TL;DR
- Apple's Mail Privacy Protection (MPP), shipped September 2021, pre-fetches every image in an email — including the invisible tracking pixel — through Apple's own proxy the moment the message is delivered. You get an "open" whether or not a human ever saw the message.
- It hits cold email exactly as hard as marketing email. MPP triggers based on the app the recipient reads in, not the platform you sent from — a 1:1 send from Google Workspace or Microsoft 365 is just as exposed as a bulk newsletter the moment it lands in Apple Mail.
- Litmus's own rolling report (1B+ tracked opens/month) put Apple Mail/MPP at ~56% of all opens in May 2025, trending toward ~65% a year later (directional — blended consumer+marketing volume, not a B2B-cold-outbound-specific measurement, and the number moves monthly).
- Click tracking is NOT directly broken by MPP — it only pre-fetches images, it doesn't pre-click links. But don't trust clicks blindly either: Microsoft's Safe Links can auto-scan and pre-click every link in Outlook/M365 mail before a human opens it.
- What still works: reply rate, positive-reply rate, meetings booked, bounce rate, and unsubscribe rate — all require a real human action a proxy can't fake. Rebuild any "no opens in 7 days" re-engagement trigger around clicks or replies instead, and consider turning the open pixel off entirely.
If your cold email dashboard still shows a 45–60% open rate and you've been treating that as a real engagement number, it isn't one. Apple quietly rewired how "open" gets recorded for well over half of tracked email, and most cold-email content either ignores it or gets the mechanism wrong — usually by confusing it with a completely different Apple privacy feature that behaves differently.
Sourcing note: technical mechanism and dates below are verified against Apple's own documentation and established deliverability authorities (Litmus, Word to the Wise, Postmark). Exact inflation percentages and B2B-specific breakouts are single-sourced or blended-audience figures and are flagged (directional) — nobody publishes a cold-outbound-only version of this number. One commonly repeated claim (that MPP-fabricated opens can register from messages sitting in spam/junk) could not be verified from any primary source, so it is explicitly not asserted as fact here.
The Short Answer
Open rate is not a usable metric for cold email anymore. Apple Mail Privacy Protection fetches every tracking pixel through Apple's own proxy servers within moments of delivery, regardless of whether a human ever opens the message — so any list with meaningful Apple Mail share (which is most B2B lists) reports an inflated, largely fictional open rate. Click tracking survives the actual MPP mechanism intact, but it has its own, unrelated contamination from Microsoft's Safe Links pre-scanning. The metrics that still mean something are reply rate, positive-reply rate, meetings booked, bounce rate, and unsubscribe rate — none of them can be faked by a client-side image fetch. If you haven't already, turn off open tracking in your sending tool: the data is unreliable, and the pixel itself is an independent, pre-existing deliverability liability that has nothing to do with Apple.
What Apple Mail Privacy Protection Actually Does
Apple announced Mail Privacy Protection at WWDC on June 7, 2021, and shipped it with iOS 15, iPadOS 15, macOS Monterey, and watchOS 8 that September. Apple's own description: MPP "stops senders from using invisible pixels to collect information about the user," helps users "prevent senders from knowing when they open an email," and "masks their IP address so it can't be linked to other online activity or used to determine their location."
The mechanism, per consistent third-party technical writeups: when MPP is enabled, Apple Mail pre-loads every remote image in a message — the header logo, the product screenshot, and the invisible 1x1 tracking pixel — through Apple's own proxy servers shortly after the message is delivered to the device. This happens automatically, before the recipient has done anything. When the person eventually opens the email (if they ever do), Apple Mail serves the images from its own cache, not from your tracking server. Your server only ever sees Apple's proxy fetch it once, on delivery.
The practical result: a sender can log a "100% open" from a recipient who deleted the email unread, moved it to a folder without reading it, or never opened Apple Mail again that week. Opened and read are now two different events, and you can only measure the first one.
MPP is opt-in, but adoption is effectively universal. Apple presents it as a single prominent toggle the first time a user opens Mail after upgrading, and most people accept the default. There's no published adoption-rate study, but the aggregate open-share numbers below only make sense if the overwhelming majority of Apple Mail users have it turned on.
Does MPP Hit Cold Email the Same Way It Hits Marketing Email?
