13 ms·
That's not how email works
- renewiltord 8mo agoTracking pixels don’t even work with Gmail because Google fetches them out of band. It doesn’t reveal open rates.
- philipwhiuk 8mo agoWhat do you mean by 'fetches them out of band'?
- CGMthrowaway 8mo agoIt downloads them and stores in serverside cache before you ever open the email
- nkrisc 8mo agoFrankly the best outcome as it makes them useless.
- philipwhiuk 8mo agoThat does mean the email address exists though which was what HSBC was questioning.
- CGMthrowaway 8mo agoSame with Apple Mail
- mike-cardwell 8mo agoApple's system doesn't work. At least not for everyone. https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt_Work https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt...
- wrs 8mo agoThey do work for the inferred purpose here though, assuming Gmail only downloads them when the email is successfully delivered to the mailbox (and thus the address is valid).
- extraduder_ire 8mo agoIIRC, google limits their opening of remote images if they're unique per email or from less reputable sources. They also send you an email back saying your email wasn't delivered after a few days or hours, so there's little benefit in using the tracking pixel to determine if an address exists. Don't know if they fetch images from emails sent to non-existent addresses, but I would if I were to design such a system.
- Almondsetat 8mo agoI mean, they still work in some way. If you use tracking pixels to see if an email was read, I agree with you that this break the functionality. But if you just want to see if the email exists, then the fact that google fetches them (and triggers the parametric URL) still tells you something
- bummy_commenter 8mo agoIt would be better if google also fetched tracking pixels in emails sent to addresses that do not exist.
- renewiltord 8mo agoSo, why use a tracking pixel for that? Just send an email. e.g. $ head -n 100 /dev/random | md5sum a6cc1b7c09ccb122cb066c89e16b3140 - And that yields an instantaneous error message https://i.imgur.com/twHhIU3.png https://i.imgur.com/twHhIU3.png that reads "Address not found. Your message to a6cc1b7c09ccb122cb066c89e16b3140@gmail.com was not delivered because the address could not be found".
- gweinberg 8mo agoTrue, but HSBC thinks you read the email, because somebody fetched the tracking pixel, right? The irony is that HSBC and others who use this kind of thing probably aren't in the least interested in when or how many times you open the email. Whoever came up with this idea (probably) really did think it was (just) a pretty good way of figuring out if they have your correct email.
- jldugger 8mo ago> Gmail because Google fetches them out of band. It doesn’t reveal open rates. "Our open rates have skyrocketed! send more emails!"
- loloquwowndueo 8mo agoWant them to really listen to you? Cancel your accounts - move to another bank. This works well as a bluff, but of course you need to be ready to follow through in case they call the bluff. Which if you are, you may as well switch banks for real anyway.
- direwolf20 8mo agoCancelling costs them no money — banks these days don't make money on customer accounts.
- pfortuny 8mo agoAs long as they keep other people’s money, they make money on it.
- bayesnet 8mo agoThis is arguable for HSBC (in the UK at least). Ringfencing laws post 2008 have made customer deposits in the UK very difficult to invest profitably, to the point where (at least last time I cared about this) they were charging commercial customers to have UK domiciled accounts.
- yjftsjthsd-h 8mo ago> Ringfencing laws post 2008 have made customer deposits in the UK very difficult to invest profitably, to the point where (at least last time I cared about this) they were charging commercial customers to have UK domiciled accounts. I don't follow; why would regulations on consumer accounts change the price of commercial customer accounts?
- bayesnet 8mo agoSmall businesses accounts were/are also subject to ring fencing, and my recollection is that large banks sought to recover the costs of ringfencing rules via charges on large clients. Come to think of it this was all also at the time of very low rates which was more likely to be the issue.
- bennyp101 8mo agoI noticed this a couple of years ago too, I just ignored the letters, continued to receive the emails, and they stopped sending me letters about it /shrug
- sparrish 8mo agoI've heard CapitalOne does the same thing... send paper mail saying their emails aren't being read.
- nickname-derail 8mo agoNAB Australia does exactly the same thing. Unless I "load remote images" when I receive their emails, they'll start mailing letters saying that they switched me to paper statements as their emails are not going through. It also took me a bit to investigate as their emails were obviously coming through.
