Mailtrack

mailtrack.iocontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

Tells you when an email you sent has been opened, through a tracking pixel and a browser extension that shows ticks in the inbox.

Promptfree, for everyone, and the only version there is
Build me email tracking that replaces Mailtrack — and read the first paragraph before you decide to, because this one deserves an argument rather than a specification.

Read this first. This category tells you when somebody opened your message, using a pixel they did not agree to and cannot see. It is surveillance of a private act, it is why mail clients now block remote images by default, and in several jurisdictions doing it without consent is unlawful. The numbers it produces are also largely fictional now: privacy proxies pre-fetch every image, so a large share of 'opens' are a machine, and a genuine reader with images off never registers at all. So build the version that is defensible — link tracking on your own domain, aggregate reporting, and consent where it is required — and skip the pixel, or use it knowing exactly what it is.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode
- A browser extension if you want the status inside your inbox, talking only to your own server
- Caddy in front

THE DATA MODEL
- messages: id, external_message_id, subject, to_hash, sent_at, campaign, consent_basis, tracking_kind
- links: id, message_id, original_url, token, position
- clicks: id, link_id, at, ip_hash, user_agent_bucket, is_probable_bot
- opens: id, message_id, at, ip_hash, user_agent_bucket, is_probable_proxy — only if you decide to use a pixel at all
- Recipients stored as a salted hash unless you have a reason to hold the address, and the reason written down

LINK TRACKING, WHICH IS THE DEFENSIBLE PART
- Every link rewritten through your own short domain and redirected with a 302, never a 301 — a permanent redirect cached in a client can never be corrected
- The redirect answers in a couple of milliseconds and records after responding
- A click is a real action taken by a person. Unlike an open, it means something
- Bot filtering: security scanners in corporate mail follow every link in a message within seconds of delivery. Discard clicks that arrive implausibly fast, that come from a datacentre range, or that hit every link in one message at once — otherwise your click rate is measuring an antivirus product
- Never rewrite an unsubscribe link, and never rewrite a mailto

IF YOU USE A PIXEL AT ALL
- Say so in the message. One line in the footer stating that opens are recorded — that is what turns this from surveillance into telemetry
- Treat the number as a lower bound with a wide margin, and label it that way everywhere it appears
- Discard opens that arrive within a second of sending, from known proxy ranges, or repeatedly from the same address hash in a burst
- Never a per-recipient notification saying somebody just read your message. That is the feature that makes people uncomfortable, and it is the one worth leaving out

CONSENT AND THE LAW
- For marketing mail in the EU and the UK, tracking is processing personal data and needs a lawful basis, usually consent gathered at signup
- Record the basis per recipient, with the date and the wording they agreed to
- A recipient who asks not to be tracked is not tracked, and that preference outranks every campaign setting
- One-click unsubscribe in every message, and the List-Unsubscribe headers
- This is not legal advice; get some before running this against a real list

WHAT TO REPORT
- Clicks per link, per message, per campaign, unique and total, with the bot filtering applied and the count of what was filtered shown
- Opens, if collected, in aggregate only, with the caveat printed beside the number
- Trends over time, which are more meaningful than any single figure
- Never a screen that shows one named person's reading behaviour. Aggregate is enough for every decision this data supports

THE EXTENSION, IF YOU BUILD ONE
- Reads your own server, shows status beside a thread, and talks to nothing else
- No permission wider than the one host it needs
- Say in its own description exactly what it does and what it sends

WHAT TO REFUSE TO BUILD
- Notifications when a specific person opens a message
- Location from the opener's address, which is inaccurate and creepy in equal measure
- Reading duration, which is guesswork dressed as data
- Any of it applied to a personal message. A newsletter is a broadcast; a message to one colleague is a conversation, and instrumenting a conversation is a different thing entirely

OPERATIONS
- .env: DATABASE_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, SHORT_DOMAIN
- Migrations on boot, each once
- A stated retention with a sweeper that actually deletes
- Nightly backup off the machine, restore script
- Health endpoint

WHAT MATTERS MOST
Bot filtering and the honesty of the numbers. Build link tracking with the scanner filter first, and put the caveat next to every figure. If you build the thing well, you will find you have replaced a product that promised certainty with one that tells you the truth — which is less satisfying and considerably more useful.

Give me the repository, migrations, .env.example, the link rewriter, and a README that opens with the argument above and states the legal position for the places you operate.

What you lose

  • A browser extension that puts the status inside Gmail, which is where the information is useful
  • Link click tracking alongside opens
  • Somebody keeping the extension working as the inbox changes

If you would rather not build

  • A pixel and a redirect, which is what everyone does
  • Your mail provider's own tracking
  • Not tracking opens, which is a legitimate choice

What it costs

as published on their pricing page

PlanBilled monthlyBilled yearlyLast read
—$4.99/mo——

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Listmonk

$0

Has open and click tracking built in, self-hosted.

knadh/listmonkfree · open source

Postal

$0

A self-hosted mail platform that records delivery and engagement.

postalserver/postalfree · open source

Why this verdict

our own opinion · changed only by a person

86/100

Verdict yes at 86. A pixel and a redirect. The important part is being honest that open tracking is a weak, easily wrong signal.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Mailtrack

answered from the record above

Is Mailtrack free?

No — the plan we track is $4.99 a month. Pro at around $4.99/month billed monthly, cheaper annually.

Can you replace Mailtrack by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 86 out of 100, build time one session. Read what you lose before you decide.

How much does Mailtrack cost?

$4.99 a month on Pro — $59.88 a year. Recorded 10 Aug 2026.

What do you lose by replacing Mailtrack?

A browser extension that puts the status inside Gmail, which is where the information is useful; Link click tracking alongside opens; Somebody keeping the extension working as the inbox changes. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Mailtrack?

Yes: Listmonk, Postal. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 33 in Email & newsletters

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc