MailSenseAI

Apple Mail Privacy Protection: What It Broke About Open Tracking

TrackingThe MailSenseAI Team4 min read

Apple Mail Privacy Protection, introduced with iOS 15 and enabled by the great majority of users who saw the prompt, does something specific: it routes remote content in email through Apple’s proxy and pre-loads it on delivery, whether or not the person ever opens the message.

For open tracking, that is close to the worst possible behaviour. It does not block your pixel — it fires it, for everybody, immediately, on messages nobody read.

Open rate is unique opens divided by delivered, times 100. Three things distort that number: mail-provider image prefetching, the sender viewing their own sent copy, and recipients who block images.unique opens÷delivered×100=open ratethree things push this number in either directionImage proxy prefetchprovider loads thepixel before a humanreads itYour own opensviewing your own SentcopyBlocked imagesopen never fires —undercounts
What open rate actually measures — and the three things that distort it.

What it actually does

  • Pre-fetches remote images when mail is delivered to Apple Mail, before any human interaction.
  • Proxies the request, so the IP address belongs to Apple rather than the recipient — location and network data become meaningless.
  • Applies to Apple Mail, on any Apple device. It is about the app, not the address: a Gmail account read in Apple Mail is affected; the same account read in the Gmail app is not.

What it does to your numbers

If a meaningful share of your list reads mail in Apple Mail — and for consumer audiences it is often a third or more — your headline open rate is a blend of real opens and automatic prefetches, weighted toward the prefetches because those happen 100% of the time.

The practical effects, in order of how much trouble they cause:

  1. Open rate inflation. The absolute number is no longer comparable to anything you measured before 2021.
  2. Broken open-based automation. "Send follow-up when opened" fires for people who never looked. If you built a sequence on that trigger, it has been misfiring for years.
  3. Useless geo and device data. Every MPP open reports Apple’s infrastructure.
  4. Distorted send-time optimisation. "Best time to open" analyses are measuring Apple’s delivery schedule, not human behaviour.

How to identify MPP opens

They are identifiable, which is the saving grace. Apple’s proxy announces itself in the request, and the behavioural signature is distinctive:

  • The request comes from Apple’s privacy relay infrastructure, with a recognisable user agent.
  • It arrives very shortly after delivery — often within seconds — regardless of the recipient’s timezone or habits.
  • It happens exactly once per message with machine regularity, rather than in the irregular clusters human reading produces.

Any competent tracker filters these rather than counting them. If your tool reports "opened" for every single recipient within a minute of sending, it is not filtering, and its numbers are decorative.

The uncomfortable consequence

Filtering correctly means that for an Apple Mail recipient you get no open data at all. Not inflated data — none. Their genuine opens are hidden behind the same proxy as the prefetch, so there is no way to separate them.

That is the trade Apple deliberately made, and it is not going to be reversed. It is also why "no opens recorded" is such weak evidence, and why the section on it in email tracking not working in Gmail matters more than it looks.

What to measure instead

MPP does not touch clicks or replies. A click is a real browser navigation initiated by a person; a reply is a person typing. Neither can be manufactured by a prefetch.

  • Clicks. Still fully reliable, with the separate caveat of corporate link scanners — see how email click tracking works.
  • Replies. The only unambiguous signal in email. Weight it above everything else.
  • Repeat opens over days. Even with MPP in the mix, a message opened again on day three from a non-Apple client is meaningful.
  • Open rate as a trend, within a segment. Comparing this month to last month for the same audience still shows you movement, even if the absolute number is inflated.

That reordering — replies first, clicks second, opens as weak corroboration — is the argument we made in an open is not intent, and MPP is the strongest evidence for it.

What to do about your benchmarks

Rebase them. Any open rate benchmark quoting a figure from before 2021, or quoting one now without saying how it handles MPP, is comparing different things. Establish your own baseline for your own list, and track movement rather than the level. The problem with published figures is covered in email open rate benchmarks.

And if you have automation keyed on opens, audit it. A follow-up that fires when a prospect "opens" is, for a third of your list, firing at random — which is worse than sending on a fixed schedule, because it feels responsive while being noise.

MailSenseAI filters Apple prefetches out of its counts rather than reporting them as reads, and weighs clicks and replies above opens when deciding whether a thread is genuinely warm. If you want the mechanics of the whole pipeline, they are in how email open tracking works.

See it in your own inbox

Know what happens after you hit send.

MailSenseAI shows opens, clicks, and replies in real time — right inside Gmail — so you follow up at the moment interest is highest.

Add to Gmail · free