- awesome_dude 8mo agoI'm in two minds on this - the bank does need to know that its communications are being received But, they have no idea if the paper statements are making it to your desk, or if they are getting swiped from the letterbox (I'm in an apartment in Melbourne, and the snail mail is not reliable at all, mail is sometimes delivered to the wrong building, sometimes the wrong address entirely, it's also swiped by miscreants who have nothing better to do, and, in some cases, the pricks set the letter boxes on fire, taking all the mail with it)
- ryandrake 8mo agoIf the bank really needed to know that its communications are being received, they would send them in a way that would reliably return this information (signature-confirmed postal mail). It's very unlikely that the bank actually needs to know this information.
- awesome_dude 8mo agoI appreciate that that has a stronger guarantee of delivery, it is also prohibitive from a costs point of view, which I, as the customer, will be paying either through fees or reduced interest for deposits or higher interests for borrowings.
- rendaw 8mo agoCapitalOne balance alerts for a low-use credit card - they silently disabled the alerts because "I wasn't reading them". Because I have read notifications disabled and don't load remote resources. Even if they truly believed I wasn't reading them, disabling them makes no sense to me. They certainly weren't bouncing and I wasn't reporting them as spam. I dropped CapitalOne after that (not sure I moved to something better though...)
- Analemma_ 8mo ago> I have a credit card with HSBC: you know, the bank with virtue-signalling multiculturalism in their ads. Was this opening sentence necessary? It is not germane at all to the rest of the article. Ironically, it is itself virtue-signalling (for some definition of virtue), just to a different audience.
- bstsb 8mo agoprecisely this. it sort of put me off an otherwise excellent article
- deleted 8mo ago[deleted]
- throwaway902984 8mo agoMy first instinct was to close the article as I didn't want to read a Republican virtue signaling to his audience. I wonder if they were trying to sound Republican? The article itself is a nice, well interesting, dive into the topic; kinda unfortunate.
- dwedge 8mo ago> I didn't want to read a Republican virtue signaling to his audience. I wonder if they were trying to sound Republican? It would be very surprising behaviour for a British guy living in the UK
- 1over137 8mo ago"Republican"?! US defaultism strikes again. He's in the UK, and he states his pronouns here https://danq.me/about/ https://danq.me/about/ so doesn't sound very "Republican" to me.
- cosmicgadget 8mo agoOn the other hand, Twitter is full of Republicans who are not from the US.
- 8mo ago
- SilverElfin 8mo agoSome may treat these as an inconvenience or annoyance, but I think it’s a sign of rot. And it may run a lot deeper. Unfortunately I feel like most financial institutions have terrible websites and practices in general, so I don’t know if switching will let you avoid problems.
- CGMthrowaway 8mo agoEmail is not a core competency of banks. They are actually pretty good at snail mail though.
- reaperducer 8mo agoAn extra century or two of experience will do that!
- barbazoo 8mo agoThe rot goes deeper because for every story like this there were hundreds of people involved in making it happen. Some by choice, some less so but rot nontheless.
- zzyzxd 8mo agoCapital One does this to me as well, but at least they make it clear so I actually understanding what they mean ("You haven't opened an email from us lately..."). It's fine, Capital One. I did open your emails, I just didn't load your shady tracking pixels.
- burnte 8mo agoDitto, I get them all the time and just ignore them. I actually have a gmail rule that if it sees that phrase it marks it read and deletes it. Them not knowing if I read an email is not a problem I need to solve.
- 63stack 8mo agoSo what do you think, what's happening here? My experience with IT in banks is that this entire "feature" of tracking who's opening/not opening emails must have went through about 50 people, and it must have taken at least a year from the idea forming in someone's head, going through all the administrative bureaucracy, getting approved, developed, tested, and rolled out. Is it that HSBC has 0 competent people who could have mentioned that "tracking pixels are unreliable, especially in 2025/26"? Or is it that everybody who mentioned this was overruled by middle/upper management because they know better? What about the http:// part? I imagine there must have been a few developers saying we should not be serving anything under http://.
