The invisible image that measures your open rate now requires consent in France and will require it in Italy before the end of October.
Two European data protection authorities reached that conclusion within weeks of each other this spring, working separately and through different legal instruments. Both decided that instructing a recipient’s device to report when a message was opened belongs in the same category as setting a cookie, carrying the same consent obligation.
The practical effect is narrower than a ban and more awkward to handle. Open rate has served as the industry’s default proxy for human contact since well before inbox placement was measurable at all. In two of Europe’s larger markets, collecting it now comes with a documentation burden and an enforcement date.
What makes August notable is what showed up alongside the restriction. A specification moving through the IETF this summer would have mailbox providers report placement and recipient reaction directly to senders, with no pixel involved at any point.
Key Takeaways
- France’s tracking pixel compliance deadline passed July 14, followed by a clarifying regulator FAQ on July 22
- Italy set an independent deadline of October 29 covering the same technology
- The deliverability exemption in both countries excludes campaign measurement and profiling
- A new IETF specification has mailbox providers sending placement and reaction data straight to senders
- DKIM2 reached its fourth working-group draft on July 5, authored by engineers at Yahoo, Google, and Fastmail
France’s deadline passes
![]()
The CNIL adopted Délibération n° 2026-042 on 12 March 2026 and published it on April 14. Its reasoning is mostly mechanical rather than moral: loading a remote image inside a mail client is a read operation on the recipient’s device, placing it under Article 82 of French data protection law, the provision that regulates cookie usage.
Senders were given three months to notify contacts collected before April 14 and provide a functioning way to object. That window ended July 14.
A follow-up FAQ published on 22 July confirmed the recommendation applies regardless of whether the recipient is a customer, prospect, or employee, and in B2B as well as B2C. It also confirmed that permission to send a marketing message under existing French rules does not extend to the pixel inside that message.
The consent rule has one exception. It covers pixels used strictly to confirm mail is being received and to retire inactive addresses. It does not cover campaign performance reporting, subject-line testing, or building interest profiles.
Most senders use one pixel for all of those purposes at once. The exemption therefore only covers the narrowest slice of what a typical program does.
Italy reached the same conclusion on its own. The Garante adopted its guidelines through provvedimento n. 284 of 17 April 2026, published in the Gazzetta Ufficiale on 29 April, with a six-month adjustment period ending 29 October 2026.
Different regulator, different exemptions, same underlying judgment. Anyone mailing both countries has two compliance clocks to track.
Providers begin sending the data themselves
In July, a specification called APRF appeared at the IETF. Aggregate Performance Reporting comes from Alex Brotman of Comcast, Tom Corbett of Iterable, and Emil Gustafsson of Google, and Comcast is already sending beta reports.
The setup will feel familiar to anyone who has configured DMARC. A sender publishes a TXT record naming a reporting address, and any participating mailbox provider returns periodic aggregated reports describing where the mail landed and how recipients treated it. The lookup is based on the DKIM signature domain and selector instead of the From domain, and an optional tag lets senders request the data broken out by an internal identifier such as a campaign ID.
Two categories come back. Classification counts messages that reached the inbox versus those routed to spam. Engagement counts positive actions, including a recipient rescuing mail from the spam folder, versus negative ones such as complaints or deletion without reading.
The main differentiator is the source. Inbox placement platforms have historically relied on seedlist testing, sending to a small collection of test mailboxes to estimate treatment. APRF reports aggregate behavior from human recipients.
Al Iverson, who has written about deliverability since 2001, was direct about the appeal in a July post:
“I’d be adding APRF support immediately.”
Adoption remains the obvious constraint, and Iverson published a useful corrective on August 10. Reviewing data shared by a smaller political sender, Comcast domains accounted for roughly 1.8% of that sender’s list, which is the entire portion APRF currently illuminates for them.
With Google co-authoring the specification, that figure has room to move. Until it does, this is a preview rather than an instrument.
Authentication work adds a feedback channel
The DKIM2 specification advanced without much attention. It reached draft-ietf-dkim-dkim2-spec-04 on 5 July 2026, authored by Richard Clayton of Yahoo, Wei Chuang of Google, and Bron Gondwana of Fastmail.
Its headline target is replay abuse, where an attacker captures a legitimately signed message and redistributes it at volume under the original sender’s reputation. DKIM2 counters this by recording the SMTP envelope values used at every hop, producing a chain of custody that exposes messages arriving somewhere they were never addressed.
Buried in the flag definitions is something that connects to the reporting story above. A signer can set a “feedback” flag requesting information about how a message was handled during delivery and afterward, and a forwarder can set “feedhere” to route that feedback through itself rather than revealing downstream systems.
The specification deliberately leaves delivery of that feedback undefined. Standards work is building formal routes for providers to tell senders what became of their mail.
The Certified Senders Alliance is running a free DKIM2 session on August 25 featuring Sebastian Kluth, Kieran Cooper of Halon, and Bron Gondwana.
What August brings
Regulators are restricting the measurement senders built themselves. Standards bodies are building the measurement providers will hand over. The tool you own is becoming a liability. The tool you’re given is becoming the trustworthy one.
What provider’s score has not changed. Placement still depends on whether recipients open, read, reply, and move messages out of the wrong folder. InboxAlly generates those exact actions, holding placement steady while the measurement rules underneath get rewritten. Start a free trial and read the reports instead of estimating them.

