How to block tracking pixels in your emails with DNS filters

  • The tracking pixels send data about openings, device, and location without the user noticing.
  • Blocking remote images, using private providers and extensions drastically limits that tracking.
  • DNS filters and some VPNs block tracking domains at the network level, protecting all devices.
  • Combining technical adjustments with email aliases and best practices offers a solid defense against tracking.

How to block tracking pixels in your emails with DNS filters

If I told you that Every time you open an email, someone might be taking notes on what you're doing.You'd probably think I was exaggerating. But no: many of the marketing emails you receive contain a tiny digital spy, an invisible tracking pixel, that reveals when you opened the message, from which device, how many times, and even where you connected from.

This type of tracking has become a form of everyday, silent, and massive surveillanceLarge platforms, advertising companies, email marketing tools, and even cybercriminals use these pixels to collect data at your expense. The good news is that you're not at a loss: with a few tweaks to your email settings, the use of DNS filters, and some additional tools, you can drastically reduce what third parties know about you.

What are tracking pixels and how do they actually work?

So-called tracking pixels, spy pixels, or web beacons are tiny images embedded in emails, websites, or appsThey are typically 1×1 pixels (or even 0×0). They are so small and usually transparent that, for all practical purposes, they are invisible to the user.

When you open an HTML email and your email client loads the remote images, The program makes a request to the server where that pixel is hosted.That simple request allows the server to record a good amount of information: date and time of opening, IP address, operating system, type of browser or email client, and the page or message from which the image was downloaded.

In marketing, a code similar to the following is often used: That URL is unique for each recipient, so it's known not only that an email has been opened, but exactly. which address opened it, how many times, and from what environment.

Something similar happens on the web, but often instead of an image, a [text/method] is used Embedded JavaScript that executes tracking codeThe result is the same: they can track your browsing path, how long you spend on a page, which sections you visit, and how you interact with the content.

All this tracking is integrated into a huge economics of digital surveillanceThe data is used to personalize ads, analyze campaigns, test designs, optimize sales funnels, build user profiles, and, in many cases, is shared or sold to third parties specializing in data.

What data can these trackers collect, and why is that a problem?

Tracking pixels are not limited to a simple “email opened/not opened”. In practice, They can draw a fairly detailed map of your behaviorAmong the most common information they collect is:

  • Whether or not you opened the email and how many times have you opened it again.
  • Exact date and time of each opening, up to the second.
  • IP address and approximate location (sometimes very precise, down to the city or neighborhood level).
  • Device, operating system, and email client that you use (Gmail, Outlook, Apple Mail, etc.).
  • Screen resolution and some technical parameters that help create a “digital fingerprint” of the device.
  • In many cases, links in the email with tracking parameters (UTM and others), which link your clicks to specific campaigns.

When you click on a link in a tracked email, you often You don't go directly to the destination siteFirst, you go through an intermediary server that records your click, saves your email address associated with that link, and only then redirects you to the final website. All of this happens so fast you don't even notice it, but it leaves a trace.

The problem is that, when you add up pixels, tracking links, cookies, and browser fingerprints, Your email address can be linked to your browsing history, interests, and purchases.Academic studies have shown that a large majority of commercial newsletters contain several trackers that send data to numerous intermediaries, not just the original sender.

With that information, they are created highly detailed profiles of your online and offline behaviorFrom whether you tend to check emails at night to whether you visit websites related to investments, health, consumer issues, political ideology, or very specific hobbies. And all of this, almost always, without anyone clearly explaining it to you or asking for your genuine consent.

In addition, some email marketing providers and automation platforms have suffered massive data leaksWhen lists containing interaction histories are leaked, attackers can use that information to launch much more credible phishing campaigns, segmented by interests or user type.

The dark side: how cybercriminals use these pixels

It's not just legitimate companies that have seen the potential of these pixels. Cybercriminals exploit them as a reconnaissance tool. before attacking with targeted phishing campaigns or compromising corporate email.

An attacker can, for example, send a seemingly innocuous first email with a spy pixelAs soon as you open it, it already knows that your address is valid, that you read the email, from what part of the world, and more or less at what times you usually connect.

With that information, the next step is Prepare a much more credible phishing email and send it during the time slot when you are usually active.This increases the likelihood that you'll fall for it. If they also link this data to previous leaks (for example, lists of cryptocurrency clients, specific banks, etc.), the scam can be extremely sophisticated.

The use of pixels has also been documented for doxxing and aggressive profilingBy cross-referencing your approximate IP address with public data (social media, records, forums), they can try to identify your home address or workplace. This becomes especially worrying when we're talking about activists, journalists, or high-profile individuals.

In corporate environments, some employers have used web beacons to Monitor which employees open internal emails, when, and from where.without them being truly aware of the level of surveillance they are subjected to. Beyond the legal aspects, it's a serious issue of trust and workplace climate.

What's more, when an email marketing provider experiences a breachNot only are email addresses exposed, but often behavioral information as well: who interacts a lot, who hardly at all, what topics generate interest, etc. All of this facilitates highly personalized campaigns by criminals.