- raverbashing 8mo agoI think people are overthinking this, though the discussion about reliability is merited For every HN technically inclined people you have dozens of other customers who will give any email (thinking it's just writing "John.smith@bt.co.uk" or something) - or worse- and they have to find a way of identifying those customers
- dwedge 8mo agoAt least they email him and don't send the stupid "you have an important message, login to see it" email. No idea what those important messages are, I'm sure sometimes they were important
- blackhaz 8mo agoCan somebody please tell Barclays their 3DS widget is never redirecting back to the seller when transaction has been approved on user's device? In fact, the sheer amount of systems not working correctly in Britain is astonishing. Feels like the whole country is falling apart.
- sd9 8mo agoCounterpoint: gov.uk is widely regarded as one of the best government websites in the world
- nomel 8mo agoI'm always curious how much these sorts of things costs each citizen, per year, from a more wholistic view?
- sd9 8mo agoLet's do some maths. There are 35,000,000 taxpayers [1], 70,000,000 citizens [2]. Say there are 5,000 people responsible for gov.uk and that each are paid £80k/year. Total budget: 5000 * £80k = £400M Cost per taxpayer per year: £400M / 35M = £11.43 Cost per citizen per year: £400M / 70M = £5.71 This source [3] cites projected GDS budget for 2026 as £420M. Previous years have been £273M (2025), and £256M (2024). So the fag packet calculations are not far off. [1] https://www.gov.uk/government/statistics/income-tax-liabilities-statistics-tax-year-2022-to-2023-to-tax-year-2025-to-2026/summary-statistics https://www.gov.uk/government/statistics/income-tax-liabilit... [2] https://www.ons.gov.uk/peoplepopulationandcommunity/populationandmigration/populationestimates/bulletins/annualmidyearpopulationestimates/mid2024 https://www.ons.gov.uk/peoplepopulationandcommunity/populati... [3] https://www.publictechnology.net/2025/07/14/government-and-politics/gds-set-for-big-budget-boost-in-fy26-dsit-accounts-show/ https://www.publictechnology.net/2025/07/14/government-and-p...
- MagicMoonlight 8mo agoWho still banks with HSBC when we have Monzo and Starling?
- reaperducer 8mo agoAdults.
- shaftway 8mo agoPeople who remember Yotta and Juno. https://en.wikipedia.org/wiki/Synapse_Financial_Technologies https://en.wikipedia.org/wiki/Synapse_Financial_Technologies
- bmenrigh 8mo agoCharles Schwab has something very similar. They keep unenrolling me from their paperless thing and then send me a letter every month telling me they unenrolled me because emails aren't being delivered. But I get their emails just fine. It's their tracking that (intentionally) isn't working.
- fooqux 8mo agoCapital One is the same. I eventually stopped caring; I know these paper mailings are costing them money. Maybe they'll get the point someday.
- WorldMaker 8mo agoAn issue is the number of banks now charging you back for paper services. At least one of my banks the fee is now $15/month for paper statements. That's way more than postage. I'd almost prefer paper statements from a few of my accounts, but not enough to pay for it directly.
- deleted 8mo ago[deleted]
- 6ak74rfy 8mo agoMaybe this is what's happening to me at Fidelity. They keep complaining about my email on custom domain but the Protonmail address works fine. I use different apps for the two because PM doesn't support IMAP, so maybe PM doesn't block the tracking pixels but the other one does.
- Dwedit 8mo agoGmail automatically downloads images ahead of time, so the tracking pixels will have been fetched by Gmail themselves regardless of when the user opens the email.
- ChicagoBoy11 8mo agoI had a demo for some high-school students for an ethics and tech class that successfully demonstrated these with a GMail account, so when this started happening I got very upset lol.
- jdhawk 8mo agoSo does Apple's Mail Client. So do most webmail providers. Open signals are generally worthless.
- mike-cardwell 8mo agoYou might want to read https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt_Work https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt...
- extraduder_ire 8mo agoI think gmail adds some heuristics on top of it, like if the same image was included in emails to multiple people. At least that's what I remember from them announcing the feature. No idea about other providers, and I haven't tested the feature myself.
