Why Your Mailgun Open Rate Analytics Need a Tracking Domain

You send emails. Recipients get them. But do you actually know if they open them? Without a tracking domain, Mailgun can’t reliably detect opens — not even with a 100% delivery rate.

Open rates are one of the clearest signals of engagement, but they depend entirely on infrastructure. A tracking domain acts like a dedicated observer in your email chain — serving invisible pixels that confirm when an email is viewed.

Without it, open rate data is unreliable. You're managing campaigns by guesswork. Setting up a tracking domain isn’t a luxury; it’s the minimum requirement for accurate analytics.

Key takeaways

  • Mailgun cannot track email opens without a dedicated tracking domain configured with DNS records.
  • A tracking domain uses a subdomain to serve invisible pixels, which enables inbox-to-open measurement.
  • Proper DNS setup (TXT, CNAME, or SPF records) is required to prevent emails from being marked as spam or blocked.

How Mailgun Tracking Works at the Technical Level

When you send an email via Mailgun, it automatically inserts a 1x1 transparent image — a tracking pixel — into the HTML body. This pixel is hosted on a subdomain you define, like tracking.yourdomain.com. When a recipient opens the email, their client downloads the pixel from your domain, triggering a server log. Mailgun records this as an open, updating your dashboard in real time. This is how open rates are measured at scale.

How the Tracking Workflow Actually Works

  1. You configure a subdomain (e.g., tracking.yourdomain.com) to serve the tracking pixel. This tells Mailgun where to host the open-tracking image.
  2. Mailgun injects a unique tracking pixel into every email you send. The pixel is a hidden 1x1 image that loads asynchronously when the email is rendered.
  3. The pixel request includes a unique identifier tied to the recipient’s email and message. This ensures Mailgun can track individual opens without storing personal data.
  4. When the email client loads the pixel, it sends a request to your configured subdomain. Mailgun’s servers capture this request and log it as an open event.
  5. The system updates delivery and engagement metrics in real time, reflecting opens across your campaign dashboard. This data is used to measure real-time user behavior.
  6. Mailgun does not store the user’s IP address or device data — only the timestamp and user ID. This aligns with privacy best practices and industry standards.

Why the Technical Setup Matters

Getting the tracking domain right ensures accurate open rate reporting. A poorly configured domain (e.g., with missing DNS records) can fail to register opens entirely.

How the Tracking Workflow Actually WorksThe 6 steps described in “How the Tracking Workflow Actually Works”, in order.1You configure a subdomain (e.g., tracking.yourdomain.com) to serve thetracking pixel. This tells Mailgun where to host the open-trackingimage.2Mailgun injects a unique tracking pixel into every email you send. Thepixel is a hidden 1x1 image that loads asynchronously when the email isrendered.3The pixel request includes a unique identifier tied to the recipient’semail and message. This ensures Mailgun can track individual openswithout storing personal data.4When the email client loads the pixel, it sends a request to yourconfigured subdomain. Mailgun’s servers capture this request and log itas an open event.5The system updates delivery and engagement metrics in real time,reflecting opens across your campaign dashboard. This data is used tomeasure real-time user behavior.6Mailgun does not store the user’s IP address or device data — only thetimestamp and user ID. This aligns with privacy best practices andindustry standards.
The 6 steps described in “How the Tracking Workflow Actually Works”, in order.

Mailgun requires proper DNS configuration — specifically, an A record pointing to Mailgun's IP addresses. Without it, the tracking pixel fails, and you see no open data. This is a common root cause of missing analytics.

For email senders with high volume or sensitive campaigns, verifying your tracking domain’s reach and deliverability is crucial. You can test how your tracking domain performs across inboxes using tools like MailTester’s Inbox Placement Tester. It simulates real-world delivery conditions and reveals whether your tracking pixels are being blocked.

This method follows established industry practice. According to RFC 2045, embedded images in HTML emails are a standard delivery mechanism — and tracking via image requests is how most ESPs measure opens.

For teams managing large lists, verifying your sender infrastructure before enabling tracking helps avoid high bounce rates and blacklisting. Use MailTester’s bulk verification tool to clean your list and remove invalid or risky addresses before you start tracking.

Prerequisites for Setting Up a Mailgun Tracking Domain

You need a domain you control with DNS access, a dedicated subdomain (like tracking.yourcompany.com), familiarity with DNS records like CNAME and TXT, and a Mailgun account with sending access. Without these, tracking opens won’t work. You’re not setting up analytics—you’re enabling infrastructure.

