posted by VaelMail · 11 October 2026
email tracking and remote images.
why a picture can reveal an open, how vael handles message images, and which privacy choices still belong to you.
an email can contain a picture that is downloaded from the sender’s server when you read it. the picture may be a product photo, a logo, or a tiny tracking pixel. its address can also contain a unique identifier for the recipient.
when that address is requested, the remote server can learn that the image was fetched. that is why vael blocks message-body remote images until you allow them.
read first, load pictures when useful.
you can read the available message text without fetching its remote pictures. sender html and css are sanitized and isolated. scripts, forms, external stylesheets and web fonts stay blocked in the message view.
if a picture is useful, approve it for the message. vael fetches approved remote images through its server, without sending your browser ip, cookies or referrer to the image host.
that proxy has a limit: the remote host can still observe the fetch. a unique image address can still identify which recipient’s copy was requested. loading through vael is not a promise that a sender cannot infer an open.
check your image settings.
open mail settings and find privacy. message images can be set to always block or ask before loading. choose the setting that fits how you read mail, and remember that approving an image is a separate decision from opening the message itself.
website icons are a different feature. vael fetches domain-level icons through its server and keeps a shared cache. these requests do not include your account or message identifier. you can turn website icons off in settings without changing the message-image setting.
links have their own tracking.
blocking a pixel doesn’t remove a tracking identifier from a link. following a link can tell the destination which email or account it came from, especially if you sign in there.
read the destination before opening an unexpected link. for a message asking you to sign in or resolve a payment problem, visiting the service through a bookmark or an address you already know can avoid trusting the email’s link. don’t enter your vael account number into a page reached through an unexpected message.
attachments are separate too. opening a file outside webmail gives the program you use its own role in handling that file. a blocked image in the email does not make its attachment safe.
choose what belongs on the device.
local draft recovery is off by default. if you enable it, unsaved message content is stored in that browser so it can help with recovery. think about this before enabling it on a shared device.
a separate mail app has its own image, storage and download settings. webmail’s controls do not automatically apply to copies you read in another app. review those settings when you connect a mail app.
for the full picture, read the privacy policy and what we store. the useful habit is simple: read the message, decide whether the remote content is needed, and approve it with the limits in mind.