- danaris 8mo agoWith a proper personalized tracking pixel, a simple deduplication won't catch it—the whole point is that each email's tracking pixel has a unique URL that lets them know that you opened the email. It is, of course, very possible that Google has heuristics that can catch tracking pixels—in fact, I would go so far as to say that if they chose to, they 100% could, probably tomorrow. But given where Google makes its money, I would not in the least trust them to do that for me.
- barbazoo 8mo ago> But it gets worse. Because HSBC are using http://, rather than https:// URLs for their tracking pixels, they’re also saying that every time you read an email from them, they’d like everybody on the same network as you to be able to know that you did so, too. If you’re at my house, on my WiFi, and you open an email from HSBC, not only might HSBC know about it, but I might know about it too. > But we’re in the Darkest Timeline. Tracking pixels have become so endemic that HSBC have clearly come to the opinion that if they can’t track when I open their emails, I must not be receiving their emails. So they wrote me a letter to tell me that my emails have been “returned undelivered” (which seems to be an outright lie).
- reaperducer 8mo agoTracking pixels have become so endemic that HSBC have clearly come to the opinion that if they can’t track when I open their emails, I must not be receiving their emails. So they wrote me a letter to tell me that my emails have been “returned undelivered” Tracking pixels are the key of thing that my computer filters out. So I wonder if this explains why I get paper statements for my Apple Card. Each time one comes in the mail, it has a letter with it stating that Goldman Sachs was unable to contact me at the email address on file, which they show as my Apple ID email address. Which works fine for everyone else in the world, including Apple.
- barbazoo 8mo agoThe German bank I have an account with solves this by making the statements available online and considering them delivered if the statements were downloaded. I’m assuming this proper way is too expensive for some banks.
- jmclnx 8mo ago>used to surreptitiously track when somebody reads an email Not in my email client, mutt. I use Thunderbird once in a great while. For some reason I thought there was an option to stop that and I enabled it. Will need to check the next time I fire up Thunderbird.
- esskay 8mo agoAll sounds about right for HSBC. They've got some of the worst banking tech in existence. How the heck anyone puts up with their crap is beyond me, I moved away a decade ago but still have a close family member with them and they're forever having issues (genuinely not user error) with the crippled online banking app they've got that looks like something from the early days of app development.
- crazygringo 8mo agoI don't see anything wrong with attempting this. A significant number of people mistype/change their e-mail address, and security messages from banks can be important, so anything that catches no-longer-working e-mail addresses is better for everyone involved. And I assume a very small proportion of people try to disable tracking pixels. But this post is entirely speculation. The author has no evidence they're basing it on tracking pixels. They're literally just guessing. And I'm dubious that tracking pixels would be a reliable enough signal to be worth it. Doesn't Gmail download images in advance anyways? Plus, I regularly filter predictable emails or just archive them directly from my inbox based on the subject line without opening. I'd more likely assume they have an e-mail bounce detector that just has a bug in it.
- jmholla 8mo ago> But this post is entirely speculation. The author has no evidence they're basing it on tracking pixels. They're literally just guessing. They literally admit to this and go on to provide the evidence for their guess: > I think I can place a solid guess about what went wrong here.
- crazygringo 8mo agoI know they admit it. I'm just pointing it out, since many of the comments here seem to be taking it as truth. And they don't provide any evidence. Not a single piece. Merely claiming it's a "solid guess" doesn't make it solid. It's based on nothing. Tracking pixels are extremely common, so there's nothing to suggest it's tied specifically to this. As opposed to, like I said, a buggy bounce detector.
- stronglikedan 8mo ago> I don't see anything wrong with attempting this. I do, when the result of that attempt is to tell people to change their email addresses unnecessarily. Most people will fall for that.
- crazygringo 8mo ago
- koakuma-chan 8mo ago> I can understand your frustration, but if the bank has sent the letter, you will have to update the e-mail address. That's why I fucking hate society. This is everywhere.
- drdec 8mo agoI would have asked, "or what?"
- Batman8675309 8mo agoIndeed. What would they do if he refused? Would they cancel his account over tracking pixels?
- kylehotchkiss 8mo agoHSBC, truly the pinnacle of Great Banks. Surprised they haven't earned your breakup yet.
