Why Open Tracking Is Critical for Deliverability

You send an email. It hits the inbox. But did the recipient even see it?

Without open tracking, you’re flying blind. You can’t know if your message landed in the inbox or got buried in a folder—or worse, blocked entirely.

Open tracking isn’t just about measuring clicks. It’s a core signal of deliverability: if people open your emails, your sender reputation is healthy. If they don’t, something’s wrong—maybe your domain is flagged, your content looks spammy, or your emails aren’t reaching inboxes at all.

Configuring Mailgun tracking domain for email open tracking gives you real-time visibility into whether your messages are seen. That’s the first step in fixing problems before they hurt your reputation or waste your send volume.

Key takeaways

  • Open tracking proves your emails are landing in the inbox and being seen.
  • Low open rates often indicate poor inbox placement or sender reputation issues.
  • Without open tracking, you can’t diagnose delivery failures or optimize campaigns effectively.

How Mailgun Tracks Opens: The Basics

Mailgun tracks email opens by embedding a tiny, invisible 1x1 pixel image in your messages. When a recipient loads the email, their email client requests this pixel from Mailgun’s servers, signaling an open. The request includes metadata like timestamp, IP address, and user agent, which you can use to measure engagement and validate deliverability.

How the Tracking Pixel Works

When you enable open tracking in Mailgun, the system inserts a unique tracking URL into your email’s HTML. This URL points to a publicly accessible image served from Mailgun’s infrastructure. The pixel isn’t visible to the user—it’s a standard practice across email platforms.

Each time the email is opened and the image is loaded, Mailgun logs the request. This gives you real-time data on who opened your message, when, and from what device or network. The timestamp and IP address help identify potentially problematic delivery patterns, such as repeated opens from the same IP or sudden spikes outside normal hours.

What Data Does Mailgun Capture?

Each tracking request includes a subset of metadata: the exact time of the open, the sender’s IP address, and the user agent string (which reveals the email client, operating system, and often the device type). This data is stored in your Mailgun dashboard and available via API.

Data like user agent and IP aren’t perfect—some clients block images by default, and proxy services can skew location data—but they’re still useful for identifying trends. For instance, a high rate of opens from mobile clients suggests your content is mobile-friendly. Low open rates, even with high delivery, may indicate poor subject lines or list fatigue.

Mailgun’s tracking relies on client behavior, not server-side logic. If the image is blocked, no open is logged. This means open rates are only as accurate as the recipient’s email client settings. According to RFC 2646, image loading is a common (but not universal) method for tracking email engagement.

Validating your email list with tools like MailTester’s bulk verification helps ensure you’re only sending to addresses that can actually render tracking pixels—reducing bounce rates and improving your sender reputation before tracking even begins.

Prerequisites for Setting Up Mailgun Open Tracking

You need a verified Mailgun domain with working SPF and DKIM records, a separate custom tracking domain configured in Mailgun (not your primary sending domain), and access to both your Mailgun control panel and your domain’s DNS settings. Only then can you enable open tracking reliably and avoid inbox placement issues caused by misconfigured authentication.

Domain & DNS Setup

  • Ensure your Mailgun domain is verified and sending with SPF and DKIM configured correctly. These records are required for deliverability; without them, open tracking fails regardless of setup.
  • Check your domain’s DNS records using tools like MXToolbox to confirm SPF and DKIM are properly published and valid.
  • Set up a dedicated tracking subdomain (e.g., track.yourdomain.com) in your DNS zone file and add the required CNAME record in Mailgun’s control panel for that subdomain.
  • Use a subdomain, not a root domain. Using a root domain as a tracking domain often breaks authentication and triggers spam filters.

Mailgun Control Panel Access

  • Log in to your Mailgun account and navigate to the Domains section to confirm your primary sending domain is verified.
  • Go to the Tracking tab under your domain settings and enter your tracking subdomain. Mailgun will validate the DNS record automatically.
  • Only after successful validation should you enable open tracking. Enabling it before DNS is verified leads to silent failures.
  • Test the setup by sending a test message and inspecting the tracking pixel URL in the email source — ensure it resolves to your tracking subdomain and doesn’t redirect unexpectedly.

Mailgun’s open tracking relies on a 1x1 pixel image delivered via HTTPS. If the tracking domain is misconfigured, the pixel fails to load, and open tracking data is lost. It’s common to see open rates drop to zero when tracking fails silently — you may not even know it happened until analytics lag is reported. Use inbox placement testing to verify your email reaches inboxes and rendering is not blocked.

How to Add a Tracking Domain in Mailgun

You can set up a tracking domain in Mailgun by logging in, going to the Domains section, selecting 'Tracking Domain', entering a subdomain like tracking.yourcompany.com, and adding the CNAME record Mailgun provides to your DNS. This enables Mailgun to track opens using a dedicated, trusted domain that avoids inbox filtering issues linked to sender reputation.

  1. Log in to your Mailgun account and go to the Domains page. This is where you manage all domains associated with your account, including tracking, sending, and routing configurations.
  2. Click 'Add Domain' and choose 'Tracking Domain'. Selecting this option tells Mailgun you’re setting up a domain specifically for tracking email opens and clicks, not for sending mail.
  3. Enter a subdomain in the format tracking.yourcompany.com. Use a subdomain that’s clearly related to tracking and doesn’t conflict with other services. The domain must resolve via DNS to be effective.
  4. Mailgun will generate a unique CNAME record for you. This record links your tracking domain to Mailgun’s infrastructure. Without it, tracking won’t work.
  5. Add the CNAME to your DNS provider’s zone file. The exact process varies by provider (e.g., Cloudflare, Route 53, GoDaddy), but you’ll need to add an entry like tracking.yourcompany.com pointing to a Mailgun-provided hostname.
  6. Wait for DNS propagation. This usually takes a few minutes to a few hours. You can verify it’s active using tools like MXToolbox or DNSChecker.

Why Use a Dedicated Tracking Domain?

Using a dedicated subdomain for tracking helps isolate tracking performance from your sending domain’s reputation. If your sending domain is flagged or blacklisted, tracking via a separate domain remains functional. This is a best practice in email deliverability, especially when sending high volumes.

Testing Tracking After Setup

After DNS propagates, send a test email with tracking enabled. Check your Mailgun webhooks or dashboard to verify open events are recorded. Real-time tracking relies on accurate DNS records and proper setup—any misstep here breaks the chain.

For an additional layer of confidence, you can validate your sending infrastructure using an email verification tool. Check your lists with MailTester’s bulk verification to ensure your addresses are deliverable and your sender reputation stays strong.

Add DNS Records for Your Tracking Domain

You need to add a CNAME record in your DNS provider (like Cloudflare or AWS Route 53) pointing your tracking subdomain (e.g., tracking.yourdomain.com) to mailgun.org. This lets Mailgun track opens by proxying image requests through its servers. DNS propagation can take up to 48 hours, so verify it using tools like MxToolbox or dig before sending.

Set Up the CNAME Record

  1. Log in to your DNS provider’s dashboard (Cloudflare, AWS Route 53, GoDaddy, etc.).
  2. Locate the zone file or DNS management section for your domain.
  3. Create a new CNAME record with the following values:
    • Name: The tracking subdomain (e.g., tracking or open).
    • Value: tracking.mailgun.org (confirm this with your Mailgun dashboard).
    • TTL: 3600 seconds is standard; use the default unless you need faster updates.
  4. Save the record. This step is required for Mailgun to receive and log open events.

Your DNS provider may not allow CNAME records at the root (naked domains), so a subdomain is required. This is an industry-standard limitation — see RFC 1034 for how DNS name resolution works.

Verify Propagation and Test

After saving the CNAME, wait up to 48 hours for global propagation. Use MxToolbox’s CNAME lookup tool or run dig CNAME tracking.yourdomain.com to confirm it resolves to tracking.mailgun.org. If you’re seeing mailgun.org instead, the setup is incomplete.

If the record isn't resolving, double-check spelling (especially in the subdomain), ensure it’s not hidden in a subzone, and confirm you're using the correct tracking domain in Mailgun. The record should not point to a different service — Mailgun must be the final resolver.

Once verified, test tracking by sending a message to a known inbox. Use Mailgun’s dashboard to check if open events appear. If they don’t, review your email body: tracking pixels must load from the exact subdomain you configured. Images hosted locally or on third-party domains won’t trigger the open tracker.

Before sending to live lists, verify your entire email address list with a reliable email verification tool — like bulk verification — to filter out invalid addresses that could hurt deliverability. You can also test inbox placement with inbox placement testing to see how your tracked emails appear in real inboxes.

Verify Tracking Domain Setup in Mailgun

After adding your tracking domain in Mailgun, go to Domain Settings, select the domain, and click Verify. Mailgun checks your DNS records in real time — if they’re correct, it confirms the setup instantly. Once verified, open tracking works automatically for all new emails sent from that domain.

Step-by-Step Verification

  1. Navigate to Domain Settings in your Mailgun dashboard. This is where you manage all domain-level configurations, including tracking, sending, and authentication.
  2. Select your tracking domain from the list. Make sure it matches the domain you added earlier — this is the one that will receive the tracking pixel requests.
  3. Click Verify. Mailgun immediately validates the DNS records you’ve set (TXT and CNAME) using standard DNS lookup protocols. This step ensures your domain is authorized to send tracking data.
  4. Wait for confirmation. The process takes seconds. If there’s a mismatch in your DNS, you’ll see a detailed error. Common issues include typos in the record values or missing TXT entries required for DMARC alignment.
  5. Track opens automatically. Once verified, every new message sent from your domain will include a visible tracking pixel. Recipients’ email clients request the pixel when they view the message, which Mailgun logs as a delivery event.

Why This Matters

Tracking open rates accurately depends on correct DNS setup. If you skip verification, Mailgun won’t recognize your domain as valid for tracking — leading to missed data and inaccurate engagement analytics. According to RFC 5321, proper DNS validation ensures email systems can trust the source of tracking data.

Step-by-Step VerificationThe 5 steps described in “Step-by-Step Verification”, in order.1Navigate to Domain Settings in your Mailgun dashboard. This is where youmanage all domain-level configurations, including tracking, sending, andauthentication.2Select your tracking domain from the list. Make sure it matches thedomain you added earlier — this is the one that will receive thetracking pixel requests.3Click Verify. Mailgun immediately validates the DNS records you’ve set(TXT and CNAME) using standard DNS lookup protocols. This step ensuresyour domain is authorized to send tracking data.4Wait for confirmation. The process takes seconds. If there’s a mismatchin your DNS, you’ll see a detailed error. Common issues include typos inthe record values or missing TXT entries required for DMARC alignment.5Track opens automatically. Once verified, every new message sent fromyour domain will include a visible tracking pixel. Recipients’ emailclients request the pixel when they view the message, which Mailgun logsas a delivery event.
The 5 steps described in “Step-by-Step Verification”, in order.

Even minor errors in CNAME or TXT records break the connection. Double-checking the setup prevents false negatives. For example, some providers block tracking domains not configured properly at the DNS level.

Once active, tracking data appears in your Mailgun dashboard within minutes. You can use this data to refine your campaigns, but only if the domain is verified. You can also use tools like MailTester’s email checker to verify individual addresses before sending — reducing the risk of sending to invalid or non-deliverable recipients.

Configure Tracking Domain in Mailgun Settings

You can enable open tracking in Mailgun by navigating to the 'Tracking' section under your domain settings, turning on Open Tracking, and selecting the verified tracking domain you've set up. This ensures email opens are recorded, and you can later analyze engagement with your campaigns.

Step-by-step: Enable Open Tracking

  1. Go to your Mailgun domain settings and select the 'Tracking' tab. This is where Mailgun handles tracking behaviors like opens and clicks, and it's essential for accurate engagement metrics.
  2. Enable Open Tracking by toggling the switch. When enabled, Mailgun will insert a tracking pixel into your emails, which fires when a recipient opens the message, helping you measure real engagement.
  3. Select your tracking domain from the dropdown. This must be a subdomain you’ve already verified and configured with a CNAME record in DNS. Using a dedicated tracking domain (e.g., track.yourdomain.com) improves sender reputation and reduces the chance of emails being flagged as spam.
  4. Set tracking to apply by default. Choose the option to include the tracking pixel in all outbound emails unless explicitly disabled. This ensures consistent data collection across your mailing activities.

Why This Matters for Deliverability

Using a dedicated tracking domain helps isolate tracking behavior from your main sending domain, which can improve inbox placement. According to industry best practices, separating tracking infrastructure reduces the risk of reputation damage if a tracking URL is misused or flagged.

Step-by-step: Enable Open TrackingThe 4 steps described in “Step-by-step: Enable Open Tracking”, in order.1Go to your Mailgun domain settings and select the 'Tracking' tab. Thisis where Mailgun handles tracking behaviors like opens and clicks, andit's essential for accurate engagement metrics.2Enable Open Tracking by toggling the switch. When enabled, Mailgun willinsert a tracking pixel into your emails, which fires when a recipientopens the message, helping you measure real engagement.3Select your tracking domain from the dropdown. This must be a subdomainyou’ve already verified and configured with a CNAME record in DNS. Usinga dedicated tracking domain (e.g., track.yourdomain.com) improves senderreputation and reduces the chance of emails being flagged as spam.4Set tracking to apply by default. Choose the option to include thetracking pixel in all outbound emails unless explicitly disabled. Thisensures consistent data collection across your mailing activities.
The 4 steps described in “Step-by-step: Enable Open Tracking”, in order.

Mailgun’s tracking system relies on email clients loading embedded pixels—a standard across the email industry. This data is collected only when a user opens an email with images enabled. The process is privacy-compliant, as no personal data is collected beyond the open event.

While Mailgun handles the technical backend, verifying your email list beforehand improves tracking accuracy. Invalid or disposable emails won’t open—but they can still impact your sender reputation if sent frequently. Use MailTester’s bulk verification to clean your list before sending, ensuring your open rates reflect real engagement.

For real-time validation during integration, consider the MailTester API to check individual addresses before they enter your campaign flow.

Test Open Tracking with a Real Email

Send a test email via Mailgun’s API or SMTP with open tracking enabled, then open it in a browser—avoiding email clients that block tracking. Within minutes, check your Mailgun dashboard to confirm the open event appears. This verifies your tracking domain is properly configured and working.

Set up and send the test email

  1. Use the Mailgun API or SMTP to send an email with tracking=1 in the request payload. This enables open tracking at the message level. Without this, your dashboard won’t record opens.
  2. Ensure your tracking domain is set in the Mailgun control panel and properly configured with DNS records (CNAME for the tracking domain and DKIM signing). If missing, open events won’t register or could be flagged as spam.
  3. Send the email to a real address—preferably one you control. Using an address from a disposable domain or a role account (like support@) may trigger delivery issues or lack of tracking due to blocking.

Confirm the open event in the dashboard

  1. Open the email in a browser tab or standalone web client (like Gmail’s web interface or Outlook on the web). Avoid clients like Apple Mail or Outlook Desktop unless you’ve verified they respect tracking—many disable image loading by default.
  2. Wait 2–5 minutes. Mailgun processes open events in real time, but delivery delays or client behavior can affect timing. A 10-minute wait is safe if nothing shows up.
  3. Check the Mailgun dashboard under Events or Tracking to see if the open event appears with a timestamp and IP location. This confirms your tracking domain is reachable and the pixel is being loaded.

Open tracking relies on image-based detection—Mailgun injects a tiny, invisible pixel (1x1 PNG) into your email. When the image loads in a browser, the server logs the event. This is an industry-standard method, used by providers like SendGrid and Amazon SES, and defined in the broader email security and tracking framework outlined in RFC 8314 on the use of tracking pixels in email.

Before sending to a large list, validate your setup using a single address. You can verify the email address first with a service like MailTester’s email checker—it confirms syntax, domain existence, and catch-all status without sending.

Common Pitfalls and How to Avoid Them

You risk damaging your sender reputation, breaking tracking, and losing visibility if you use your primary sending domain for tracking, skip DNS records, or ignore client-side tracking blockers. Let’s cover the real pitfalls teams face and how to fix them before they hurt deliverability.

Tracking Domain Misconfiguration

  • Use a dedicated subdomain (like track.yourdomain.com) for tracking, not your primary sending domain. Sending a tracking pixel from your main domain can trigger inbox filters that flag unusual behavior, especially if your sending volume is high.
  • Ensure both the CNAME and TXT records are set up correctly in your DNS. An incomplete record means tracking won’t register, and you’ll see 0 opens even when emails are delivered. Double-check with tools like MXToolbox or DNSPer to validate propagation.
  • Don’t assume your email client will display tracking pixels. Apps like Outlook and Apple Mail block remote content by default. This isn’t a bug — it’s a security feature. If you depend on open tracking for engagement metrics, prepare for lower signal fidelity, especially with enterprise clients.

Overlooking Reputation and Infrastructure Risks

  • Leverage dedicated IP addresses and monitor DMARC alignment when setting up tracking. Shared infrastructure can carry reputational baggage from other senders. Even a single misconfigured tracking pixel can hurt your IP reputation if it triggers spam reports.
  • Use your inbox placement tester to check how tracking pixels behave across real mail clients. MailTester’s inbox-tester helps you preview how messages land — including whether tracking images are blocked — before you send at scale. Test your campaigns in real inboxes.
  • Combine your tracking setup with a clean sender list. Verify every email address with a trusted service like MailTester’s email checker to eliminate invalid, role-based, or disposable addresses that harm reputation and skew tracking data.
Even a well-configured tracking domain can fail if the underlying list quality is poor. Your tracking data only matters if the email is actually delivered to a real mailbox.

How to Monitor Tracking Performance and Inbox Placement

You can monitor email tracking performance and inbox placement by using Mailgun’s event webhooks to capture opens, clicks, bounces, and spam reports. Cross-reference these events with your send volume to spot delivery drop-offs or engagement issues. Ensure your sending domain has a clean reputation by avoiding role accounts, disposable emails, and consistently high bounce rates—tools like MailTester's inbox placement tester can help validate deliverability before you send.

Use Webhooks to Capture Real-Time Engagement Data

Mailgun’s event webhooks push real-time notifications for every user interaction—opens, clicks, bounces, and spam complaints. You’ll need to set up a webhook endpoint that logs these events and associates them with specific campaigns and recipients. This enables you to see exactly when and how your audience engages with your emails.

For example, if you send 10,000 emails but only 6,000 opens are recorded, the 4,000 missing opens may point to delivery issues, blocking, or misconfigured tracking. By analyzing the timing and volume of these events, you can quickly detect patterns like sudden drops in engagement or delivery failures across certain regions or ISPs.

Validate Your Domain’s Reputation and List Health

Even with accurate webhooks, poor inbox placement will still hurt overall performance. A high-open-rate campaign can still fail if too many emails land in spam folders or are silently blocked. That’s why you need to verify your domain’s reputation and your list’s health.

Role accounts (like admin@ or sales@) frequently trigger spam filters. Disposable email domains are often flagged by ISPs and may cause reputational harm. You can use MailTester’s bulk verification tool to filter out these problematic addresses before sending. Similarly, consistently high bounce rates—especially hard bounces—deter ISPs and signal poor list hygiene.

The Internet Society’s ISOC reports that IP and domain reputation are critical factors in email deliverability. ISPs use reputation scores to filter large email volumes, and they’re increasingly cautious with domains that show spikes in bounces or spam complaints. Maintaining a clean domain record through consistent list hygiene and proper authentication (SPF, DKIM, DMARC) is not optional—it’s foundation-level deliverability.

Conclusion: Open Tracking Is a Deliverability Signal

Properly configured tracking domains are not just about measuring opens—they reveal whether your messages land in inboxes at all.

They validate delivery and confirm engagement, providing data that helps refine sender reputation and campaign performance over time.

Without this visibility, you’re optimizing blind. Open tracking isn’t just a metric—it’s a signal of trustworthiness to email providers.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can I use my main domain as the tracking domain in Mailgun?

No. Use a dedicated subdomain like tracking.yourcompany.com to isolate tracking and improve sender reputation.

Why isn’t my open tracking showing up in Mailgun?

Check DNS records for the tracking domain, ensure open tracking is enabled, and verify the email was opened in a compatible client.

Do all email clients support open tracking pixels?

No. Clients like Apple Mail and older Outlook versions disable image loading by default, preventing tracking.

How long does DNS propagation take for a tracking domain?

Typically 5 to 48 hours. Use tools like MxToolbox to verify DNS resolution has completed.

What is the difference between open tracking and click tracking?

Open tracking detects whether an email was viewed. Click tracking records when a link is clicked.

Does Mailgun support tracking for bulk emails?

Yes. Open tracking works for all outgoing messages, including bulk campaigns, once properly configured.

Can I disable tracking for individual emails?

Yes. Use the 'tracking' parameter in the API to exclude tracking per message.

Do tracking pixels affect email deliverability?

No, if hosted on a properly authenticated domain. They do not impact inbox placement when correctly set up.

How does Mailgun handle spam traps and bounces during tracking?

Mailgun logs and reports bounces and spam complaints. Tracking only occurs if the email is successfully delivered.

Can I use Mailgun’s tracking domain with third-party tools?

Yes. The tracking domain works with any outbound email tool that supports Mailgun's SMTP or API.

Is open tracking GDPR-compliant?

Not by default. You must inform users and obtain consent if required by law in your jurisdiction.

How does open tracking help with list hygiene?

It identifies inactive recipients. Low open rates over time signal poor list quality and justify list cleaning.