Guides

Open tracking

PristineSend lets you choose how much you measure a recipient — per workspace, per campaign, or per message. Three modes trade analytics for privacy: full, essential, and off. Deliverability protection (bounce and complaint handling) is always on regardless of the mode — you only ever change what open and click data is kept.

The three modes

fullFull

Precise opens and clicks — the default, unchanged.

Opens
First open recorded with a full timestamp (date + time).
Clicks
Every click on a tracked link recorded with a full timestamp.
List hygiene
Best signal for engagement segments, open-rate reporting, the campaign health score, and inactive-subscriber sunsetting.
Privacy
Standard email analytics — an invisible tracking pixel and link redirects. The right default for a US/international audience.
essentialEssential

Day-level opens, full clicks — minimized analytics that keep list hygiene working.

Opens
The open DATE only (day-granular, stored at midnight UTC, last-open wins, no time and no per-open history). An open still counts — it just isn't timestamped to the minute.
Clicks
Unaffected — clicks are tracked at full fidelity, exactly like Full.
List hygiene
List hygiene keeps working: 'opened in the last N days' is a date-range check, so essential opens still drive engagement segments and inactive-subscriber sunsetting. Open RATE and the campaign health score, which is built on it, are marked not-applicable (the day-only data isn't precise enough to report as a percentage).
Privacy
The data-minimized shape behind the France (CNIL) / Italy (Garante) list-hygiene exemption for the open pixel: measure deliverability and engagement without retaining behavioural open-time analytics.
offOffGated

No open or click tracking — maximum recipient privacy.

Opens
Not tracked. No pixel is injected, so no open is ever recorded (opened_at stays null — read as 'not tracked', never 'not opened').
Clicks
Not tracked. Links are not rewritten, so no click is ever recorded (clicked_at stays null).
List hygiene
Inactive subscribers can't be detected via opens or clicks — engagement segments and open-based sunsetting go dark for these sends. Bounce and complaint suppression are still fully enforced (the deliverability floor never drops), so hard bounces and spam complaints still protect your reputation.
Privacy
The strongest privacy posture: the recipient is not measured at all. Choose it for privacy-first audiences or where consent for tracking wasn't given.
Availability
Gated. Until your account is provisioned for off-tracking, a send requesting 'off' is rejected with 503 service_unavailable (per-item in a batch). Contact support to enable it.

What an open actually measures

An open is one remote image fetch. When a message is rendered with images enabled, the recipient's mail client requests a tiny tracking image from us, and that request is what we record. That is the entire mechanism, and it is the only one that exists: no email protocol reports back that a message was read. The nearest thing to a standard read receipt (Disposition-Notification-To, RFC 8098) asks the recipient for permission, is ignored by most clients, and is treated as suspicious on bulk mail — so nobody uses it.

Everything sometimes described as an alternative — a background image, a remote web font, a CSS import, your hosted logo — is the same mechanism wearing a different hat. They are all remote fetches, and they all fail in exactly the same circumstances. The pixel is not the industry standard because it is good. It is the standard because it is the only thing there is.

Which means an open rate carries error in both directions, and knowing which one your audience produces is the difference between a useful number and a misleading one.

Under-reporting — the open never fires

Business recipients are the common case. Corporate mail systems — Outlook and Exchange deployments, on-premise gateways, and older filtering appliances — very often block remote images by default for senders outside the organisation. That is a sensible security posture, not a misconfiguration: it stops senders from confirming an address is live and from learning when and where a message was viewed.

The consequence for you is that the message can be delivered, opened and read by a human, and still record no open at all. On an audience made up mostly of company addresses, a low open rate is frequently a fact about their IT policy rather than about your email. In the extreme — a list of business domains on legacy infrastructure — the rate can sit near zero while the campaign is performing normally.

Over-reporting — an open with no reader

Apple Mail Privacy Protection fetches remote images for messages sent to users who have it enabled, whether or not anyone ever looks at the message. Those opens are recorded and they are not engagement. Gmail separately routes every image through its own proxy and caches it, so an open there is logged at Google's fetch rather than at the moment a person read anything. Some security gateways also retrieve message content for scanning, which can register as an open before the message reaches a mailbox.

