Tells you when an email you sent has been opened, through a tracking pixel and a browser extension that shows ticks in the inbox.
Build me email tracking that replaces Mailtrack — and read the first paragraph before you decide to, because this one deserves an argument rather than a specification. Read this first. This category tells you when somebody opened your message, using a pixel they did not agree to and cannot see. It is surveillance of a private act, it is why mail clients now block remote images by default, and in several jurisdictions doing it without consent is unlawful. The numbers it produces are also largely fictional now: privacy proxies pre-fetch every image, so a large share of 'opens' are a machine, and a genuine reader with images off never registers at all. So build the version that is defensible — link tracking on your own domain, aggregate reporting, and consent where it is required — and skip the pixel, or use it knowing exactly what it is. STACK - Node 20+ with Fastify - SQLite through better-sqlite3, WAL mode - A browser extension if you want the status inside your inbox, talking only to your own server - Caddy in front THE DATA MODEL - messages: id, external_message_id, subject, to_hash, sent_at, campaign, consent_basis, tracking_kind - links: id, message_id, original_url, token, position - clicks: id, link_id, at, ip_hash, user_agent_bucket, is_probable_bot - opens: id, message_id, at, ip_hash, user_agent_bucket, is_probable_proxy — only if you decide to use a pixel at all - Recipients stored as a salted hash unless you have a reason to hold the address, and the reason written down LINK TRACKING, WHICH IS THE DEFENSIBLE PART - Every link rewritten through your own short domain and redirected with a 302, never a 301 — a permanent redirect cached in a client can never be corrected - The redirect answers in a couple of milliseconds and records after responding - A click is a real action taken by a person. Unlike an open, it means something - Bot filtering: security scanners in corporate mail follow every link in a message within seconds of delivery. Discard clicks that arrive implausibly fast, that come from a datacentre range, or that hit every link in one message at once — otherwise your click rate is measuring an antivirus product - Never rewrite an unsubscribe link, and never rewrite a mailto IF YOU USE A PIXEL AT ALL - Say so in the message. One line in the footer stating that opens are recorded — that is what turns this from surveillance into telemetry - Treat the number as a lower bound with a wide margin, and label it that way everywhere it appears - Discard opens that arrive within a second of sending, from known proxy ranges, or repeatedly from the same address hash in a burst - Never a per-recipient notification saying somebody just read your message. That is the feature that makes people uncomfortable, and it is the one worth leaving out CONSENT AND THE LAW - For marketing mail in the EU and the UK, tracking is processing personal data and needs a lawful basis, usually consent gathered at signup - Record the basis per recipient, with the date and the wording they agreed to - A recipient who asks not to be tracked is not tracked, and that preference outranks every campaign setting - One-click unsubscribe in every message, and the List-Unsubscribe headers - This is not legal advice; get some before running this against a real list WHAT TO REPORT - Clicks per link, per message, per campaign, unique and total, with the bot filtering applied and the count of what was filtered shown - Opens, if collected, in aggregate only, with the caveat printed beside the number - Trends over time, which are more meaningful than any single figure - Never a screen that shows one named person's reading behaviour. Aggregate is enough for every decision this data supports THE EXTENSION, IF YOU BUILD ONE - Reads your own server, shows status beside a thread, and talks to nothing else - No permission wider than the one host it needs - Say in its own description exactly what it does and what it sends WHAT TO REFUSE TO BUILD - Notifications when a specific person opens a message - Location from the opener's address, which is inaccurate and creepy in equal measure - Reading duration, which is guesswork dressed as data - Any of it applied to a personal message. A newsletter is a broadcast; a message to one colleague is a conversation, and instrumenting a conversation is a different thing entirely OPERATIONS - .env: DATABASE_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, SHORT_DOMAIN - Migrations on boot, each once - A stated retention with a sweeper that actually deletes - Nightly backup off the machine, restore script - Health endpoint WHAT MATTERS MOST Bot filtering and the honesty of the numbers. Build link tracking with the scanner filter first, and put the caveat next to every figure. If you build the thing well, you will find you have replaced a product that promised certainty with one that tells you the truth — which is less satisfying and considerably more useful. Give me the repository, migrations, .env.example, the link rewriter, and a README that opens with the argument above and states the legal position for the places you operate.
What you lose
- A browser extension that puts the status inside Gmail, which is where the information is useful
- Link click tracking alongside opens
- Somebody keeping the extension working as the inbox changes
If you would rather not build
- A pixel and a redirect, which is what everyone does
- Your mail provider's own tracking
- Not tracking opens, which is a legitimate choice
What it costs
as published on their pricing page
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $4.99/mo | — | — |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Postal
$0A self-hosted mail platform that records delivery and engagement.
postalserver/postalfree · open source
Why this verdict
our own opinion · changed only by a person
86/100
Verdict yes at 86. A pixel and a redirect. The important part is being honest that open tracking is a weak, easily wrong signal.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Mailtrack
answered from the record above
Is Mailtrack free?
No — the plan we track is $4.99 a month. Pro at around $4.99/month billed monthly, cheaper annually.
Can you replace Mailtrack by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 86 out of 100, build time one session. Read what you lose before you decide.
How much does Mailtrack cost?
$4.99 a month on Pro — $59.88 a year. Recorded 10 Aug 2026.
What do you lose by replacing Mailtrack?
A browser extension that puts the status inside Gmail, which is where the information is useful; Link click tracking alongside opens; Somebody keeping the extension working as the inbox changes. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Mailtrack?
Yes: Listmonk, Postal. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

