
Tracking pixel
A tracking pixel is a tiny, usually invisible image embedded in a webpage or email whose retrieval tells the sender that and when someone opened the page or message. It is one of the oldest and most widely used tools for measuring user behavior on the internet.
A tracking pixel is an extremely small image hidden in a webpage or an email. Most of the time it is exactly one pixel in size and transparent. So you can’t see it. Its purpose isn’t its appearance anyway, but rather the request: for your device to display the image, it first has to download it from a server on the internet. At exactly that moment, the operator of that server learns that you have opened the page or the message. The image itself carries no information — the information arises simply from the fact that it is requested at all.
Why advertisers rely on the invisible image
Anyone running ads on the internet wants to know whether the money paid off. A tracking pixel supplies the numbers for that. An online shop, for instance, can measure how many people actually bought something after clicking on an ad. Without this feedback, digital advertising would be flying blind. Large parts of the business models of Google, Meta, and many smaller providers depend on such measurements.
With emails, it’s about a different metric: the open rate. Newsletter senders want to know how many recipients even looked at their message. Salespeople also use this to see whether an offer was read. For recipients this is often surprising, because opening an email feels like a private act.
This is exactly where the dispute arises. Privacy advocates see tracking pixels as surveillance without consent. The European General Data Protection Regulation, GDPR for short, requires explicit consent for many such measurements. German courts have already ruled against companies for using pixels in newsletters without permission.
What actually happens when the pixel loads
In the source code of a page there is a normal image command that points to an external address. This address often already contains an ID number that belongs specifically to you or to that one email. Your browser or your mail program retrieves the address. The remote server logs the timestamp, the ID number, and sends the tiny image back. You notice nothing.
Along the way, your device reveals further details with every such request. These include the IP address, i.e., the number identifying your internet connection, as well as your operating system and browser version. The approximate location can be derived from the IP address. A single request reveals little. But many requests across different websites add up to a movement profile.
A common misconception is that tracking pixels and cookies are the same thing. A cookie is a small file that is stored on your device. A pixel stores nothing on your device at all; it merely triggers a request. In practice, the two often work together: the pixel provides the occasion, the cookie provides recognition. Because browsers are now blocking cookies more aggressively, pixels and similar techniques are gaining importance again.
Where you encounter counting pixels every day
Practically every major website embeds at least one such pixel, often several dozen. Well-known examples are the Meta Pixel for Facebook and Instagram advertising, as well as comparable components from Google and TikTok. News sites also use them to measure reach. Whenever a cookie banner asks for your consent, it is almost always about this technology as well.
In the news, tracking pixels mostly come up in connection with fines and lawsuits. Authorities check whether companies obtained consent correctly. Violations can become expensive, because the GDPR allows for high penalties. There have also been cases involving health insurers and clinics, since particularly sensitive data was involved there.
You can protect yourself with simple measures. Many mail programs only load external images after an explicit click, and Apple Mail additionally hides the IP address. Browser extensions and privacy-focused browsers block known pixel addresses. However, the technology won’t disappear entirely, because today’s advertising-driven internet doesn’t work without measurement.