What role do law and regulation play in email tracking?

From a legal standpoint, the use of tracking pixels treads on delicate ground. In Europe, The GDPR (General Data Protection Regulation) is quite clearAny processing of personal data, and this includes tracking of opens and clicks, requires a solid legal basis, usually explicit consent.

European data protection authorities have shown a very strong opposition to this type of “silent” surveillanceBecause it stores and sends information about the recipient's behavior without their explicit knowledge. In theory, to comply with GDPR, companies using pixels should:

  • Explain transparently what data is collected and for what purpose.
  • Obtain informed, specific and unambiguous consent before activating tracking.
  • Allow the user withdraw that consent just as easily with which he granted it.
  • Document and be able to prove that all these requirements have been met.

In practice, many email marketing campaigns do not meet this strict standard and simply include generic mentions in the privacy policy or terms of use, which is not enough according to the most demanding interpretation of the GDPR.

Whereas in the United States the situation is different: the CAN-SPAM Act It does not expressly prohibit the use of pixelsHowever, it does establish obligations for commercial emails (sender identification, clear unsubscribe option, truthful data, etc.). It does not require explicit consent for tracking as such, which leaves users less protected against these practices.

Other countries (Canada, Australia and some US states) They are also tightening their privacy legislationTherefore, everything suggests that covert email tracking will face increasing legal restrictions, at least in theory. Meanwhile, if you want to protect yourself, it depends primarily on your own settings.

It should be remembered that Tracking pixels are not illegal per seMany companies use them to measure the effectiveness of a campaign in aggregate. The big problem is opacity: it's almost never clearly stated that they're there, nor is there an easy way to disable them.

How DNS filters block tracking and why they are so powerful

How to block tracking pixels in your emails with DNS filters

One of the most effective approaches to cutting off many trackers, including email trackers, is to use DNS filters that block known tracking domainsInstead of acting only in the browser or email client, you attack the problem at the domain name resolution level.

The DNS is the system responsible for translate domain names (e.g., example.com) into IP addresses that devices understand. Every time your email tries to load a remote image, or your browser resolves a tracking domain, a DNS query is made.

If you use a DNS service or server that implements blocking filters, When your email client requests to resolve the domain of a spy pixel, the response will be "does not exist" or it will be redirected to a null IP address.Result: the pixel never loads, the request does not reach the crawler's server, and therefore the opening is not recorded.

This approach has one major advantage: It works across all devices and apps that use that DNSIf you configure it on your router, it will affect your mobile phones, tablets, laptops, smart TVs, and, of course, your email clients and browsers. It's a very effective "hygiene layer."

Many secure DNS services and some VPNs already include this. specific blocklists for advertising, web trackers, malware, and email tracking domainsActivating them greatly reduces the exposure area, although no filter is 100% perfect and new areas will always appear.

The key is to combine these DNS filters with Other measures at the email client, browser, and behavior levelThe more layers you add, the harder it will be for a pixel or script to sneak in and send data about you.

Blocking tracking pixels in email: essential basic settings

Beyond DNS filters, there are a number of very simple settings that you should definitely activate in your email clients to to make things very difficult for the trackers.

1. Disable automatic uploading of remote images

It's probably the most effective step of all. Since most pixels function as remote images uploaded from an external serverIf you block that automatic upload, you cut off the tracking at the root.

In Gmail (web version), you can go to Settings → General → Images and select the option “Ask before displaying external images”. This way, emails will arrive without loading images by default and will only display them when you authorize it.

On the other hand, in Outlook.com, you'll find a similar option in Settings → General → Imageswhere you can adjust how external images are uploaded. In the Outlook desktop applications, you can also block automatic image downloads for privacy and security reasons.

In Apple Mail, on both iPhone and iPad as well as Mac, you have the option to disable remote content upload from the Mail settings. Apple has also gone a step further with Mail Privacy Protection, which preloads images through its own servers to hide your IP address and "break" traditional open metrics.

The disadvantage is obvious: Some emails will look rather bare, without banners or graphics until you decide to upload the images. But in terms of privacy, the benefit is enormous.

2. Use privacy-focused email providers

If you're seriously concerned about this, consider using an email service that Block tracking pixels by default and clean tracking linksProton Mail is one of the leading companies in this field.

Proton Mail incorporates a Enhanced tracking protection It does several things at once: it removes known spy pixels upon receiving the email, preloads other images through a proxy with a generic IP (so that your real location is not revealed), and cleans the links to remove UTM parameters and other tracking identifiers.

Additionally, it caches the images for a while so that subsequent access will be faster and will not involve new requests to the sender's serverThe user sees a shield icon with a number indicating how many trackers and tracking links have been blocked or cleaned in that message.

Other providers such as Tutanota or StartMail are also betting on aggressively reduce tracking and offer end-to-end encryptionThey are usually located in countries with strong privacy laws, which adds an interesting legal layer.

