William Weiner

Italy's Pixel Deadline Is Real. The EU Law Already Was.

Italy’s tracking-pixel deadline lands October 29, 2026, a little under eight weeks from this post. That date gets treated, understandably, as the news. The more useful fact sits underneath it: the consent requirement it enforces was never missing from the rest of Europe or the UK. It was already the law almost everywhere. France and Italy are just the first two regulators to write down exactly what compliance looks like, with a date attached.

Continue reading

Changing Your Email Tells Them Who You Became

The two earlier posts in this series – The Cookie That Never Expires and What 1,500 Emails Reveal About Tracking – described how a hashed email address became the ad industry’s favorite way to connect you across companies, and then showed that happening in one person’s real mail. This post looks at the same problem from the other side: what happens when you try to get out from under it.

You switch to an email aliasing service. Over the next few weeks you work through every account you have and swap the old address for a fresh alias – the bank, the airline, the pharmacy, the streaming service, fifty places in all. It feels like real work, and it is. When you finish, you feel unlinked: the old address is retired, the new ones are scattered across dozens of services, and nothing ties them together but a list only you can see.

Continue reading

The Loophole CNIL Left Open

The guidance this blog covered earlier in July treats an email tracking pixel like a cookie and requires consent for it in most cases. It also carves out an exemption for one specific use: measuring whether an email was opened, for the narrow purpose of keeping a mailing list’s deliverability healthy. That exemption is real, and read in full it is narrower than most summaries of it suggest. It is also written loosely enough, in one specific place, that a sender inclined to stretch it has room to do so. This post is about that one place, and about how it should eventually be closed.

Continue reading

What 1,500 Emails Reveal About Tracking

The earlier posts on this blog – The Cookie That Never Expires and UID2: The Standard That Replaced the Cookie – made an argument about how the ad industry replaced the cookie with your email address. This post is not an argument. It is what happened when that argument got pointed at one person’s actual mail.

The corpus is two personal mailboxes, a handful of single-service aliases, and a script that never once touches the network – it only reads what senders already embedded in the message. What came back is a specific, traceable answer to the industry’s favorite defense, that tracking pixels are harmless aggregate telemetry counting opens. The mail says otherwise, and it says something stranger besides.

Continue reading

France and Italy Just Turned Email Tracking Pixels Into a Consent Problem

In the spring of 2026, two of Europe’s most active data protection regulators reached the same conclusion within weeks of each other, without coordinating on it: an invisible pixel that reports when you opened an email is not meaningfully different from a cookie, and it needs the same consent.

The pixel did not change. The law around it did.

Consent risk you didn’t sign up for is still risk. EMail Parrot removes it at the source instead of asking you to manage it.

Continue reading

You Run the List. You Own the Risk.

If you run a group email list, you own the risk for everyone on it. Every address your members handed you, every message that flows through, every threat that rides in with it – that is yours to protect now, whether you signed up for the job or not.

I learned this the hard way. For about twenty-five years I have run the email list for my extended family, and it has taught me more about email privacy than any specification ever did. Eventually it made me write my own email system.

Continue reading

Apple Just Labeled Your Private Email Address

Apple announced this month that all new Hide My Email addresses will move from @icloud.com to @private.icloud.com. Your existing addresses keep working. But every new alias you create from this summer forward carries a domain name that tells any email filter on the planet exactly what it is: a privacy relay. Any site, bank, or mail system that wants to block anonymous signups can now do it with a single rule.

Continue reading

UID2: The Standard That Replaced the Cookie

The earlier post – The Cookie That Never Expires – showed how hashed email addresses became the ad industry’s replacement for the tracking cookie. Companies hash your address when you hand it over, and the hash becomes the identifier that follows you across sites and devices. That practice did not stay informal for long. In 2019, The Trade Desk gave it a name, a spec, and an open-source implementation. The result is called Unified ID 2.0, UID2 for short, and it is now the infrastructure underneath a significant share of the open web’s advertising.

Continue reading

Who Is Email Security For?

Email has a security stack. SPF, DKIM, DMARC, BIMI, spam filtering – decades of standards work and infrastructure investment. Ask one question of each layer and a pattern emerges that I think explains a lot about the state of email today:

Who is this layer designed to protect?


Authentication protects brands

SPF verifies that a mail server is authorized to send for a domain. DKIM cryptographically signs messages so tampering is detectable. DMARC ties the two to the visible From address and lets domain owners publish a policy for failures.

Continue reading

The Cookie That Never Expires

You probably remember when the tracking cookie died. Browsers blocked them, regulators demanded banners for them, and the advertising industry spent years announcing its move to a “post-cookie world.” It felt like a win for privacy.

It wasn’t a win. It was a substitution. The identifier that replaced the cookie is your email address.


A cookie lived in one browser on one device, and you could clear it whenever you wanted. Your email address follows you everywhere. You type it into every store, newsletter, app, loyalty program, and login screen. It is the same on your phone, your laptop, and your work computer. It survives for decades.

Continue reading