- jackfranklyn 8mo ago[flagged]
- crazygringo 8mo agoDoes HTTP really matter in this particular case though? HTTPS still typically exchanges the Server Name Identification. So you know somebody is talking to HSBC. And the rest of the URL is just an anonymized tracking ID. So I'm having a hard time seeing what the threat is this particular instance.
- wolfi1 8mo agoas it's a tracking pixel it's personalized, if you are reading your email in the cafeteria with their wifi, potentially everybody in the cafeteria know more about you than they need
- crazygringo 8mo agoWhat do you mean it's personalized? It's an anonymous identifier token specific only to that email. Like I said, even with HTTPS everyone in the cafeteria theoretically knows you're connecting to HBSC as well. So I don't see the difference.
- sharperguy 8mo agoThey know that you likely read some email from HSBC and if you happen to read the same one again they will know it was the same one.
- crazygringo 8mo agoRight. But even over HTTPS it's not rocket science to figure out that connecting to www.email1.hsbc.co.uk pretty strongly suggests you've opened an e-mail with an image. And the number of times you request the same URL tells someone... what exactly? Because HTTPS still tells people the number of times you access any URL on a domain.
- hrimfaxi 8mo agoThe same exact thing would happen to me with interactive brokers.
- kkfx 8mo agoBanks have some of the worst IT in the world. Being purely manager-led, with developers completely subservient to the bean counters, the results are terrible. This is one of the reasons why in 2019 they wrote about their own demise https://web.archive.org/web/20240213185758/https://www.cimb.ch/uploads/1/1/5/4/115414161/banking_disrupted_geneva22-1.pdf https://web.archive.org/web/20240213185758/https://www.cimb.... against fintech (which is only slightly less archaic) and how cryptos, I don't know which ones, but maybe some yet to be born, will eventually displace them because regardless of their dominant position, the level of poor service and archaic systems is not humanly/socially sustainable for much longer. Their leadership is mentally incapable of changing. Unfortunately, I fear that most of the population isn't either.
- almosthere 8mo agoThis isn't going to get to someone at HSBC. Nothing will change. They hired another company to do it. The project has been over for 4 years. The man who determined the requirements no longer works at HSBC or the other company. The coder doesn't even know HSBC is using his code. It's absolutely useless - humans going into the age of software. It's a death spiral of I don't know's for a hundred miles.
- JasonADrury 8mo ago[flagged]
- anonymousiam 8mo agoYears ago, I used to get marketing spam emails from Bank of America. In their email, they did not offer a way to opt out from those types of email, so I invalidated the unique email address that I had created just for them. A few months later, I got a snail mail letter like the one Dan got, telling me that emails were being rejected and that I needed to correct my email address. I went through the same sort of nonsensical dialog with them, and they simply would not let me opt out from their marketing emails, so I left it disabled for a few years. Eventually they offered "email preferences", so I re-enabled it. My wife continues to get spam snail mail from Citi, and they offer no way to opt out. If it was my account, I would switch banks. Back to the main topic: I think it's pretty stupid of the HSBC IT folks to assume that an email was not read because the tracking pixels were never accessed. Lots of email clients these days do not load images by default.
- adastra22 8mo ago“We need to confirm you are receiving our emails, please click this link” is a phishing setup. That is absolutely not what they should do.
- crabmusket 8mo agoAgreed. What would be a good way for a bank to do this? What about "reply to this email"?
- adastra22 8mo agoSend a verification code on login.
- WorldMaker 8mo ago"Reply to this email" might not be a bad idea for some basic "making an explicit action" check. Arguably if the question is mail delivery, email already has a complex system of delivery failure reporting. Just trust that, like email programs have been doing since email was invented? "No failure is a success," doesn't have an explicit acknowledgement action from a user, but it is still a meaningful criteria.
- NoGravitas 8mo agoTell them "Log in to your online banking" with no link, show an alert about the email problem when they do.
- dpoloncsak 8mo agoIsn't this the exact reason we 'verify email address'? What's the point of that entire handshake then?
- jrs235 8mo agoUsing tracking pixels in emails is like using AI to generate solutions/code. It is not deterministic, is is only probabilistic.
- mmmlinux 8mo agoId be willing to bet the number of people who sign up for ebilling, then screw up their email address is huge. then those people blame the bank for not contacting them to tell them the issue. yes, its not how email is supposed to work. but people can be really really stupid.
- johnea 8mo agoIt seems the article and most of the comments here are nonsense. The focus on http versus https in allowing surveillance of fetching the tracking pixel are all but completely irrelevant. In any case, the domain name of the tracking pixel locations will be resolved through DNS, which is almost always unencrypted. So anyone on the LAN will see the DNS query, revealing the banking URL, in plain text. The big issue here, which I couldn't find one comment regarding, is that the email client is interpreting HTML. Use plain text email! Problem solved. At least use a "Simple HTML" or similar mode when viewing email. Where the HTML is rendered, but no links are followed.
- treetalker 8mo agoWho has two thumbs and (1) will never open an HSBC account because of this and (2) will advise his legal clients to bank elsewhere?
- fragmede 8mo agoWhat do you tell your illegal clients them?
- extraduder_ire 8mo agoBased on their history, HSBC. Obviously.
- bdangubic 8mo ago> We need to check that you’re receiving our emails. Please click this link to confirm that you are mate was on a toll till this. I mean after all that amazing write-up we gon be clicking links in emails??!
- amprisewinner 8mo agoI've been getting similar letters in the mail from Ameriprise for over 15 years. I receive all my account-related emails, but because they can't _track me doing that_ they _assume_ there is some kind of problem. I've contacted them about this multiple times and always get the same clueless & useless responses that ultimately end with "just disregard the notices" result. What a waste of resources, at so many levels.
- kayo_20211030 8mo agoHang on. The OP gets a paper statement already (there's a picture). If the email address is correct, and OP does nothing, what's the worst that could happen? If the bank wants to waste time and energy with this nonsense, that's their business. As long as nothing real bad can happen, let them at it. I don't think I'd be inclined to do the "bank's job" when it affects me not a bit. As sure as eggs is eggs, I wouldn't spend hours on the phone or chatline explaining what their problem is. It seems like it's their problems and not the OP's.
- ivanjermakov 8mo ago> If you’re at my house, on my WiFi, and you open an email from HSBC, not only might HSBC know about it, but I might know about it too. To be fair, if someone was on my local network, I would have greater issues to worry about.
- effnorwood 8mo agoYou had me at HELO
- nticompass 8mo agoYou're not using EHLO?
- TheJoeMan 8mo agoI take bigger offense to the message that says "your emails were returned undelivered", because that is a lie. A bank, sent to a customer, a lie. "Scale" should never be an acceptable excuse but somehow we let it slide when it comes to the internet. As an aside, at least the email wasn't "a new document is available in your secure portal click here to view it"!
- believ3 8mo agoHSBC = The Hongkong and Shanghai Banking Corporation ... of China Do you get it now? http:// isn't a bug -- it's by design.
- exidy 8mo agoSurely you know HSBC is a British bank? It was founded in 1865 when Hong Kong was under the control of the British and is headquartered in London.
- VladVladikoff 8mo agoI send over 1M transactional (user opt in only) emails per day for one of my websites. We have to be pretty strict how we handle bounces and complaints or it can tarnish our sending rep. Sometimes people accidentally flag mail as spam, or maybe their client does, or maybe their server does, and this comes back to us as a complaint. Under the ToS of my email gateway I must stop sending to that address until the user updates their email. There is a lot of assumptions in this post about tracking pixels etc, without any concrete evidence. The truth could be far simpler.
- janpeuker 8mo agoI had the exact same experience with HSBC, with a little twist: I was really impressed by their 100% online signup process with digital government ID which took less than 10 minutes. The process was extremely smooth, except for a very scammy sounding verification phone call. Within 1 day I had a digital card for Apple Pay and within 3 days a courier handed my my physical debit card. I liked the app too. I hadn't consented to marketing mail but HSBC decided to send me some "welcome upsell" anyways, which was returned as I refuse marketing mail. Immediately my card and account were blocked which sent me down the same experience as OP describes here.
- NoGravitas 8mo agoI am, in fact, shocked that any email clients (including the BigCo webmail clients) load remote images automatically in 2026. I haven't seen a client that didn't require an extra click to open remote resources since like 2020. Even Outlook 365 only seems to do it for emails within the same organization.