The advantage of this type of service is that, Without you having to change too many settings, they block a good portion of trackers by default.And, as a bonus, they usually integrate powerful anti-spam filters and strict policies against selling data.

3. Install browser extensions that block email tracking

If you check your email from a web browser (Gmail, Outlook web, etc.), you can rely on privacy-focused extensions that detect and block tracking attempts within messages.

There are specific email extensions, such as Email Privacy Protector, Ugly Email, PixelBlock or TrockerThese apps display an icon when they detect spy pixels and block their execution. Some even tell you how many trackers were embedded and which services they came from.

You can also use more general blockers such as uBlock Origin with scanlists enabledThese filters block many requests to advertising and tracking domains. While not designed exclusively for email, they help reduce noise.

However, it's wise to be cautious: Any extension you want to "touch" your email will have very broad access to its contentMake sure to install add-ons only from official sources (Chrome Web Store, Firefox Recommended Catalog, etc.) and with a good reputation.

Also keep in mind that the protection of these extensions is usually limited to the specific browser where you have them installedIf you read your email from a mobile app or another browser, the effect is lost, which is why DNS filters and email client settings remain key.

4. Email aliases and disposable addresses to compartmentalize your identity

Another very useful tactic is to resort to aliases and temporary emails for anything that smacks of aggressive marketing, quick registrations, or websites of dubious trustworthiness.

Services like SimpleLogin, Proton Pass or AnonAddy They allow you to create random email addresses that redirect to your actual inbox. That way, if one of those addresses starts receiving spam or excessively tracked newsletters, you know where the problem is coming from and you can "kill" the alias without touching your main account.

This not only reduces the clutter in your inbox, but also It limits the chances of your primary address ending up on third-party lists. or in data breaches. If an alias is compromised, you deactivate it and it automatically disappears from the equation.

Many users choose to keep a “clean” main address for trusted personal and professional mattersand then several aliases or secondary emails for store accounts, subscriptions, free trials, and the like.

If you combine this strategy with DNS filters and image blocking, the chances of being tracked en masse are greatly reducedeven if you remain subscribed to some newsletters that interest you.

DNS filters on the system and router: protect your entire network against web beacons.

If you want to go a step further and protect not only your email, but all the activity in your home or officeIt's worth setting up a filtering DNS on your devices or directly on the router.

At the operating system level, you can manually change the DNS server on Windows, macOS, Android, or iOS to point to a provider that offers tracker blockingMany security services and some VPNs already include specific profiles that block domains associated with advertising, tracking, and malware.

When you move that same setting to the router, things get especially interesting: All devices connected to your local network will inherit that configuration.This means that if a smart TV, mobile app, or email client attempts to upload images or contact tracking servers, the DNS will return a blocked response.

This systemic approach prevents you from having to go device by device installing specific extensions or apps. It works in the background, silently, and protects even those who share your network. and perhaps they are not so careful with what they open or configure.

However, it must be kept in mind that DNS filters cannot distinguish whether an image is a legitimate logo or a spy pixel.They depend on domain lists. If a sender hosts their pixels on the same domain as the rest of the "good" resources, some of the tracking might slip through. That's why it's so important to combine it with blocking remote images in email.

In some cases, a good VPN with a built-in tracker blocker can be a convenient alternative, especially if you usually connect from public or unreliable networksThe VPN encrypts your traffic, hides your IP address, and, if it includes a blocklist, blocks many tracking requests, including some email pixels.

More defense measures: plain text, best practices, and common sense

If someone needs the maximum possible privacy, there is always the radical option of Read and send emails exclusively in plain text.disabling HTML and images completely. It's awkward and visually poor, yes, but it eliminates the vast majority of tracking vectors in one fell swoop.

For the rest of us mortals, it's more realistic to adopt a combination of good practices and some oversightFor example, avoid opening emails from unknown or clearly suspicious senders, do not click on strange links, and be wary of messages that ask for personal data or unjustified urgency.

Many email clients allow View a secure preview of the message without loading remote content.If something seems suspicious, it's best to mark it as spam or delete it altogether. On a daily basis, it also helps to occasionally review which newsletters you're subscribed to and unsubscribe from anything that no longer benefits you.

At home or in the office, it is advisable to everyone is at least minimally aware of the problemBlocking pixels and links is pointless if someone then shares your device or account and opens and forwards anything they want. A short awareness talk can prevent many unpleasant surprises.

And, of course, although we're talking about tracking here, don't forget the other pillars of email security: strong passwords, two-step authentication, backups, and, if possible, end-to-end encryption for sensitive content.

Ultimately, it's about recovering something we should never have lost: the feeling that your inbox isn't a showcase for half the internet to take notes on what you doWith filters DNS Properly configured, blocking remote content, using privacy-friendly services, and applying four simple habits, you can read your emails again with considerable peace of mind, knowing that, at the very least, you are no longer giving away your entire digital life to every invisible pixel that crosses your path.


Add as preferred source