{"id":13069,"date":"2026-08-28T16:10:15","date_gmt":"2026-08-28T14:10:15","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/toolbox\/email-tracking-pixel-auditor\/"},"modified":"2026-08-28T16:10:15","modified_gmt":"2026-08-28T14:10:15","slug":"email-tracking-pixel-auditor","status":"publish","type":"page","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/","title":{"rendered":"Email Tracking Pixel and Remote Content Auditor"},"content":{"rendered":"<div class=\"gtm-analyser-container\" style=\"background: var(--bg-panel, #1e1e24); padding: 25px; border-radius: 8px; border: 1px solid var(--border, #2a2a35);\">\n<p style=\"color: var(--text-secondary, #a0a0b0); margin-bottom: 20px;\">A tracking pixel is an image one pixel across, fetched from a server the moment a message is opened. That fetch is the whole legal matter: it happens on the reader&#039;s own device. This lists every remote resource an email carries, separates the ones that reach a server from the ones that do not, and marks the addresses that carry an identifier tying the open to a single recipient.<\/p>\n<div style=\"margin-bottom: 14px;\">\n        <label for=\"ep-quelle\" style=\"color: var(--text-secondary, #a0a0b0); display: block; font-size: 0.85rem; margin-bottom: 5px;\">Email source, the HTML part of the message<\/label><br \/>\n        <textarea id=\"ep-quelle\" rows=\"10\" class=\"form-control\" style=\"width: 100%; padding: 10px; background: var(--bg-body, #14141a); border: 1px solid var(--border, #2a2a35); color: var(--text-primary, #e8e8ee); border-radius: 6px; box-sizing: border-box; font-family: monospace; font-size: 0.8rem;\"><\/textarea>\n    <\/div>\n<p style=\"color: var(--text-secondary, #a0a0b0); font-size: 0.82rem; margin-bottom: 16px;\">The source is parsed with DOMParser. The document that produces has no browsing context: it loads nothing and runs nothing, so inspecting an email here does not trigger the very pixels being looked for. Nothing is transmitted or stored. The legal notes reflect the CNIL recommendation of 14 April 2026 and its FAQ of 22 July 2026.<\/p>\n<p>    <button id=\"ep-btn\" class=\"button\" style=\"background: var(--accent, #7ee787); color: var(--on-accent, #0b1114); border: none; padding: 12px 24px; border-radius: 6px; font-weight: 700; cursor: pointer;\">Inspect<\/button><\/p>\n<div id=\"ep-ausgabe\" style=\"margin-top: 22px;\"><\/div>\n<\/div>\n<p><script>\n(function () {\n    'use strict';<\/p>\n<p>    const T = {\"einleitung\":\"A tracking pixel is an image one pixel across, fetched from a server the moment a message is opened. That fetch is the whole legal matter: it happens on the reader\\u0027s own device. This lists every remote resource an email carries, separates the ones that reach a server from the ones that do not, and marks the addresses that carry an identifier tying the open to a single recipient.\",\"label_quelle\":\"Email source, the HTML part of the message\",\"datenschutz\":\"The source is parsed with DOMParser. The document that produces has no browsing context: it loads nothing and runs nothing, so inspecting an email here does not trigger the very pixels being looked for. Nothing is transmitted or stored. The legal notes reflect the CNIL recommendation of 14 April 2026 and its FAQ of 22 July 2026.