Outbound Atlas

Atlas/Deliverability/Practice

Content and tracking

Open rates are now mostly noise (Apple MPP, security scanners, Gmail image caching); link tracking adds a shared-domain liability; plain, short, link-light text with real variation is the 2026 default, and content tricks are what Gmail's classifiers are built to catch.

Deliverabilitymedium confidence8 minupdated 2026-10-0510 sources

Two things changed what "content" means for cold email. First, measurement broke. Apple Mail Privacy Protection, Gmail's image proxy and corporate link scanners make opens and clicks unreliable, and Google says flatly that it "doesn't track open rates" and "can't verify the accuracy of open rates reported by third parties". Second, the classifier got better at the tricks. Gmail's RETVec text model was built to resist "homoglyphs, invisible characters, and keyword stuffing" and lifted spam detection by 38%. The cold-email consensus for 2026 follows from both: short plain text, few or no links, tracking off by default, and variation that changes what the email says rather than how its characters look.

Open tracking is mostly noise

Open tracking works by loading a unique invisible image. Three things now fire that image without a human reading the email:

Litmus data is consumer-skewed

Litmus measures marketing email, so Apple and Gmail dominate. B2B cold email reaches more Outlook and Microsoft 365 clients, where the scanner problem is worse and the MPP problem smaller. No B2B-specific client split was found.

Vendors now say the same. Saleshandy reports a 21% average open rate in H1 2026 and says many platforms show 40–55% "because Apple Mail Privacy Protection and ESP pre-scanning inflate the numbers artificially". Belkins stopped tracking opens and rebuilt its benchmark around sends, saying "the rate tracking pixel was hurting deliverability throughout the industry in 2024".

Does the pixel itself hurt placement?

The claim that tracking pixels lower inbox placement is widespread among practitioners and stated by Belkins. No Google or Microsoft documentation found for this pass says so. The defensible version: the pixel adds a remote image from a third-party (often shared) domain to an otherwise plain email, and that domain's reputation travels with every message.

Click tracking rewrites each link through a redirect on a tracking domain. Two costs:

  1. Shared reputation. Spamhaus checks domains appearing in headers and body, e.g. URLs. A sequencer's default shared tracking domain is one listing away from contaminating every customer's mail. The standard fix is a custom tracking domain (a CNAME on the sender's own domain), so each customer carries only its own risk. See Custom tracking domains.
  2. Polluted data. Safe Links and gateway scanners click links before delivery. Without bot filtering, click-through rates are inflated in exactly the enterprise accounts that matter most.

Google's content guidance adds a third constraint: "Web links in the message body should be visible and easy to understand. Recipients should know what to expect when they click a link." Redirect chains and link shorteners cut against that.

Plain text, HTML, images, attachments

Element2026 practiceWhy
Plain text vs HTMLPlain text or minimal HTMLOne-to-one emails look like plain text. Google warns against using "HTML and CSS to hide content".
LengthShort. Instantly says elite campaigns stay "under 80 words"; Saleshandy says keep first touches "under 100 words".Vendor reply data; also less surface for content classifiers.
Links0–1 in the first touch, none trackedFewer domains to be judged on.
ImagesAvoid in first touchRemote images are tracking-like; Google bans images or emoji near display names that imply verification.
AttachmentsAvoid in cold first touchUnsolicited attachments are the classic malware vector and get extra gateway scanning. Practitioner consensus, not a published rule.
Subject linesNo fake "Re:"/"Fwd:"Google: don't start subjects with Re: or Fwd: "unless the messages are actual replies or forwards".
Display nameReal person, consistentGoogle: display names should be "a consistent, clear, and accurate statement of the sender's identity".

Several once-standard cold-email "growth hacks" (fake reply threads, emoji in sender names, invisible text to break fingerprints) are now named explicitly in Google's guidelines. A platform that offers them is offering policy violations.

Spintax and variation

Spintax ({Hi|Hello|Hey}) exists so that hundreds of mailboxes don't send byte-identical text that a provider can fingerprint. Its value is shrinking for two reasons:

  • Character-level tricks are what RETVec targets. Google built the model to be robust to "homoglyphs, invisible characters" and typos. Swapping synonyms in a template leaves the meaning, and the embedding, nearly unchanged.
  • LLM personalisation produces real variation. Every email that is actually different (different opening fact, different angle) beats a template with spun greetings. Woodpecker claims advanced personalisation reaches "up to 18% vs. ~9% for basic templates" (vendor claim, methodology not published).

See Spintax and message variants and AI personalisation. AI-written text is not a free pass either. Woodpecker blames part of the reply-rate decline on "a flood of low-effort AI-generated outreach", and classifiers are trained on whatever the spam of the day looks like.

What to measure instead

MetricReliability in 2026Use
OpensLowSubject-line A/B at best, and only within one recipient-provider cohort
ClicksLow–mediumOnly with bot/scanner filtering (time-to-click, scanner IP/UA lists)
Replies (all)MediumIncludes auto-replies and out-of-office unless classified
Positive repliesHighRequires reply classification; see AI reply agent and Replies, booking and handoff
Bounces / SMTP codesHighBest real-time deliverability signal; see Reputation and blocklists
MeetingsHighestNeeds calendar/CRM linkage; see CRM sync

What this means for an entrant

  • Ship with open tracking off by default and say why. It is a credible, cheap signal of deliverability seriousness, and it removes a third-party domain from every email. Keep opens as an opt-in, cohort-only subject-line test.
  • If you track clicks, own the bot filter. Scanner-click detection (time-to-click, known scanner ranges, every-link-clicked patterns) is an under-built feature. Without it, click data from Microsoft 365 recipients is mostly fiction.
  • Make custom tracking domains mandatory, not optional, whenever tracking is on. A shared tracking domain is a single point of failure across your whole customer base.
  • Lint copy against Google's named prohibitions. Fake Re:/Fwd:, hidden text, deceptive display names and invisible characters can be detected automatically. Blocking them protects your shared reputation and your relationship with providers.
  • Make positive replies and meetings the primary analytics. Classified replies and meetings are where measurement has moved (see Campaign analytics and Reply benchmarks). A product whose dashboards lead with open rate looks dated to sophisticated buyers.
10 sources cited on this page · 10 domains
  1. doesn't track open rates support.google.com
  2. homoglyphs, invisible characters, and keyword stuffing security.googleblog.com
  3. stops senders from using invisible pixels to collect information about the user apple.com
  4. 62.26% of tracked opens, and says MPP affects roughly 55-60% of all email opens litmus.com
  5. prior to message delivery, regardless of whether the URLs are rewritten learn.microsoft.com
  6. 21% average open rate in H1 2026 and says many platforms show 40–55% because Apple Mail Privacy Protection and ESP pre-scanning inflate the numbers artificially saleshandy.com
  7. the rate tracking pixel was hurting deliverability throughout the industry in 2024 belkins.io
  8. domains appearing in headers and body, e.g. URLs spamhaus.org
  9. under 80 words instantly.ai
  10. up to 18% vs. ~9% for basic templates woodpecker.co