Apple Mail Privacy Protection inflated opens. Track clicks you trust, replies, conversions, and complaints. Here is how we classify a click.
I still look at open rate. I just don't let it pick the winner.
In June 2021 Apple said Mail Privacy Protection would stop senders from using invisible pixels to learn when a person opened a message, and would mask the IP so it couldn't be tied to other activity or a location. Their privacy write-up is more mechanical. Protect Mail Activity downloads remote content in the background when the message arrives, whether or not anyone engages with it.
If you still make list and creative decisions on opens alone, you may be reacting to a prefetch rather than a reader.
Apple's Mail Privacy Protection, in the Mail app on iOS 15 and later, hides the recipient's IP and prefetches images, including the tracking pixel most ESPs still use. The prefetch can fire whether or not anyone opened the message.
Apple does not publish the share of mail that hits MPP. You can see the effect in your own data. Unique opens step up after a list picks up more Apple Mail, and clicks stay flat. That pattern is a reason to investigate the measurement before attributing the change to creative.
Other clients prefetch too. The honest position is this: an open is a hint that a client fetched a pixel. It is not evidence that a person read the subject, let alone the body.
| Signal | What it can tell you | What it cannot |
|---|---|---|
| Click classified as human | Likely interest in a link | Classification can be wrong; a click does not prove completion |
| Click-to-open | Useless if opens are inflated | Do not use this ratio on an MPP-heavy list |
| Reply | Feedback or a conversation to inspect | Automatic replies need to be filtered |
| Conversion | The intended action happened | Attribution alone does not prove the email caused it |
| Unsubscribe / complaint | The mail cost you trust | Complaints are the one Gmail will throttle you on |
Gmail's bulk-sender page is explicit about spam rate. Stay under 0.1%, and treat 0.3% as a hard ceiling. That number belongs on the same dashboard as revenue, not in a deliverability appendix.
Bots click. Prefetchers click. Some security gateways open every URL in a message.
Our rule on the Brew side is simple. A click we believe is a real person must never be labeled a bot. We'd rather leave a suspicious click in the human bucket than throw away a customer who used a strict corporate filter.
The reverse is allowed. Strong automated patterns can be excluded from "human clicks." Classification is still an estimate, not proof of who followed the link. That bias is deliberate. A vanity bot-rate feels good in a screenshot and lies in a report to finance.
If your ESP lets you choose the bias the other way, know that you're optimizing a chart, not a decision.
For a campaign, I want four numbers in this order:
Opens can sit on row five, labeled as pixel fetches. Use abrupt changes as a prompt to investigate rendering, audience composition, or tracking. The pattern alone does not diagnose the cause.
I stopped killing variants on open rate. I stopped calling a 40% open "healthy" without looking at clicks. I stopped reporting click-to-open to anyone who still thinks the denominator is people.
The email either moved the job you wrote down, or it didn't. The pixel will not tell you.
Name the job in the brief before you look at a chart. For inbox placement, use email deliverability. For the legal split that changes which headers you send, use transactional emails.
