MailSignals

Guides

How email tracking actually works, and where it stops.

Six explanations written from the same evidence the product is built on. They apply to every tracker, not just this one; where MailSignals does something specific about a problem, the guide says so and links to the feature.

8 min read · 2026-09-08

Why your email tracker says you opened your own email

Every Gmail tracker turns green when you open your own Sent folder. Here is exactly why the request is indistinguishable, and the four ways MailSignals tells it apart without the Gmail API.

Read the guide →
7 min read · 2026-09-08

What Apple Mail Privacy Protection does to open tracking

Apple downloads your tracking pixel on delivery, before anyone reads the message. What that request looks like, why it should never count as an open, and what you can still learn from it.

Read the guide →
6 min read · 2026-09-08

Gmail's image proxy, and why your open count is a lower bound

Gmail fetches every image through its own proxy and caches it. What that hides, what it still reveals, and why an honest tracker labels a proxied open as a lower bound.

Read the guide →
7 min read · 2026-09-08

Are email tracking pixels legal? The EU, UK and US position in plain terms

Tracking pixels are regulated, and the rules are tightening. What ePrivacy, the CNIL and CAN-SPAM say, what it means for one-to-one email, and which controls let you comply.

Read the guide →
7 min read · 2026-09-08

What a Gmail OAuth scope really costs: verification, CASA and the 100-user cap

Why commercial trackers ask for full mailbox access, what Google demands in return, and how a tracker can do the whole job from inside the Gmail page with no scope at all.

Read the guide →
8 min read · 2026-09-08

Tracking email an AI agent sends through the Gmail API

An agent that sends mail itself bypasses the browser, so no extension can see it. How MailSignals prepares the body server-side, why the agent never holds a key or a policy, and how to wire it up with MCP.

Read the guide →

Run it in your own project.

One Firebase project, two subdomains, one deploy script. About an hour the first time, and no subscription afterwards.