every proxy, relay, and scanner, ask what decision that classification will support. Are you correcting an obvious analytics distortion, or trying to identify which recipients can be mailed without the protective machinery noticing?

Even a technically impressive NHI filter cannot manufacture certainty from an event that never contained it. M3AAWG’s own conclusion is beautifully pragmatic: filtering changes the numbers, but senders can never know whether they have found every nonhuman interaction, and the effort may not be worth it.

There are legitimate reasons to filter obvious automation from reporting. Mailgun, for example, identifies detected Apple, Gmail, and generic automated activity in its event data to help give senders more information about recorded activities. Classification adds context, but it doesn’t transform a pixel load into proof of human attention.

More importantly, finding the robot does not answer the question marketers should actually care about:

Do these recipients want this email?

If they knowingly subscribed, recognize the sender, continue to find value in the messages, and can easily leave when they are done; you don’t need a perfect forensic reconstruction of every pixel load to justify the relationship.

But if you’re unsure whether recipients wanted the mail in the first place, just be aware that perfectly identifying every bot will not repair the underlying problem.

Sometimes the pixel is innocent and the math is weird

Even perfectly valid events can produce misleading metrics once reporting methodology enters the picture.

We have seen senders report that their open rates were too low because their template design prevented the tracking pixel from loading correctly. Once the implementation problem was fixed, the same sender’s open rates appeared too high because of measurement and aggregation quirks.

In one case, an hourly unique open rate exceeded 100%. Nobody had discovered a way for more than 100% of recipients to read an email. Deliveries were counted during the hour in which they occurred, while unique opens were counted during the hour in which they occurred later. The two hourly populations were not matched using the Message-ID.

Bear with me while we math it out. Imagine that 100 messages are delivered at 9 a.m. and many of them are opened at 10 a.m. If only 20 new messages are delivered during the 10 a.m. hour, those later opens can outnumber that hour’s new deliveries. Dividing one hourly population by the other can produce a rate above 100%, even if each message is counted as uniquely opened only once.

So, good news: nobody has violated the laws of mathematics. Bad news: we now have a time-bucketing problem misidentified as an open-rate bug.

At a daily or campaign-level resolution, where more of the deliveries and their later activity occupy the same reporting window, the apparent impossibility may disappear.

This is why the final percentage cannot be evaluated without understanding how it was produced.

Two ESPs, two open rates, neither necessarily “wrong”

Senders using multiple ESPs sometimes discover that the platforms report different open rates for comparable mail. The intuitive conclusion is that one platform must be measuring correctly and the other must be wrong.

But the finished percentages may reflect differences in:

  • tracking-pixel placement;
  • template rendering;
  • bot and proxy classification;
  • treatment of repeat requests;
  • definitions of “unique” activity;
  • numerator and denominator selection;
  • time zones and aggregation windows;
  • attribution of delayed events;
  • and data-retention periods.

And that’s before accounting for differences in audience segmentation, timing, content, historical reputation, or recipient behavior.

You’ve heard of comparing apples to apples? Well, comparing the percentages without comparing those decisions is asking why the fruit salad does not look like applesauce.

A competitor producing the expected number does not prove that its number is more accurate, or even that things are going well. It may be filtering different events, deduplicating them differently, or reporting them over a broader window. Changing another measurement system until both dashboards agree may produce more familiar numbers, but it does not necessarily produce truer ones.

At some point, attempting standardization becomes analytics cosplay.

For senders splitting traffic across multiple ESPs, the better comparison begins with equivalent cohorts, content, timing, definitions, and reporting windows. It should end with outcomes that can be defined consistently across both populations: clicks, conversions, purchases, account activity, complaints, unsubscribes, and other meaningful customer behavior.

The question is not, “Which ESP gave us the open rate we expected?”

It’s, “Which evidence helps us understand what actually happened?”

Open rates still have value

After all of that, it would be easy to conclude that open rates are useless.

But just to complicate your life further (sorry!), they aren’t.

A pixel load is still a post-delivery event. It tells us that something happened after the mailbox provider accepted the message. Across a large enough population and a reasonably consistent measurement system, that activity can provide useful directional information.

Tracked “opens” can help senders:

  • identify changes in visibility across campaigns or providers;
  • compare trends within the same reporting environment;
  • investigate sudden anomalies;
  • build a broader picture of recent recipient activity;
  • and estimate possible inbox presence when stronger placement data is unavailable.

High open rates sometimes correlate with successful campaigns because messages that reach visible inbox positions have more opportunities to generate image requests. Low open rates can accompany spam-folder placement, weak interest, rendering problems, or broken tracking.

The open rate tells us where to investigate, not which explanation is correct.

That makes opens evidence, but they’re still circumstantial.

A better framework for using tracked “opens”

Don’t do anything drastic! You don’t need to remove open rates from every dashboard. Just stop asking them to impersonate human attention.

A more useful approach looks like this:

  • Call the event what it is. At the technical level, it is a pixel load or image request. “Open” is a convenient reporting label, not a literal description of proven human behavior. It will probably be a while before ESP dashboard terminology catches up, but at least internally you can refer to them as their new name, “pixel loads”.
  • Prefer unique message or recipient activity to raw event counts. Repeat image requests can increase event volume without representing additional recipients, or even additional views.
  • Match the numerator, denominator, and reporting window. A rate is only meaningful when the populations being divided belong together.
  • Compare trends within a consistent system. Changes across campaigns, cohorts, and providers are easier to interpret when the underlying methodology remains stable.
  • Use tracked opens as a lower-confidence engagement signal. A recent unique open may contribute useful evidence, but it should not outweigh a click, conversion, purchase, reply, login, or other meaningful action.
  • Remember that no recorded open does not mean no readership. Image blocking, proxy behavior, caching, template problems, and alternative inbox interfaces can all conceal activity.
  • Remember that a recorded open does not mean permission. Automated retrieval cannot tell you whether the recipient asked for the message, recognizes the sender, or wants the relationship to continue.
  • Measure metrics as a team. Pair opens with clicks, conversions, complaints, unsubscribes, bounces, inbox-placement testing, and business outcomes. Each answers a different question.

Open rates are weakest when treated as a precise headcount of interested humans. They are strongest when used as one imperfect signal among several, and when senders understand how that signal was collected.

The open is not the desired outcome

Email measurement will continue getting messier. Mailbox providers and security systems have good reasons to protect their users, obscure personal details, inspect content, and limit tracking. Senders have good reasons to want to understand whether their messages are reaching and resonating with recipients.

Those interests will never align perfectly inside one invisible pixel.

A sender’s goal isn’t to recover a perfectly “human” open rate. It is to make better decisions with the evidence available.

You may never know exactly who, or what, loaded the pixel. But you can know whether recipients asked for your email and whether you sent what you promised.

The certainty was never in the pixel. Stop asking it to explain a relationship you should already understand.

What this article says

Something is unclear? Ask about the article — I will explain in plain words.

Do not want to dig deeper? We will sort it out for you.