PristineSend lets you choose how much you measure a recipient — per workspace, per campaign, or per message. Three modes trade analytics for privacy: full, essential, and off. Deliverability protection (bounce and complaint handling) is always on regardless of the mode — you only ever change what open and click data is kept.
fullFullPrecise opens and clicks — the default, unchanged.
essentialEssentialDay-level opens, full clicks — minimized analytics that keep list hygiene working.
offOffGatedNo open or click tracking — maximum recipient privacy.
An open is one remote image fetch. When a message is rendered with images enabled, the recipient's mail client requests a tiny tracking image from us, and that request is what we record. That is the entire mechanism, and it is the only one that exists: no email protocol reports back that a message was read. The nearest thing to a standard read receipt (Disposition-Notification-To, RFC 8098) asks the recipient for permission, is ignored by most clients, and is treated as suspicious on bulk mail — so nobody uses it.
Everything sometimes described as an alternative — a background image, a remote web font, a CSS import, your hosted logo — is the same mechanism wearing a different hat. They are all remote fetches, and they all fail in exactly the same circumstances. The pixel is not the industry standard because it is good. It is the standard because it is the only thing there is.
Which means an open rate carries error in both directions, and knowing which one your audience produces is the difference between a useful number and a misleading one.
Business recipients are the common case. Corporate mail systems — Outlook and Exchange deployments, on-premise gateways, and older filtering appliances — very often block remote images by default for senders outside the organisation. That is a sensible security posture, not a misconfiguration: it stops senders from confirming an address is live and from learning when and where a message was viewed.
The consequence for you is that the message can be delivered, opened and read by a human, and still record no open at all. On an audience made up mostly of company addresses, a low open rate is frequently a fact about their IT policy rather than about your email. In the extreme — a list of business domains on legacy infrastructure — the rate can sit near zero while the campaign is performing normally.
Apple Mail Privacy Protection fetches remote images for messages sent to users who have it enabled, whether or not anyone ever looks at the message. Those opens are recorded and they are not engagement. Gmail separately routes every image through its own proxy and caches it, so an open there is logged at Google's fetch rather than at the moment a person read anything. Some security gateways also retrieve message content for scanning, which can register as an open before the message reaches a mailbox.
So a consumer-heavy list tends to read higher than reality, and a business list lower. Comparing the open rates of two campaigns sent to different audiences mostly compares their mail infrastructure.
off. They are also the numbers that decide whether you keep reaching inboxes at all.One thing an open never tells you is where the message landed. A message can be accepted by the receiving server and filed in a spam folder; delivery reporting says it was accepted, and that is all it says. If you suspect placement rather than engagement, test with real mailboxes at the providers your recipients actually use — no analytics can answer it from our side.
Where we cannot measure something, we say so rather than reporting a zero. A campaign sent with essential shows opens without an open rate; one sent with off reads Not tracked rather than 0%. See Deliverability essentials for the parts of this you can act on.
Regulators in France (the CNIL) and Italy (the Garante) treat the email open pixel as consent-gated under ePrivacy law — with a narrow exemption for deliverability and list-hygiene measurement if the stored data is minimized. essential is that minimized shape: the open date is retained (day-granular, last-open only, no time and no per-open history), which is enough to keep engagement segments and inactive-subscriber sunsetting working, without keeping behavioural open-time analytics. Clicks are unaffected. It's the middle ground between full analytics and going dark — measure your list's health, drop the surveillance.
The effective mode is resolved per message → per campaign → workspace default:
tracking field on POST /send and each item of POST /send/batch. Omit it to inherit the workspace default.off requires a dedicated events-only sending configuration, so it's available on request rather than on by default. Until your account is enabled for it, a send requesting off is rejected with 503 service_unavailable — nothing is sent, and in a batch only the off items fail while the rest deliver. PristineSend never silently falls back to tracking-on when you ask for off. Contact support to turn it on.
Every email row carries an open_tracking_mode field (see the email object) so a reader can interpret opened_at/clicked_at correctly:
| Mode | opened_at | clicked_at | Webhook events |
|---|---|---|---|
| full | Full timestamp (first open) | Full timestamp | email.opened, email.clicked |
| essential | Day-granular date (midnight UTC) | Full timestamp | email.opened (day-granular), email.clicked |
| off | null — not tracked | null — not tracked | neither fires |
A null opened_at under off means "not tracked", not "not opened" — the open_tracking_mode field is how you tell them apart. See Webhooks for the event-level detail.