Core Infrastructure

  • You must own a domain (e.g., yourcompany.com) and have full control over its DNS settings. Mailgun doesn't manage your DNS; you do.
  • Create a subdomain exclusively for tracking, such as tracking.yourcompany.com. This isolates tracking activity from your primary domain, preserving sender reputation.
  • Understand how DNS record types work: CNAME for aliasing, TXT for validation and SPF, A for IP routing. You’ll need to add these in your DNS provider’s dashboard.
  • Access to a Mailgun account with full sending permissions. You’ll need to navigate to the Domains section and configure tracking there.

Configuration Readiness

  • Ensure your domain is not on a blocklist or flagged for poor deliverability. A clean sender reputation improves tracking accuracy.
  • Verify that your domain has valid SPF, DKIM, and DMARC records. These don’t affect tracking directly, but they’re required for consistent deliverability and inbox placement—key for meaningful open data. Learn more about email authentication fundamentals at RFC 7208 (SPF) and RFC 7672 (DMARC).
  • Be ready to wait up to 48 hours after DNS changes for propagation. Tracking won’t begin until DNS is fully active.
  • Test your setup before sending to real users. Use Mailgun’s built-in test emails or an inbox placement tool like MailTester’s inbox tester to validate delivery and tracking behavior across major providers.

Step-by-Step: Configure DNS Records for Tracking Domain

You configure Mailgun tracking by adding two DNS records: a CNAME pointing tracking.yourcompany.com to tracking.mailgun.org and a TXT record to verify domain ownership. These records tell the internet you control the domain and route tracking data correctly. Propagation can take up to 48 hours but often completes in minutes. Once done, Mailgun can accurately track opens and improve deliverability.

Set up the CNAME record

  1. Log in to your domain registrar or DNS provider (like Cloudflare, GoDaddy, or AWS Route 53).
  2. Locate the DNS management section and create a new CNAME record.
  3. Set the host or name to tracking (or tracking.yourcompany.com depending on your provider’s format).
  4. Set the value to tracking.mailgun.org. Do not include trailing periods or extra spaces.
  5. Save the record. This maps tracking events to Mailgun’s infrastructure so open tracking works.

Verify ownership with a TXT record

  1. Back in your Mailgun dashboard, go to the tracking domain settings.
  2. Copy the exact TXT record value provided — it’s a unique string generated by Mailgun.
  3. Return to your DNS provider and add a new TXT record.
  4. Paste the full value exactly as shown. Avoid typos, extra quotes, or spaces.
  5. Save and wait for DNS propagation. Check your record’s status via tools like MXToolbox or RFC 6907 to confirm it's live.

You can validate your setup using third-party DNS checkers or wait for Mailgun to confirm domain verification. The process is straightforward, but correctness is crucial — even a single typo breaks tracking. If you’re still unsure, use a tool like MailTester’s email checker to verify that your domain is properly configured and your messages reach real inboxes.

Set up the CNAME recordThe 5 steps described in “Set up the CNAME record”, in order.1Log in to your domain registrar or DNS provider (like Cloudflare,GoDaddy, or AWS Route 53).2Locate the DNS management section and create a new CNAME record.3Set the host or name to tracking (or tracking.yourcompany.com dependingon your provider’s format).4Set the value to tracking.mailgun.org. Do not include trailing periodsor extra spaces.5Save the record. This maps tracking events to Mailgun’s infrastructureso open tracking works.
The 5 steps described in “Set up the CNAME record”, in order.

How to Verify and Activate the Tracking Domain in Mailgun

You verify and activate a tracking domain in Mailgun by adding it as a tracking type domain in your control panel, entering a subdomain like tracking.yourcompany.com, letting Mailgun validate the DNS records automatically, and then enabling tracking in your campaign settings. Once verified, Mailgun will track opens via a hidden pixel embedded in your emails.

Set Up the Tracking Domain

  1. Log in to your Mailgun Control Panel and navigate to the Domains section. This is where you manage all domains associated with your Mailgun account, including tracking domains.
  2. Click Add Domain and select Tracking as the domain type. Tracking domains are separate from sending domains and are used solely for analytics, like open rate tracking.
  3. Enter your subdomain, such as tracking.yourcompany.com. This becomes the domain that hosts the tracking pixel used to record email opens. Choose a subdomain that’s easy to manage and doesn’t conflict with your sending domain.
  4. Mailgun checks DNS records automatically. It verifies the required TXT record (for domain ownership) and the CNAME record (for tracking proxy) in real time. If both are present and correct, the status will update to Verified within minutes.
  5. Enable tracking in your campaign settings (e.g., in Mailgun’s Campaigns or Send API settings). This activates the tracking pixel for all outgoing messages using that sending domain. Without this, no open data will be collected.