\",\"knopf\":\"Inspect\",\"beispiel\":\"\\u003Chtml\\u003E\\n\\u003Cbody style=\\u0022background-image:url(https:\\\/\\\/cdn.newsletter.example.net\\\/bg\\\/paper.png)\\u0022\\u003E\\n\\u003Cp\\u003EHello,\\u003C\\\/p\\u003E\\n\\u003Cimg src=\\u0022https:\\\/\\\/cdn.newsletter.example.net\\\/logo.png\\u0022 width=\\u0022180\\u0022 height=\\u002240\\u0022 alt=\\u0022Logo\\u0022\\u003E\\n\\u003Cimg src=\\u0022data:image\\\/gif;base64,R0lGODlhAQABAAAAACw=\\u0022 width=\\u002212\\u0022 height=\\u002212\\u0022 alt=\\u0022dot\\u0022\\u003E\\n\\u003Cimg src=\\u0022cid:signature-block-1\\u0022 width=\\u0022200\\u0022 height=\\u002260\\u0022 alt=\\u0022Signature\\u0022\\u003E\\n\\u003Cp\\u003ERead the \\u003Ca href=\\u0022https:\\\/\\\/click.newsletter.example.net\\\/ls\\\/click?upn=aGVsbG8tdGVzdC1yZWNpcGllbnQtaWQ\\u0022\\u003Efull article on example.com\\u003C\\\/a\\u003E.\\u003C\\\/p\\u003E\\n\\u003Cp\\u003E\\u003Ca href=\\u0022https:\\\/\\\/example.com\\\/unsubscribe?email=anna.beispiel%40example.org\\u0022\\u003EUnsubscribe\\u003C\\\/a\\u003E\\u003C\\\/p\\u003E\\n\\u003Cimg src=\\u0022https:\\\/\\\/open.newsletter.example.net\\\/o\\\/9f2c1ab47de35061c8b04f2a?e=anna.beispiel%40example.org\\u0022 width=\\u00221\\u0022 height=\\u00221\\u0022 alt=\\u0022\\u0022\\u003E\\n\\u003C\\\/body\\u003E\\n\\u003C\\\/html\\u003E\",\"h_zusammenfassung\":\"Summary\",\"zeile_abrufe\":\"Fetches on open\",\"zeile_hosts\":\"Distinct hosts contacted\",\"zeile_zaehlpixel\":\"Invisible images\",\"zeile_kennung\":\"Addresses carrying an identifier\",\"zeile_umschrieben\":\"Wrapped links\",\"zeile_ohne_abruf\":\"Embedded, no fetch\",\"h_ressourcen\":\"Remote resources\",\"spalte_art\":\"Kind\",\"spalte_host\":\"Host\",\"spalte_masse\":\"Size\",\"spalte_befund\":\"Finding\",\"art_img\":\"Image\",\"art_srcset\":\"Image, srcset\",\"art_rahmen\":\"Frame\",\"art_medien\":\"Media\",\"art_stil\":\"Stylesheet\",\"art_hintergrund\":\"Background image\",\"schema_data\":\"embedded, data:\",\"schema_cid\":\"attached, cid:\",\"schema_relativ\":\"relative, unreachable\",\"befund_kein_abruf\":\"reaches no server\",\"befund_zaehlpixel\":\"invisible: a beacon, not a picture\",\"befund_abruf\":\"fetch on open\",\"befund_verweis\":\"link\",\"befund_umschrieben\":\"wrapped: the visible host is not the target\",\"befund_kennung_mailadresse\":\"carries the recipient address\",\"befund_kennung_parameter\":\"carries a recipient parameter\",\"befund_kennung_brocken\":\"carries an opaque per-recipient token\",\"h_verweise\":\"Links\",\"spalte_text\":\"Visible text\",\"spalte_ziel\":\"Target host\",\"h_hinweise\":\"Notes\",\"hinweis_keine_eingabe\":\"Nothing to inspect yet - the source of the message goes in the field above.\",\"hinweis_kein_abruf\":\"No remote resource. Opening this message reaches no server, so nothing is read from the reader\\u0027s device and Article 5(3) has nothing to bite on.\",\"hinweis_zugriff\":\"Every fetch above happens on the reader\\u0027s terminal equipment the moment the message is opened. That is what makes it access under Article 5(3) of the ePrivacy Directive - the image being decorative changes nothing about the mechanism.\",\"hinweis_ausnahme_leer\":\"Two exemptions exist: strictly necessary for transmission, and strictly necessary for a service the reader explicitly asked for. The CNIL FAQ of 22 July 2026 closes the second for anything that collects the IP address or the user agent - and every HTTP fetch transmits both by construction. That is why the exemption is nearly empty in practice rather than merely narrow.\",\"hinweis_zaehlpixel\":\"An image of one pixel, or one hidden by its style, is not there to be seen. Its only effect is the fetch, which is the measurement.\",\"hinweis_kennung\":\"At least one address carries something that identifies a single recipient. That turns a count of opens into a record of who opened, which is a different processing operation and needs its own basis.\",\"hinweis_viele_hosts\":\"More than one host learns that this message was opened: {hosts}. Each is a separate recipient of that fact.