Yes — and this is the point most cold-email content skips because it's copied from marketing-email sources. MPP triggers based on which app the recipient uses to read the message, not on how or where the message was sent. It doesn't check whether you sent through a bulk ESP, a cold-email platform like Smartlead or Instantly, or a plain SMTP connection from Google Workspace or Microsoft 365. If your prospect opens your 1:1, hand-personalized cold email in the Apple Mail app on their iPhone with MPP enabled, the exact same proxy pre-fetch fires. There is no "this is a real 1:1 send" exemption.
The corollary matters for interpreting your own numbers: if a lead reads your email through a Gmail-hosted inbox using the native Gmail app or Gmail's webmail, MPP doesn't apply at all — Google's own decade-old image proxy does instead (more on that below), with a different distortion profile. Which privacy layer touches your tracking pixel depends entirely on the client the recipient opens the message in, not on your sending stack.
How Big Is This, Really?
Litmus tracks over a billion email opens a month and publishes a rolling market-share report. As of May 2025 it put Apple Mail Privacy Protection at roughly 56% of all tracked opens; pulling the same live report a year later shows Apple's total share (iPhone Mail, iPad Mail, Apple Mail, and MPP combined) trending toward roughly 65%. Two caveats worth keeping in mind before you repeat either number:
- It's a blended, mostly consumer/marketing sample — newsletters, receipts, and B2C sends alongside B2B mail. Nobody publishes a cold-outbound-only breakout, and B2B inboxes skew somewhat more toward Outlook/Microsoft 365 than the general population, so treat any specific percentage you apply to your own cold-email list as directional, not measured.
- It's a rolling figure that keeps moving — Litmus's own number shifted roughly 8–9 points across a year. Cite it with the access date you pulled it, not as a fixed constant.
You'll also see figures elsewhere — including in a few of our own deliverability posts — citing "roughly half" or a 15–40 percentage-point inflation range. Those are consistent with the direction of the Litmus data (Apple Mail is a majority-plurality of opens and MPP fabricates a large share of them) but come from different, less rigorously sourced aggregations. Treat all of them as pointing the same way rather than as competing precise numbers.
Three Privacy Features Get Confused Constantly — Here's the Real Difference
This is the single most common error in MPP content, including a lot of vendor blog posts: treating Apple Mail Privacy Protection, Apple's iCloud Private Relay, and Google's Gmail image proxy as the same thing, or as one feature causing all your tracking problems. They're three separate mechanisms, they break different metrics, and one of them (Gmail's) predates MPP by nearly eight years.
| Feature | Launched | What it actually does | What it breaks |
|---|---|---|---|
| Apple Mail Privacy Protection | Sept 2021 (iOS 15 / macOS Monterey) | Pre-fetches all remote images (including tracking pixels) via Apple's proxy on delivery | Open rate, CTOR, open-based A/B tests, "no opens in X days" triggers |
| iCloud Private Relay | Sept 2021 (separate opt-in, Safari/system-wide) | Masks the IP address behind a real click or page load | Geolocation on real clicks — does not fabricate clicks that never happened |
| Gmail image proxy | Dec 2013 | Routes all remote images through Google's own proxy (googleusercontent.com), caching the first fetch | Open IP/location (always shows Google's IP); can under-count real re-opens after the first cached fetch |
| Microsoft Safe Links | Defender for Office 365 feature, ongoing | Automatically scans (and can pre-click) links in Outlook/M365 mail before the human does | Click tracking — generates false-positive clicks on Microsoft 365 recipients |
Get the first two straight in particular: MPP fakes opens; Private Relay does not fake clicks, it just hides who clicked from where. A lot of "MPP broke my click tracking" claims are actually describing Private Relay's IP-masking, or Safe Links' pre-scanning — a different vendor, a different mechanism, and in Safe Links' case, a different company entirely.
What Breaks (and What Doesn't)
Open rate — dead as a decision metric
Any campaign or contact reporting a suspiciously high open rate on a cold-email list is mostly measuring Apple's proxy, not human attention. There is no reliable adjustment you can apply after the fact to back out the "real" number, because MPP doesn't inflate opens by a fixed percentage — it fires on delivery for a large, variable share of your list depending on how many recipients use Apple Mail with MPP enabled.
Click-to-open ratio (CTOR) — artificially collapses
CTOR divides clicks by opens. MPP inflates the denominator (opens) without touching the numerator (clicks) — proxy-triggered fetches never click anything. The result is a CTOR that trends downward over time purely as an artifact of rising MPP adoption, with zero relationship to whether your copy or offer got worse.