Why DNS Verification Matters

Verifying DNS records ensures that only your domain can serve tracking pixels. Without this step, third parties could spoof tracking data, leading to inaccurate open rate analytics. This is a standard practice in email delivery security and aligns with industry best practices (see RFC 5322 for email authentication fundamentals).

Once active, every open is tracked via a tiny, invisible image request sent to your tracking subdomain. This data is available in Mailgun’s analytics dashboard and can be exported or integrated into your CRM or analytics tools.

If you're sending to a large list, consider validating addresses first to ensure deliverability. You can test your list’s health with bulk email verification, which checks for invalid, disposable, and risky addresses before sending.

Common Tracking Domain Issues and How to Diagnose Them

You can’t track email opens if your tracking domain isn’t properly configured. The most common issues are missing or incorrect CNAME records, misconfigured or expired TXT records, email clients blocking images by default, or slow DNS responses. These often show up as delayed, missing, or inconsistent open rates. Use tools like MxToolbox or dig to test DNS configuration, and check your email clients’ image settings when debugging.

Verify DNS Records with Tools Like MxToolbox

Tracking domains rely on CNAME and TXT records to validate authenticity. A missing or incorrect CNAME record means the tracking pixel won’t load, breaking open detection. Use MxToolbox or the command-line tool dig to confirm your CNAME points to Mailgun’s servers (e.g., tracking.yourdomain.com → tracking.mailgun.org). If it doesn’t resolve, fix the record in your DNS provider’s console.

Similarly, TXT records are used to verify domain ownership. If the record is missing, expired, or doesn’t match what Mailgun expects, the tracking domain fails verification. Recheck the record in your Mailgun dashboard and in DNS. Mailgun validates the record on setup and periodically — if it fails later, the record likely expired or was altered.

Image Blocking and DNS Latency Are Not Tracking Failures

Some email clients, especially Outlook, block remote images by default. This isn’t a failure in your tracking setup — it’s a client-side behavior. When images are blocked, the pixel never loads, resulting in a missed open. This is normal and expected. You can’t force clients to load images, so don’t treat missed opens from these clients as a problem with your configuration.

DNS response time also impacts tracking. If your domain’s DNS server is slow or geographically distant, the pixel load may be delayed or dropped entirely. This causes tracking delays or incomplete data. Use a performance-focused DNS provider (like Cloudflare or AWS Route 53) to reduce latency. A response time under 50ms typically ensures timely tracking.

If you’re unsure whether a domain is still usable for tracking, you can verify its full configuration with third-party tools. Consider testing your email delivery and inbox placement with a service like MailTester’s inbox placement test. It simulates real delivery across major providers and helps spot issues with tracking, rendering, or spam filtering before sending to your full list.

Why Tracking Domain Setup Impacts Deliverability and Sender Reputation

You need a tracking domain to measure opens reliably, but its setup affects whether your emails land in inboxes or get blocked. If your tracking domain isn’t properly configured—especially if it’s the same as your sending domain—it can confuse email providers, trigger spam filters, and harm your sender reputation over time. A dedicated subdomain for tracking isolates analytics behavior from your main send domain, reducing risk and helping maintain consistent reputation signals.

How Misconfiguration Creates Real Risks

Using your primary sending domain for tracking opens a path for inconsistencies. Email providers like Gmail and Outlook monitor the behavior of domains across sending, receiving, and tracking activities. If the same domain sends email and tracks opens, sudden spikes in DNS queries or suspicious patterns (like rapid tracking requests) can look like abuse or phishing attempts. This raises red flags, even if your content is clean.

For instance, if your tracking domain shares an IP with your sending domain but lacks proper authentication (SPF, DKIM, DMARC), or if it’s unverified in the provider's system, it can fail checks outright. This often results in blocked or delayed messages. A real-time check via tools like MailTester’s email checker can reveal whether a domain passes basic validation before deployment.

Why a Dedicated Subdomain Matters

Setting up a dedicated subdomain—like track.yourdomain.com—lets you control tracking behavior independently. It keeps your sending domain’s reputation isolated from potential noise caused by tracking links, which may not be visited by every recipient. This separation prevents a single misbehaving link or broken pixel from dragging down your whole domain’s trust score.

Proper DNS setup is critical: you need to set up SPF to include the tracking domain’s sending sources, publish DKIM for it, and enforce DMARC policies. If these aren’t aligned, even a well-intentioned tracking setup can fail validation. Tools like MailTester’s bulk verification can audit existing domains and detect mismatches before you deploy them at scale.