\",\"hinweis_umschrieben\":\"At least one link points somewhere other than the host its text names. The redirect records the click before passing the reader on; the visible address is not the one contacted first.\",\"hinweis_kennung_verweis\":\"No fetch carries an identifier, but a link does. Click measurement then still ties an action to a person, even though opening the message on its own does not.\",\"hinweis_ohne_abruf\":\"Resources embedded as data: or attached as cid: reach no server. They are the way to show a picture without measuring anything.\",\"hinweis_b2b\":\"Business contacts are not exempt. The recommendation covers messages to professional addresses in the same way as to private ones.\",\"hinweis_frist\":\"The grace period the CNIL granted ended on 14 July 2026, so the recommendation applies rather than merely being announced.\",\"hinweis_ausserhalb\":\"This is a French authority\\u0027s reading of a European directive. The directive applies across the Union; how strictly each authority reads it does not, so the conclusion travels further than the enforcement does.\",\"hinweis_lokal\":\"This inspection ran entirely in the browser and fetched none of the addresses listed above.\"};<\/p>\n<p>    \/\/ =========================================================================\n    \/\/ Hilfsfunktionen ueber einzelne Adressen\n    \/\/ =========================================================================<\/p>\n<p>    \/** Host einer Adresse, ohne dass dabei etwas abgerufen wird. *\/\n    function hostAus(adresse) {\n        var a = String(adresse == null ? '' : adresse).replace(\/^\\s+|\\s+$\/g, '');\n        if (!a.length) { return null; }\n        if (\/^(data|cid|mailto|tel):\/i.test(a)) { return null; }\n        var m = a.match(\/^[a-zA-Z][a-zA-Z0-9+.\\-]*:\\\/\\\/([^\\\/?#]+)\/);\n        if (m) { return m[1].toLowerCase().replace(\/^.*@\/, '').replace(\/:\\d+$\/, ''); }\n        if (\/^\\\/\\\/\/.test(a)) {\n            var p = a.slice(2).split(\/[\\\/?#]\/)[0];\n            return p ? p.toLowerCase().replace(\/:\\d+$\/, '') : null;\n        }\n        return null; \/\/ relative Adressen erreichen in einer E-Mail nichts\n    }<\/p>\n<p>    function schema(adresse) {\n        var a = String(adresse == null ? '' : adresse).replace(\/^\\s+\/, '');\n        var m = a.match(\/^([a-zA-Z][a-zA-Z0-9+.\\-]*):\/);\n        return m ? m[1].toLowerCase() : (\/^\\\/\\\/\/.test(a) ? 'https' : null);\n    }<\/p>\n<p>    \/**\n     * Traegt die Adresse eine Kennung, die sie an eine einzelne Empfaengerin\n     * bindet? Drei Spuren: eine Mailadresse, ein sprechender Parametername,\n     * ein langer undurchsichtiger Brocken.\n     *\/\n    function kennungVerdaechtig(adresse) {\n        var a = String(adresse == null ? '' : adresse);\n        if (!a.length) { return null; }\n        var entschluesselt = a;\n        try { entschluesselt = decodeURIComponent(a); } catch (e) { entschluesselt = a; }<\/p>\n<p>        if (\/[A-Za-z0-9._%+\\-]+@[A-Za-z0-9.\\-]+\\.[A-Za-z]{2,}\/.test(entschluesselt)) { return 'mailadresse'; }\n        if (\/[?&](email|e|mail|addr|address|recipient|rcpt|subscriber|sid|uid|rid|mid|cid|contact)=\/i.test(a)) { return 'parameter'; }<\/p>\n<p>        \/\/ Lange Brocken in Pfad oder Parameterwert, die wie eine Kennung aussehen.\n        var teile = a.replace(\/^[a-zA-Z][a-zA-Z0-9+.\\-]*:\\\/\\\/[^\\\/?#]*\/, '').split(\/[\\\/?