A/B testing on subject lines using open rate — produces false winners
Both variants in a subject-line test get inflated by MPP's near-universal proxy-open, so the "lift" you measure is largely noise layered on top of noise. This is exactly why our A/B testing guide and subject line guide both tell you to test reply rate, not open rate — this post is the deeper explanation of why that rule exists.
"No opens in X days" re-engagement and sunset automations — broken
Re-engagement and list-sunset logic that triggers off "hasn't opened in 14/30/60 days" assumes non-openers are disengaged. Under MPP, most Apple Mail recipients register a false open within seconds of delivery whether they're engaged or not — so the segment that should be shrinking (genuinely cold contacts) never separates cleanly from the segment that's actually still reading. Deliverability platforms including WordFly and Bloomreach explicitly warn that open-based automations are no longer reliable post-MPP and recommend rebuilding suppression and re-engagement logic around click activity, replies, or time-since-last-send instead.
Click tracking — mostly intact, but not clean either
This is the nuance almost everyone gets wrong in one direction or the other. MPP itself only pre-fetches images — it does not pre-click links, so a genuine click in your tracking data reflects a genuine click. But two separate mechanisms can still contaminate click data: Apple's iCloud Private Relay (a different, separately-toggled feature) masks the IP address behind a real click, removing geolocation without fabricating the click; and Microsoft's Safe Links, active on Outlook and Microsoft 365 mailboxes with Defender for Office 365, automatically scans — and in doing so can trigger — every link in an incoming email, including tracking and unsubscribe links, independent of whether the human recipient ever opens the message. For a B2B list with meaningful Microsoft 365 share, that means some fraction of your "clicks" are Microsoft's scanner, not your prospect.
Net take on clicks: more reliable than opens, not immune to bot activity. Filter out clicks that land within a few seconds of delivery — that's the timing signature of an automated scanner, not a human reading an email and deciding to click.
The Metrics That Still Work
Everything below requires an actual human action that a client-side image fetch or security scanner can't fabricate — that's the dividing line.
| Metric | Still reliable? | Why |
|---|---|---|
| Open rate | ❌ No | Apple's proxy fetches the pixel on delivery regardless of a human open |
| Click-to-open ratio | ❌ No | Denominator (opens) is inflated; numerator (clicks) isn't |
| Click rate | ⚠️ Mostly | Not touched by MPP directly; filter for Safe Links bot-speed clicks |
| Reply rate / positive-reply rate | ✅ Yes | Requires a human-composed response; no proxy can fake this |
| Meetings booked | ✅ Yes | Downstream, human-driven conversion event |
| Bounce rate | ✅ Yes | SMTP-level rejection, unrelated to client-side rendering |
| Unsubscribe / opt-out rate | ✅ Yes | Requires an explicit human click on a real link, not an image fetch |
Reply rate and positive-reply rate should be your primary cold-email KPIs now, benchmarked against our 2026 outbound benchmarks. One caveat worth adding to "reply rate is unhackable": raw reply counts still get polluted by out-of-office autoresponders and bounce misclassification, so track positive reply rate — human-qualified replies — not raw reply volume.
Should You Turn Off Open Tracking for Cold Email?
Most cold-email platforms — Smartlead, Instantly, and Lemlist among them — offer a toggle to disable the open-tracking pixel entirely, and several explicitly recommend doing so for cold outbound. Apollo's own guidance states plainly that post-MPP, open rate alone is an unreliable north-star metric, and recommends shifting to reply rate and meetings-booked-per-thousand-delivered as the primary KPIs instead.
There are two separate reasons to turn it off, and it's worth keeping them apart:
- The data is now mostly noise. That's the MPP story above.
- The tracking pixel is an independent, pre-existing deliverability signal — a foreign tracking domain and redirect embedded in your email that spam filters can weigh negatively, a concern that predates MPP entirely and has nothing to do with Apple.
Combined, the case for disabling open tracking on cold sends is straightforward: you lose data that was already unreliable, and you remove a signal spam filters can penalize. Keep tracking on only if a specific downstream workflow depends on the open event and you've accepted the noise — for most cold-email programs, there isn't one. Our deliverability monitoring guide covers the dashboards worth watching instead, and warmup tooling covers the reputation side this interacts with.