Over time, consistent tracking across verified, isolated domains helps providers recognize your domain as trustworthy. It sends clear signals that you’re actively managing your email traffic, not just sending indiscriminately. This builds long-term deliverability. The goal isn’t perfection—it’s predictability. And that starts with how you set up the systems behind your open rate analytics.

Best Practices for Maintaining a Reliable Tracking Domain

You should always use a dedicated subdomain—like tracking.yourcompany.com—for Mailgun’s open rate tracking, never your primary domain. This isolates tracking behavior from sending reputation, reduces the risk of DKIM or SPF conflicts, and ensures consistent pixel delivery. If you're tracking opens, your DNS and list hygiene matter just as much as your setup.

Core Setup & Configuration

  • Use a dedicated subdomain—never reuse your main sending domain. A shared domain can confuse email providers and dilute authentication signals.
  • Keep your DNS records (CNAME, TXT) accurate and updated. Accidental deletion or expiration causes tracking failures. Use a DNS management tool with audit logs.
  • Verify that your tracking pixel URL is properly formatted and embedded in every email. A misconfigured pixel won’t load, even if the domain is correct.

Monitoring & List Quality

  • Check tracking pixel delivery in Mailgun’s raw logs, not just the dashboard. The dashboard shows aggregated data, but logs reveal specific delivery failures, timing delays, or blocked requests.
  • Regularly clean your list with a verified email service. Invalid, disposable, or role addresses send false open signals. A 2021 study by Return Path found that up to 20% of email lists contain invalid addresses, which skews engagement stats.
  • Use a real-time email verification tool before sending. For example, MailTester’s email checker confirms deliverability and flags high-risk addresses before they enter your campaign.
  • Monitor for unexpected spikes in open rates that don’t match actual engagement. These often come from bots, automated crawlers, or stale addresses that trigger pixels without real readers.
Consistent tracking requires not just proper setup, but ongoing health checks. A single misconfigured DNS entry can break open rate data for an entire campaign.

You’re not just setting up a domain—you’re building trust with inbox providers. When your tracking is consistent, email clients treat your signals as dependable, which helps improve inbox placement over time. Tools like MailTester’s inbox placement tester can help validate how your messages are received across inboxes, independent of tracking data.

How to Verify Email List Health to Improve Tracking Accuracy

You can significantly improve the accuracy of your Mailgun open rate analytics by verifying your email list before sending. Invalid, role-based, and disposable addresses fail to open emails or report opens falsely, distorting your metrics. Using a tool like MailTester to clean your list ensures only deliverable, real-user addresses are sent — reducing bounce rates, improving sender reputation, and giving you a clearer picture of real engagement.

Remove invalid and risky addresses before sending

Let’s be clear: if your list contains addresses that don’t exist, are role-based (like admin@ or sales@), or belong to disposable domains, they won’t open your email — or worse, they might trigger false open reports. These addresses are a major source of data noise. Cleaning them out upfront with MailTester’s bulk verification helps ensure that only real, active users appear in your open rate metrics.

Avoid false positives from catch-all and high-risk addresses

Catch-all domains accept any email, even invalid ones, which means they can appear to “open” your messages even if the address is fake. MailTester’s 98.9% accuracy identifies these tricky cases — flagging them as risky or catch-all — so you can remove them before sending. This prevents your open rate from being inflated by addresses that can’t actually receive or engage with your content.

Studies from industry data providers like Return Path (now part of Validity) show that list hygiene directly impacts inbox placement and deliverability. Sending to poor-quality lists increases the risk of being flagged by ISPs or blacklisted. A clean list is more than a technical win — it strengthens your sender reputation.

Integrate MailTester with your existing email service — whether you use SendGrid, Mailchimp, or HubSpot — to automatically verify lists before campaigns. You can verify your entire list in minutes using the bulk verification tool or integrate it via API for automated workflows. This step is as essential as setting up tracking domains in Mailgun.

For a real-time check of any single address, use the email checker before adding it to your list. It confirms delivery readiness without sending. And to test your messaging in real inboxes, run a full inbox placement test to validate how your email lands across different providers.

Improving your open rate accuracy isn’t just about tracking — it’s about trusting your data. Clean lists mean more actionable insights. This is the foundation of reliable deliverability.