&=#]+\/);\n        for (var i = 0; i < teile.length; i++) {\n            var t = teile[i];\n            if (t.length < 16) { continue; }\n            if (\/^[0-9a-fA-F]{16,}$\/.test(t)) { return 'brocken'; }\n            if (\/^[A-Za-z0-9_\\-]{20,}$\/.test(t) &#038;&#038; \/[0-9]\/.test(t) &#038;&#038; \/[A-Za-z]\/.test(t)) { return 'brocken'; }\n            if (\/^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\/.test(t)) { return 'brocken'; }\n        }\n        return null;\n    }\n\n    \/** Masse aus Attributen und Inline-Stil. Ein Pixel oder null heisst unsichtbar. *\/\n    function masse(element) {\n        function lesen(wert) {\n            if (wert === null || wert === undefined) { return null; }\n            var m = String(wert).match(\/^\\s*(\\d+(?:\\.\\d+)?)\\s*(px)?\\s*$\/i);\n            return m ? Number(m[1]) : null;\n        }\n        var stil = element.getAttribute('style') || '';\n        function ausStil(name) {\n            var re = new RegExp(name + '\\\\s*:\\\\s*([^;]+)', 'i');\n            var m = stil.match(re);\n            return m ? lesen(m[1]) : null;\n        }\n        var breite = ausStil('width');\n        var hoehe = ausStil('height');\n        if (breite === null) { breite = lesen(element.getAttribute('width')); }\n        if (hoehe === null) { hoehe = lesen(element.getAttribute('height')); }\n        var versteckt = \/display\\s*:\\s*none\/i.test(stil) || \/visibility\\s*:\\s*hidden\/i.test(stil);\n        var winzig = (breite !== null &#038;&#038; breite <= 1) || (hoehe !== null &#038;&#038; hoehe <= 1);\n        return { breite: breite, hoehe: hoehe, unsichtbar: versteckt || winzig };\n    }\n\n    \/\/ =========================================================================\n    \/\/ Zerlegung\n    \/\/ =========================================================================\n\n    \/**\n     * Zerlegt die Quelle mit DOMParser. Das dabei entstehende Dokument hat\n     * keinen Browsing-Kontext: es laedt nichts nach und fuehrt nichts aus.\n     * Genau deshalb darf ein Pruefer dieser Art ueberhaupt existieren.\n     *\/\n    function analysieren(quelle) {\n        var text = String(quelle == null ? '' : quelle);\n        var ressourcen = [];\n        var verweise = [];\n\n        if (!text.replace(\/\\s\/g, '').length) {\n            return { ressourcen: ressourcen, verweise: verweise, leer: true };\n        }\n        if (typeof DOMParser === 'undefined') {\n            return { ressourcen: ressourcen, verweise: verweise, leer: true, kein_parser: true };\n        }\n\n        var dok = new DOMParser().parseFromString(text, 'text\/html');\n\n        function aufnehmen(typ, adresse, element) {\n            var a = String(adresse == null ? '' : adresse).replace(\/^\\s+|\\s+$\/g, '');\n            if (!a.length) { return; }\n            var s = schema(a);\n            var host = hostAus(a);\n            var m = element ? masse(element) : { breite: null, hoehe: null, unsichtbar: false };\n            var abruf = host !== null;\n            ressourcen.push({\n                typ: typ,\n                url: a,\n                host: host,\n                schema: s,\n                abruf: abruf,\n                breite: m.breite,\n                hoehe: m.hoehe,\n                unsichtbar: m.unsichtbar,\n                kennung: abruf ? kennungVerdaechtig(a) : null,\n                rolle: (typ === 'img' &#038;&#038; m.unsichtbar) ? 