Mail Privacy Protection doesn't block a tracking pixel — it pre-fetches it. Apple Mail downloads every remote image in a message, tracking pixels included, through its own relay infrastructure before a recipient necessarily ever looks at the email. That's why "opened" has become the least trustworthy number in most senders' dashboards, and why this report walks through exactly what MPP does and doesn't touch.
How Mail Privacy Protection actually works
Per Apple's own documentation, once a recipient enables Mail Privacy Protection (on by default since iOS 15 / macOS Monterey), all remote content in a message — images, and anything else Mail would otherwise fetch live — is routed through two separate relays operated by different parties:
- The first relay knows the recipient's real IP address, but never sees the remote content itself.
- The second relay fetches and sees the remote content, but never learns the recipient's IP address.
No single party — not Apple, not the sender — ends up holding both pieces of information at once. The practical effect for a sender: every image request, tracking pixel included, now comes from Apple's own infrastructure rather than the recipient's device or network.
Why open rates go up under MPP
The privacy mechanism alone wouldn't distort open rates — masking an IP address doesn't fabricate an open. The distortion comes from when the fetch happens: Apple pre-fetches a message's images proactively, on its own schedule, independent of whether the recipient ever actually opens or reads it. A tracking pixel fires, gets logged as an open, and that open may correspond to nothing more than the message sitting unread in a folder.
The result is a one-directional bias: MPP can only inflate open counts, never deflate them, and it inflates them by an amount that has nothing to do with genuine recipient engagement.
Gmail's proxy is a milder version of the same idea
Gmail has run its own image caching proxy since December 2013 — every remote image URL gets rewritten to a googleusercontent.com address, masking the recipient's IP address the same way Apple's relays do. The meaningful difference is timing: Gmail's proxy fetches on open rather than pre-fetching ahead of any recipient action, so a first Gmail open still corresponds to a real open. It's a narrower privacy mechanism than MPP, but it establishes the same underlying lesson a decade earlier — image-based tracking has been eroding for longer than Apple's 2021 change alone would suggest.
What still works: interaction-based tracking
MPP pre-fetches passive content — images the message loads automatically, with no recipient action required. It has no equivalent mechanism for content that only exists because a recipient deliberately did something: clicked a link, voted in a poll, submitted a form, completed a quiz, or bought something. Those are real HTTP requests a person's own action triggered, not a background fetch Apple's infrastructure performs on the message's behalf — so they carry exactly the same evidentiary weight under MPP that they did before it existed.
This is the practical case for interactive email over static, image-and-link email as a measurement strategy, not just an engagement one: a poll vote or a quiz completion is a signal MPP cannot inflate, where an open count already can be.
Practical takeaway
- Treat open rate as directional, not precise, for any list with a meaningful share of Apple Mail — which, per The 2026 State of Email Client Rendering, is most consumer lists.
- Weight click-through, poll/quiz completion, form submission, and purchase events more heavily than opens when judging a campaign's real performance.
- Don't compare open rates across time periods or segments with different Apple Mail shares — the MPP-driven inflation isn't constant, so the comparison isn't apples-to-apples (no pun intended).