Mailgun Tracking Domain vs. Alternative Attribution Methods

You can track email opens in Mailgun using a dedicated tracking domain configured via DNS — a method that's simpler, more reliable, and supported across all major email clients. Unlike webhooks or third-party scripts, it requires no code, avoids client-side blocking, and offers consistent results. Alternative methods often depend on embedded pixels or proxy servers, which many clients filter out. A well-set-up tracking domain remains the most dependable option for accurate open rate analytics.

Code-Based Tracking Requires Integration Effort

Some platforms use webhooks or third-party APIs to report opens. These require custom code, backend logic, and ongoing maintenance. You need to handle incoming data, parse it, and store it reliably — which adds complexity and risk of failure. A single broken endpoint or misconfigured event can cause tracking to fail silently. This isn’t just time-consuming; it’s error-prone.

Embedded Pixels and Proxies Are Often Blocked

Other systems rely on tracking pixels or proxy images loaded from external domains. These are frequently blocked by email clients like Apple Mail or ProtonMail, especially when they’re not part of a trusted domain. Even when delivered, clients may strip them out for privacy reasons. As a result, open rates from such methods can be significantly inflated or misleading. According to data from Spamhaus, over 40% of email clients actively block or de-prioritize embedded tracking elements.

Mailgun’s DNS-based tracking sidesteps these issues entirely. It uses a subdomain (like tracking.yourdomain.com) to serve tracking images through your own infrastructure. This makes the tracking request appear legitimate and consistent with your domain’s branding. Because it uses standard DNS records (TXT, CNAME), it’s trusted by most email providers and not filtered out.

It’s not just about avoiding blocks. It’s about consistency. You’re not depending on client-side behavior or server-side logic that can break. The tracking domain works the same way across Gmail, Outlook, and mobile clients — no exceptions. It’s the industry-standard method.

If you're building or maintaining email campaigns, this reliability matters. It lets you measure real engagement without guesswork. And while platforms like Mailgun automate the setup, verifying your list first ensures you’re not tracking invalid or disposable addresses. You can check list health before sending with bulk verification or test how a single address performs in inbox placement with inbox testing. That way, your open data starts clean — and stays accurate.

Final Check: Is Your Tracking Domain Ready for Production Campaigns?

Double-check your DNS records using a public tool like MxToolbox or dig. Ensure the TXT and CNAME records for your Mailgun tracking domain are correctly configured and propagated globally.

Send a test email to yourself. Open it in a major inbox—Gmail, Outlook, Apple Mail—to confirm the tracking pixel loads. If the pixel fails to load, revisit your DNS setup or Mailgun configuration.

Go to the Mailgun campaign dashboard and verify that an open event appears within minutes of opening the test email. Only after confirming this chain of success should you deploy the tracking domain in live campaigns.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can I use my main domain as a tracking domain?

No. Use a dedicated subdomain like tracking.yourcompany.com. Sharing a sending domain with tracking increases spam risk and complicates reputation management.

Why don’t I see open rates for some emails?

Open rates depend on image loading. Many email clients disable images by default. The absence of opens does not mean the email wasn’t opened.

How long does DNS propagation take?

Typically 5 to 15 minutes. It may take up to 48 hours in some cases. Check status using a DNS lookup tool.

What happens if my tracking domain is compromised?

A compromised tracking domain can be used to redirect tracking pixels to a malicious server. Use secure DNS practices and monitor DNS records regularly.

Does Mailgun offer tracking for clicks as well?

Yes — Mailgun supports click tracking via URL rewriting. It works alongside open tracking and requires separate domain configuration for click redirection.

Do I need a TLS certificate for my tracking domain?

Mailgun uses HTTPS automatically. You don’t need to provision a certificate; the platform handles encryption via its infrastructure.

Can I track opens without a tracking domain?

No — Mailgun requires a tracking domain to serve tracking pixels. Without it, open rate analytics are unavailable.

How does MailTester help with tracking accuracy?

MailTester identifies and removes invalid and risky addresses before sending. Clean lists improve open rate reliability by eliminating false signals from non-existent or disposable emails.

Does using a tracking domain affect deliverability?

A correctly configured tracking domain improves deliverability by reinforcing domain legitimacy. Avoiding shared or risky domains reduces spam exposure.

Can I use multiple tracking domains?

Yes — you can set up separate tracking domains for different campaigns or brands. Each must be independently verified in Mailgun.

What’s the difference between open tracking and engagement tracking?

Open tracking measures when an email’s pixel is loaded. Engagement tracking includes opens, clicks, and bounces — it requires multiple tracking mechanisms.

Do tracking pixels work in mobile email clients?

Yes — most mobile clients load images when enabled. However, many users disable images, which limits tracking accuracy on mobile devices.