'zaehlpixel' : typ\n            });\n        }\n\n        Array.prototype.forEach.call(dok.querySelectorAll('img'), function (e) {\n            aufnehmen('img', e.getAttribute('src'), e);\n            var srcset = e.getAttribute('srcset');\n            if (srcset) {\n                srcset.split(',').forEach(function (teil) {\n                    aufnehmen('srcset', teil.replace(\/^\\s+|\\s+$\/g, '').split(\/\\s+\/)[0], e);\n                });\n            }\n        });\n        Array.prototype.forEach.call(dok.querySelectorAll('iframe, frame'), function (e) {\n            aufnehmen('rahmen', e.getAttribute('src'), e);\n        });\n        Array.prototype.forEach.call(dok.querySelectorAll('video, audio, source, embed'), function (e) {\n            aufnehmen('medien', e.getAttribute('src'), e);\n        });\n        Array.prototype.forEach.call(dok.querySelectorAll('link[href]'), function (e) {\n            var rel = (e.getAttribute('rel') || '').toLowerCase();\n            if (rel.indexOf('stylesheet') !== -1 || rel.indexOf('icon') !== -1 || rel.indexOf('preload') !== -1) {\n                aufnehmen('stil', e.getAttribute('href'), e);\n            }\n        });\n\n        \/\/ Hintergrundbilder: aus Inline-Stilen, aus background-Attributen und\n        \/\/ aus \n\n<style>-Bloecken. url(...) mit und ohne Anfuehrungszeichen.\n        function urlsAus(css, element) {\n            var re = \/url\\(\\s*['\"]?([^'\")]+)['\"]?\\s*\\)\/gi;\n            var m;\n            while ((m = re.exec(css)) !== null) { aufnehmen('hintergrund', m[1], element); }\n        }\n        Array.prototype.forEach.call(dok.querySelectorAll('[style]'), function (e) {\n            urlsAus(e.getAttribute('style') || '', e);\n        });\n        Array.prototype.forEach.call(dok.querySelectorAll('[background]'), function (e) {\n            aufnehmen('hintergrund', e.getAttribute('background'), e);\n        });\n        Array.prototype.forEach.call(dok.querySelectorAll('style'), function (e) {\n            urlsAus(e.textContent || '', null);\n            var imp = \/@import\\s+(?:url\\(\\s*)?['\"]?([^'\")\\s;]+)\/gi;\n            var m2;\n            while ((m2 = imp.exec(e.textContent || '')) !== null) { aufnehmen('stil', m2[1], null); }\n        });<\/p>\n<p>        \/\/ Verweise: sichtbarer Text gegen Ziel.\n        Array.prototype.forEach.call(dok.querySelectorAll('a[href]'), function (e) {\n            var href = String(e.getAttribute('href') || '').replace(\/^\\s+|\\s+$\/g, '');\n            if (!href.length) { return; }\n            var s = schema(href);\n            if (s === 'mailto' || s === 'tel') { return; }\n            var zielHost = hostAus(href);\n            var text = (e.textContent || '').replace(\/\\s+\/g, ' ').replace(\/^\\s+|\\s+$\/g, '');\n            var textHost = null;\n            var mm = text.match(\/(?:https?:\\\/\\\/)?((?:[a-z0-9\\-]+\\.)+[a-z]{2,})\/i);\n            if (mm) { textHost = mm[1].toLowerCase(); }\n            verweise.push({\n                href: href,\n                host: zielHost,\n                text: text.slice(0, 60),\n                textHost: textHost,\n                umschrieben: !!(textHost && zielHost && textHost !== zielHost),\n                kennung: zielHost ? kennungVerdaechtig(href) : null\n            });\n        });<\/p>\n<p>        return { ressourcen: ressourcen, verweise: verweise, leer: false };\n    }<\/p>\n<p>    \/\/ =========================================================================\n    \/\/ Bewertung\n    \/\/ =========================================================================<\/p>\n<p>    function bewerten(befund) {\n        var b = befund || { ressourcen: [], verweise: [], leer: true };\n        var ressourcen = b.ressourcen || [];\n        var verweise = b.verweise || [];<\/p>\n<p>        var abrufe = ressourcen.filter(function (r) { return r.abruf; });\n        var ohneAbruf = ressourcen.filter(function (r) { return !r.abruf; });\n        var hosts = [];\n        abrufe.forEach(function (r) { if (hosts.indexOf(r.host) === -1) { hosts.push(r.host); } });\n        var zaehlpixel = abrufe.filter(function (r) { return r.rolle === 'zaehlpixel'; });\n        var mitKennung = abrufe.filter(function (r) { return !!r.kennung; });\n        var umschrieben = verweise.filter(function (v) { return v.umschrieben; });\n        var verweiseMitKennung = verweise.filter(function (v) { return !!v.kennung; });<\/p>\n<p>        var hinweise = [];\n        if (b.leer) {\n            hinweise.push('keine_eingabe');\n        } else if (!abrufe.length) {\n            hinweise.push('kein_abruf');\n        } else {\n            hinweise.push('zugriff');\n            hinweise.push('ausnahme_leer');\n            if (zaehlpixel.length) { hinweise.push('zaehlpixel'); }\n            if (mitKennung.length) { hinweise.push('kennung'); }\n            if (hosts.length > 1) { hinweise.push('viele_hosts'); }\n        }\n        if (umschrieben.length) { hinweise.push('umschrieben'); }\n        if (verweiseMitKennung.length && !mitKennung.length) { hinweise.push('kennung_verweis'); }\n        if (ohneAbruf.length) { hinweise.push('ohne_abruf'); }\n        \/\/ Die rechtliche Einordnung haengt am Abruf. Eine Nachricht, die\n        \/\/ keinen ausloest, braucht sie nicht - dort waere sie Rauschen.\n        if (abrufe.length) {\n            hinweise.push('b2b');\n            hinweise.push('frist');\n            hinweise.push('ausserhalb');\n        }\n        hinweise.push('lokal');<\/p>\n<p>        return {\n            ressourcen: ressourcen,\n            verweise: verweise,\n            abrufe: abrufe,\n            ohneAbruf: ohneAbruf,\n            hosts: hosts,\n            zaehlung: {\n                abrufe: abrufe.length,\n                hosts: hosts.length,\n                zaehlpixel: zaehlpixel.length,\n                mitKennung: mitKennung.length,\n                umschrieben: umschrieben.length,\n                ohneAbruf: ohneAbruf.length,\n                verweise: verweise.length\n            },\n            hinweise: hinweise\n        };\n    }<\/p>\n<p>    \/\/ --- Pruefpunkt ----------------------------------------------------------\n    window.LW_TEST = window.LW_TEST || {};\n    window.LW_TEST.EP = {\n        analysieren: analysieren,\n        bewerten: bewerten,\n        hostAus: hostAus,\n        schema: schema,\n        kennungVerdaechtig: kennungVerdaechtig,\n        T: T\n    };<\/p>\n<p>    \/\/ =========================================================================\n    \/\/ Oberflaeche\n    \/\/ =========================================================================<\/p>\n<p>    var btn = document.getElementById('ep-btn');\n    var out = document.getElementById('ep-ausgabe');\n    if (!btn || !out) { return; }<\/p>\n<p>    var feld = document.getElementById('ep-quelle');\n    if (feld && !feld.value) { feld.value = T.beispiel; }<\/p>\n<p>    function el(tag, stil, text) {\n        var e = document.createElement(tag);\n        if (stil) { e.setAttribute('style', stil); }\n        if (text !== undefined) { e.textContent = text; }\n        return e;\n    }<\/p>\n<p>    var UEBERSCHRIFT = 'font-family: \"Nunito Sans\", sans-serif; font-weight: 700; color: var(--text-primary, #e8e8ee); font-size: 0.92rem; margin: 18px 0 8px;';\n    var ZELLE = 'padding: 5px 12px 5px 0; color: var(--text-secondary, #a0a0b0); font-size: 0.87rem;';\n    var ZELLE_WERT = 'padding: 5px 12px 5px 0; color: var(--text-primary, #e8e8ee); font-size: 0.87rem; font-family: monospace; word-break: break-all;';\n    var GUT = ' color: #7ee787;';\n    var WARN = ' color: #ffa94d;';\n    var GRAU = ' color: #8a8a99;';<\/p>\n<p>    function