A pixel tracker is a piece of surveillance technology so small it's effectively invisible. It's a single image, often just one pixel wide, embedded in an email or a web page. When your device loads that image, it sends a signal back to whoever planted it. That signal can confirm when you opened an email, what device you used, your approximate location, and even your IP address. It all happens in a fraction of a second, without your knowledge, and without a single tick box or consent prompt.
Pixel trackers are sometimes called "tracking pixels", "spy pixels", or "web beacons". The technology itself is decades old, but its use has expanded dramatically as marketers, advertisers, and data brokers have built increasingly sophisticated systems around it.
How a pixel tracker actually works
Every image on a web page or in an HTML email is loaded from a server. When your browser or email client fetches that image, the request carries metadata: your IP address, your browser type, your operating system, and a timestamp. A tracking pixel exploits this mechanism. The image itself is meaningless. The data in the request is everything.
The pixel is typically hosted on the sender's server, or on a third-party analytics server. When it loads, the server logs the request. Marketers use this to measure whether an email campaign was opened. Advertisers use it to confirm that someone saw an ad. Data brokers use it to stitch together profiles across multiple websites. The pixel doesn't need cookies to work, which makes it harder to block through standard cookie controls. It's worth reading about what cookies actually do in your browser to understand why pixels fill in the gaps that cookie-blocking leaves open.
Most people can't see a tracking pixel. It renders as blank space, or it doesn't render at all if it's transparent. The sender doesn't need to disclose it. In many jurisdictions, including parts of Australia, disclosure requirements for tracking pixels in emails remain vague or weakly enforced.
Who uses pixel trackers and why
Email marketing platforms are the most common users. Services like Mailchimp, HubSpot, and Campaign Monitor embed tracking pixels by default in every campaign. When a newsletter reports an "open rate", those numbers come from pixel data. A 42% open rate means 42% of recipients loaded the tracking image.
Advertisers use pixels to measure conversions. The Meta Pixel is one of the most widely deployed examples. It sits on millions of websites and sends data back to Meta whenever a visitor lands on a page, adds a product to a cart, or completes a purchase. That data lets advertisers retarget the same users on Facebook and Instagram. It also feeds into Meta's broader profile of your interests and behaviour across the web, whether or not you have a Facebook account.
Governments and political campaigns have also used pixel trackers in mass email communications. In 2021, a BBC investigation found that hundreds of organisations, including political parties, news outlets, and charities, were embedding spy pixels in emails without disclosure.
What data a tracking pixel can collect
A single pixel request can reveal more than most people realise. The data it captures includes:
- Your IP address, which can be used to approximate your city or suburb
- The date and time you opened the email or visited the page
- Your email client or browser (Chrome, Outlook, Apple Mail, etc.)
- Your device type and operating system
- How many times you opened the same email
When a tracker is embedded in multiple emails or pages and linked to a unique identifier, it builds a timeline. A company can see that the same person opened 14 emails over six months, on an iPhone in Sydney, usually between 7am and 9am. That's a detailed behavioural profile from what most people assume is a passive act: reading their inbox.
How pixel tracking interacts with other surveillance tools
Pixel trackers don't operate in isolation. They're frequently combined with cookies, device fingerprinting, and login data to build cross-platform profiles. A website might use a tracking pixel alongside a cookie to match your anonymous browsing session to a known email address the moment you log in. Understanding how encryption protects your data matters here, because even encrypted connections don't prevent the tracking pixel request from carrying your IP address to the host server.
Apple introduced Mail Privacy Protection in iOS 15 (released in 2021), which pre-fetches email images through a proxy server. This masks the user's real IP address and prevents accurate open-time tracking. It was a significant disruption to email marketing analytics. Email open rates across many platforms jumped artificially by 20 to 40 percentage points after the feature rolled out, because Apple's proxy loads the images regardless of whether the user actually opens the email.
Google added similar protections to Gmail. But these measures help primarily with email. Web-based tracking pixels embedded in websites still function normally in most browsers unless you use an ad blocker with specific tracking protection rules.
How to protect yourself from pixel trackers
A few practical steps reduce your exposure significantly. Set your email client to block remote images by default. In most apps this is a single toggle in the privacy or display settings. Apple Mail, Outlook, and Thunderbird all support it. The trade-off is that emails with genuine images won't display them automatically, but most content remains readable as text.
For web browsing, browser extensions that block trackers go further than standard cookie controls. uBlock Origin, for example, maintains filter lists that include known tracking pixel domains. The EFF's Privacy Badger learns which domains behave like trackers and blocks them automatically. A VPN can mask your IP address from pixel requests, though it doesn't stop the request from being made.
No single measure eliminates all tracking. Pixel trackers remain effective against users who take no action. The companies deploying them have little incentive to change, because the data they collect has real commercial value. Australian privacy law reform discussions in 2024 and 2025 included proposals to tighten rules around covert tracking, but the regulatory position continues to lag behind the technology.
Understanding what pixel trackers are is the first step. They're not exotic hacking tools. They're standard practice, built into the infrastructure of modern digital marketing, sitting quietly inside emails you read every morning.