So a consumer-heavy list tends to read higher than reality, and a business list lower. Comparing the open rates of two campaigns sent to different audiences mostly compares their mail infrastructure.

What to steer on instead

  • Clicks are the real signal. A click is an HTTP request the recipient deliberately made. It cannot be manufactured by a prefetch and it does not depend on images being allowed — which is why a campaign with no opens and no clicks tells you something a campaign with no opens alone does not.
  • Replies, for business audiences. On B2B and outbound, reply rate is the metric that survives all of the above intact.
  • Bounces and complaints, always. These are reported by the receiving server, not inferred from a fetch, so they are accurate in every mode — including off. They are also the numbers that decide whether you keep reaching inboxes at all.

One thing an open never tells you is where the message landed. A message can be accepted by the receiving server and filed in a spam folder; delivery reporting says it was accepted, and that is all it says. If you suspect placement rather than engagement, test with real mailboxes at the providers your recipients actually use — no analytics can answer it from our side.

Where we cannot measure something, we say so rather than reporting a zero. A campaign sent with essential shows opens without an open rate; one sent with off reads Not tracked rather than 0%. See Deliverability essentials for the parts of this you can act on.

Why Essential exists

Regulators in France (the CNIL) and Italy (the Garante) treat the email open pixel as consent-gated under ePrivacy law — with a narrow exemption for deliverability and list-hygiene measurement if the stored data is minimized. essential is that minimized shape: the open date is retained (day-granular, last-open only, no time and no per-open history), which is enough to keep engagement segments and inactive-subscriber sunsetting working, without keeping behavioural open-time analytics. Clicks are unaffected. It's the middle ground between full analytics and going dark — measure your list's health, drop the surveillance.

Setting the mode

The effective mode is resolved per message → per campaign → workspace default:

  • Workspace default — Settings → Workspace → Open tracking. Applies to everything unless overridden.
  • Per campaign — the campaign editor's Open tracking control (inherits the workspace default unless you change it).
  • Per message (API) — the optional tracking field on POST /send and each item of POST /send/batch. Omit it to inherit the workspace default.
"color:#ff7b72">import { PristineSend } "color:#ff7b72">from "pristinesend"

"color:#ff7b72">const ps = "color:#ff7b72">new PristineSend(process.env.PRISTINESEND_API_KEY!)

// Send this one message with reduced (day-level) open tracking.
// Omit `tracking` to inherit your workspace default.
"color:#ff7b72">await ps.emails.send({
  to: "reader@example.com",
  subject: "Your weekly digest",
  html: "<p>…</p>",
  tracking: "essential", // "full" | "essential" | "off"
})

Off availability

off requires a dedicated events-only sending configuration, so it's available on request rather than on by default. Until your account is enabled for it, a send requesting off is rejected with 503 service_unavailable — nothing is sent, and in a batch only the off items fail while the rest deliver. PristineSend never silently falls back to tracking-on when you ask for off. Contact support to turn it on.

// Requesting "off" before your account is enabled for it:
{
  "error": {
    "code": "service_unavailable",
    "message": "Open-tracking mode 'off' is not available on this account yet.",
    "request_id": "req_…"
  }
}
// HTTP 503. In a batch, only the "off" items fail this way; the rest still send.

What reads and webhooks see

Every email row carries an open_tracking_mode field (see the email object) so a reader can interpret opened_at/clicked_at correctly:

Modeopened_atclicked_atWebhook events
fullFull timestamp (first open)Full timestampemail.opened, email.clicked
essentialDay-granular date (midnight UTC)Full timestampemail.opened (day-granular), email.clicked
offnull — not trackednull — not trackedneither fires

A null opened_at under off means "not tracked", not "not opened" — the open_tracking_mode field is how you tell them apart. See Webhooks for the event-level detail.