gitter(spalten) {\n        return el('div', 'display: grid; grid-template-columns: ' + spalten + '; gap: 0 18px; align-items: baseline;');\n    }\n    function paar(g, name, w, stil) {\n        g.appendChild(el('div', ZELLE, name));\n        g.appendChild(el('div', ZELLE_WERT + (stil || ''), w));\n    }\n    function kopf(g, spalten) {\n        spalten.forEach(function (s) {\n            g.appendChild(el('div', ZELLE + ' font-weight: 700; color: var(--text-primary, #e8e8ee);', s));\n        });\n    }<\/p>\n<p>    btn.addEventListener('click', function () {\n        var feldWert = feld ? feld.value : '';\n        var erg = bewerten(analysieren(feldWert));\n        out.innerHTML = '';<\/p>\n<p>        \/\/ --- Zusammenfassung ---\n        out.appendChild(el('div', UEBERSCHRIFT, T.h_zusammenfassung));\n        var g = gitter('auto auto');\n        paar(g, T.zeile_abrufe, String(erg.zaehlung.abrufe), erg.zaehlung.abrufe ? WARN : GUT);\n        paar(g, T.zeile_hosts, String(erg.zaehlung.hosts), erg.zaehlung.hosts > 1 ? WARN : '');\n        paar(g, T.zeile_zaehlpixel, String(erg.zaehlung.zaehlpixel), erg.zaehlung.zaehlpixel ? WARN : GUT);\n        paar(g, T.zeile_kennung, String(erg.zaehlung.mitKennung), erg.zaehlung.mitKennung ? WARN : GUT);\n        paar(g, T.zeile_umschrieben, String(erg.zaehlung.umschrieben), erg.zaehlung.umschrieben ? WARN : GUT);\n        paar(g, T.zeile_ohne_abruf, String(erg.zaehlung.ohneAbruf), GRAU);\n        out.appendChild(g);<\/p>\n<p>        \/\/ --- Ressourcen ---\n        if (erg.ressourcen.length) {\n            out.appendChild(el('div', UEBERSCHRIFT, T.h_ressourcen));\n            var r = gitter('auto auto auto auto');\n            kopf(r, [T.spalte_art, T.spalte_host, T.spalte_masse, T.spalte_befund]);\n            erg.ressourcen.forEach(function (x) {\n                r.appendChild(el('div', ZELLE, T['art_' + x.typ] || x.typ));\n                r.appendChild(el('div', ZELLE_WERT + (x.abruf ? '' : GRAU),\n                    x.abruf ? x.host : (T['schema_' + (x.schema || 'relativ')] || x.schema || '-')));\n                r.appendChild(el('div', ZELLE_WERT,\n                    (x.breite === null && x.hoehe === null) ? '-'\n                        : ((x.breite === null ? '?' : x.breite) + ' x ' + (x.hoehe === null ? '?' : x.hoehe))));\n                var befund = !x.abruf ? T.befund_kein_abruf\n                    : (x.rolle === 'zaehlpixel' ? T.befund_zaehlpixel\n                        : (x.kennung ? T['befund_kennung_' + x.kennung] : T.befund_abruf));\n                r.appendChild(el('div', ZELLE + (!x.abruf ? GRAU : (x.rolle === 'zaehlpixel' || x.kennung ? WARN : '')), befund));\n            });\n            out.appendChild(r);\n        }<\/p>\n<p>        \/\/ --- Verweise ---\n        if (erg.verweise.length) {\n            out.appendChild(el('div', UEBERSCHRIFT, T.h_verweise));\n            var v = gitter('auto auto auto');\n            kopf(v, [T.spalte_text, T.spalte_ziel, T.spalte_befund]);\n            erg.verweise.forEach(function (x) {\n                v.appendChild(el('div', ZELLE, x.text || '-'));\n                v.appendChild(el('div', ZELLE_WERT, x.host || '-'));\n                var befund = x.umschrieben ? T.befund_umschrieben\n                    : (x.kennung ? T['befund_kennung_' + x.kennung] : T.befund_verweis);\n                v.appendChild(el('div', ZELLE + (x.umschrieben || x.kennung ? WARN : ''), befund));\n            });\n            out.appendChild(v);\n        }<\/p>\n<p>        \/\/ --- Hinweise ---\n        out.appendChild(el('div', UEBERSCHRIFT, T.h_hinweise));\n        var liste = el('ul', 'margin: 0 0 0 18px; padding: 