William Weiner

The Loophole CNIL Left Open

The guidance this blog covered earlier in July treats an email tracking pixel like a cookie and requires consent for it in most cases. It also carves out an exemption for one specific use: measuring whether an email was opened, for the narrow purpose of keeping a mailing list’s deliverability healthy. That exemption is real, and read in full it is narrower than most summaries of it suggest. It is also written loosely enough, in one specific place, that a sender inclined to stretch it has room to do so. This post is about that one place, and about how it should eventually be closed.

Continue reading

What 1,500 Emails Reveal About Tracking

The earlier posts on this blog – The Cookie That Never Expires and UID2: The Standard That Replaced the Cookie – made an argument about how the ad industry replaced the cookie with your email address. This post is not an argument. It is what happened when that argument got pointed at one person’s actual mail.

The corpus is two personal mailboxes, a handful of single-service aliases, and a script that never once touches the network – it only reads what senders already embedded in the message. What came back is a specific, traceable answer to the industry’s favorite defense, that tracking pixels are harmless aggregate telemetry counting opens. The mail says otherwise, and it says something stranger besides.

Continue reading

France and Italy Just Turned Email Tracking Pixels Into a Consent Problem

In the spring of 2026, two of Europe’s most active data protection regulators reached the same conclusion within weeks of each other, without coordinating on it: an invisible pixel that reports when you opened an email is not meaningfully different from a cookie, and it needs the same consent.

The pixel did not change. The law around it did.

Consent risk you didn’t sign up for is still risk. EMail Parrot removes it at the source instead of asking you to manage it.

Continue reading

You Run the List. You Own the Risk.

If you run a group email list, you own the risk for everyone on it. Every address your members handed you, every message that flows through, every threat that rides in with it – that is yours to protect now, whether you signed up for the job or not.

I learned this the hard way. For about twenty-five years I have run the email list for my extended family, and it has taught me more about email privacy than any specification ever did. Eventually it made me write my own email system.

Continue reading

Apple Just Labeled Your Private Email Address

Apple announced this month that all new Hide My Email addresses will move from @icloud.com to @private.icloud.com. Your existing addresses keep working. But every new alias you create from this summer forward carries a domain name that tells any email filter on the planet exactly what it is: a privacy relay. Any site, bank, or mail system that wants to block anonymous signups can now do it with a single rule.

Continue reading

UID2: The Standard That Replaced the Cookie

The earlier post – The Cookie That Never Expires – showed how hashed email addresses became the ad industry’s replacement for the tracking cookie. Companies hash your address when you hand it over, and the hash becomes the identifier that follows you across sites and devices. That practice did not stay informal for long. In 2019, The Trade Desk gave it a name, a spec, and an open-source implementation. The result is called Unified ID 2.0, UID2 for short, and it is now the infrastructure underneath a significant share of the open web’s advertising.

Continue reading

Who Is Email Security For?

Email has a security stack. SPF, DKIM, DMARC, BIMI, spam filtering – decades of standards work and infrastructure investment. Ask one question of each layer and a pattern emerges that I think explains a lot about the state of email today:

Who is this layer designed to protect?


Authentication protects brands

SPF verifies that a mail server is authorized to send for a domain. DKIM cryptographically signs messages so tampering is detectable. DMARC ties the two to the visible From address and lets domain owners publish a policy for failures.

Continue reading

The Cookie That Never Expires

You probably remember when the tracking cookie died. Browsers blocked them, regulators demanded banners for them, and the advertising industry spent years announcing its move to a “post-cookie world.” It felt like a win for privacy.

It wasn’t a win. It was a substitution. The identifier that replaced the cookie is your email address.


A cookie lived in one browser on one device, and you could clear it whenever you wanted. Your email address follows you everywhere. You type it into every store, newsletter, app, loyalty program, and login screen. It is the same on your phone, your laptop, and your work computer. It survives for decades.

Continue reading

The Right Call, Handled Badly: The DreamHost Mailman Shutdown

DreamHost recently announced they are shutting down their hosted Mailman service. If you run a mailing list there, you have until July 31 to figure out where to go.

The announcement landed badly. Community forums and Reddit threads filled up quickly – not just with people asking what to do next, but with people who were genuinely angry. And the anger has been spilling over into broader conversations about DreamHost as a company.

Continue reading

Pixels Were Just the Beginning

Back in March we published a breakdown of how email tracking has evolved beyond the pixel – per-recipient identifiers planted in multiple places at once so that blocking any single vector leaves the others intact. We said we were treating tracking removal as a first-class feature, non-optional, like virus scanning. And we said we’d announce when it shipped.

It shipped.

This post covers what changed, what it means for your members, and why some of these protections matter more than the pixel ever did.

Continue reading