If You Keep Open Tracking On, Filter the Noise
Some teams keep the pixel active for other reasons — a legacy report, a client contract that specifies open rate, a rotation tool that uses it as one input among several. If that's you, two practitioner-level filters reduce (not eliminate) the noise:
- Timing filter. Flag opens (and clicks) occurring within a few seconds of delivery as likely bot/proxy/scanner activity rather than genuine engagement, and treat opens that arrive minutes or hours later, especially alongside a click, as more likely real (directional — a common practitioner heuristic, not a validated universal threshold).
- IP cross-reference. Apple publishes the current IP ranges used by iCloud Private Relay, which some deliverability tools cross-reference to flag opens or clicks originating from Apple's relay infrastructure rather than a real device IP.
Neither filter gets you back to a trustworthy open rate — they reduce the contamination, they don't remove it. Reply rate remains the metric that doesn't need filtering in the first place.
Where to Start This Week
- Pull up your last 90 days of cold-email reporting and mentally strike out the open-rate column — stop making decisions off it today, before you change any tooling.
- Audit any automation that triggers on "no opens in X days" — re-engagement, list sunsetting, lead scoring decay — and rebuild the trigger around clicks, replies, or elapsed send time instead.
- Re-run your next subject-line test scoring on reply rate, not open rate, per our A/B testing guide.
- Check whether your sending tool lets you disable the open pixel, and turn it off unless something specific depends on it.
- Make reply rate and positive-reply rate the numbers you report upward, benchmarked against 2026 outbound benchmarks — and if replies are healthy but meetings aren't converting, that's a reply-handling problem, not a tracking problem.
Frequently Asked Questions
What is Apple Mail Privacy Protection (MPP)?
MPP is a privacy feature Apple shipped with iOS 15, iPadOS 15, and macOS Monterey in September 2021. When enabled, Apple Mail pre-loads every remote image in a message — including invisible tracking pixels — through Apple's own proxy servers shortly after delivery, and masks the recipient's IP address. This makes it impossible for a sender to know whether or when a recipient actually opened the email.
Does Apple Mail Privacy Protection affect cold email the same way it affects marketing newsletters?
Yes. MPP triggers based on the app the recipient uses to read a message, not on how or where it was sent. A 1:1 cold email sent from Google Workspace or Microsoft 365 is exposed to MPP identically to a bulk marketing send, as long as the recipient opens it in the Apple Mail app with MPP enabled.
Does MPP affect click tracking in cold email campaigns?
Not directly. MPP only pre-fetches images; it does not pre-click links, so a genuine click in your data reflects a genuine click. Click data can still be distorted by two unrelated mechanisms: Microsoft's Safe Links, which can auto-scan and pre-click links in Outlook/Microsoft 365 mail before a human opens it, and Apple's iCloud Private Relay, a separate opt-in feature that masks the IP address behind a real click without fabricating the click itself.
What percentage of email opens now come from Apple Mail?
Litmus, which tracks over a billion opens a month, put Apple Mail Privacy Protection at roughly 56% of all tracked opens in its May 2025 report, trending toward roughly 65% a year later. That figure is blended across marketing and B2B email broadly — no authority publishes a cold-outbound-specific breakout — and it shifts month to month, so treat any number you quote as directional and dated.
What metrics should cold email teams track instead of open rate?
Reply rate, and specifically positive-reply rate, is the primary metric — it requires a genuine human-written response that no proxy can fake. Meetings booked, bounce rate, and unsubscribe rate are also reliable. Click rate is next-best but should be filtered for near-instant bot or security-scanner activity before you trust it.
Should I turn off open tracking entirely in my cold email tool?
For most cold-email programs, yes. Smartlead, Instantly, and Lemlist all let you disable the open-tracking pixel. The data it produces is largely unreliable post-MPP, and the tracking pixel itself is an independent, pre-existing deliverability signal — a foreign tracking domain embedded in your email — that spam filters can weigh negatively regardless of Apple's privacy features. Keep it on only if a specific workflow still depends on the open event.
If your reporting still leans on open rate, the fix isn't a new tool — it's re-pointing your dashboards at the metrics that survived MPP. Start with deliverability monitoring and 2026 reply-rate benchmarks, or talk to our team and we'll rebuild your cold email measurement around signals that hold up.
By the GenFlows GTM engineering team. Apple's MPP mechanism and launch date are verified against Apple's own documentation; Litmus market-share figures are verified against Litmus's published, methodology-stated report as of the access date noted above but change monthly. Inflation percentages, bot-timing heuristics, and B2B-specific open shares are directional and not independently measured by us. This is not legal advice. Last updated August 2026.
The GenFlows team builds AI-powered cold outbound systems for B2B teams.