0; color: var(--text-secondary, #a0a0b0); font-size: 0.87rem; line-height: 1.65;');\n        erg.hinweise.forEach(function (h) {\n            var text = T['hinweis_' + h];\n            if (!text) { return; }\n            liste.appendChild(el('li', '', text.replace('{hosts}', erg.hosts.join(', '))));\n        });\n        out.appendChild(liste);\n    });\n})();\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lists everything in an email that reaches a server the moment the message is opened: invisible pixels, background images, wrapped links and the identifiers that tie an open to one person. Parsing happens locally and fetches nothing.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":38,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-tool-base.php","meta":{"footnotes":""},"tags":[91279,91270,91516],"class_list":["post-13069","page","type-page","status-publish","hentry","tag-prywatnosc-danych-pl","tag-gdpr","tag-tracking"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog\" \/>\n<meta property=\"og:description\" content=\"Lists everything in an email that reaches a server the moment the message is opened: invisible pixels, background images, wrapped links and the identifiers that tie an open to one person. Parsing happens locally and fetches nothing.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/email-tracking-pixel-auditor\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/email-tracking-pixel-auditor\\\/\",\"name\":\"Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-08-28T14:10:15+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/email-tracking-pixel-auditor\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/email-tracking-pixel-auditor\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/email-tracking-pixel-auditor\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Toolbox\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Email Tracking Pixel and Remote Content Auditor\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"luky\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"luky\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/","og_locale":"en_US","og_type":"article","og_title":"Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog","og_description":"Lists everything in an email that reaches a server the moment the message is opened: invisible pixels, background images, wrapped links and the identifiers that tie an open to one person. Parsing happens locally and fetches nothing.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/","og_site_name":"Lukas Wojcik - Blog","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/","name":"Email Tracking Pixel and Remote Content Auditor - Lukas Wojcik - Blog","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"datePublished":"2026-08-28T14:10:15+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-tracking-pixel-auditor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Toolbox","item":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/"},{"@type":"ListItem","position":3,"name":"Email Tracking Pixel and Remote Content Auditor"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"luky","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"luky"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/13069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=13069"}],"version-history":[{"count":0,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/13069\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/38"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=13069"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=13069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}