# Email Tracking

Flomailr tracks campaign emails in two ways: a tiny image records opens, and rewritten links record clicks. Both are signed per recipient, so a forged request cannot add to your numbers. Reports are on the campaign's analytics page and the Overview. See [Analytics](/docs/platform/analytics).

## Opens

An open is recorded when the recipient's mail client loads the 1x1 image added to the end of the email. If the client blocks images, the open is not measured. Each person counts once per campaign: later opens by the same person are not added.

Many image requests come from machines, not people, so Flomailr classifies each one:

| Kind                                 | Counts as a human open | Examples                                                    |
| ------------------------------------ | ---------------------- | ----------------------------------------------------------- |
| Human                                | Yes                    | A normal mail client or browser                             |
| Image proxy                          | Yes                    | Gmail and Yahoo, which fetch the image when it is displayed |
| Unknown                              | Yes                    | A request with no user agent                                |
| Likely Apple Mail Privacy Protection | No                     | Apple's pre-fetch of every image in a delivered message     |
| Machine                              | No                     | Crawlers, scripts, security gateways, link previews         |

- **Human open rate** on a campaign counts the first three kinds. The hint under it shows the rate including machine and Apple opens.
- Apple Mail Privacy Protection loads images whether or not the message is read. Flomailr spots it from the shape of the request. That is a heuristic, so a first fetch that arrives more than 24 hours after the send is reclassified as human by a background job. A pre-fetch happens at delivery, not a day later.
- The **Engagement** card on a contact counts human opens and clicks only, so it reads lower than campaign totals. Contacts are Active (engaged in the last 30 days), Cooling (31 to 90 days), Dormant (longer ago), or Never engaged (they received mail and never opened or clicked).

## Clicks

Every `http` or `https` link in the body is rewritten to a Flomailr address that records the click and redirects to your real link. The signature covers the destination, so the link cannot be edited to send someone elsewhere.

- Not rewritten: `mailto:` and `tel:` links, anchors, relative links, the unsubscribe and preference links in the footer, and any link too long to encode.
- Every click is recorded, repeat clicks included. **Click rate** uses unique clickers divided by sent. **Top links** lists clicks per URL.
- Security gateways open every link in a message within seconds. A click is treated as a scanner when it comes from a machine user agent, or when the same recipient hits a different link of that message within 2 seconds. A scanner click is still recorded and redirected, but it does not start automations, score the contact, send a webhook or update engagement.

## Polls

A poll block gives each answer its own link, and a vote is a click on that link. Results appear under **Top links**. Those are raw click counts, so a repeat click and a scanner click both add a vote. Treat small gaps with care.

## UTM parameters

In the builder's document settings, **UTM Tracking** has the toggle **Append UTM parameters to links** and fields for Source, Medium, Campaign and Content. At send time Flomailr adds the fields you filled in to each link, before tracking is applied. Links that already carry a `utm_` parameter and the unsubscribe link are left alone. Campaign sends add them. Automation emails do not.

## Site tracking

**Settings > Site tracking** gives you a script for your own site:

```html
<script async src="https://flomailr.com/track.js" data-flomailr-site="YOUR_SITE_ID"></script>
```

It records page views as `page_viewed` events, which can feed lead scoring and automations. It never creates a contact and never changes a subscription status. A page view only moves scoring or automations when the visitor arrived from a tracked link in one of your emails. Calling `flomailr.identify("customer@example.com")` attributes page views to a contact for reporting, but an address anyone can type proves nothing, so it moves nothing. The identity lives in `sessionStorage` and ends with the browser session.

## What is not measured

- Delivery per recipient. A message counts as sent when the mail provider accepts it.
- The plain-text part of an email. It has no image and its links are not rewritten.
- Which campaign an unsubscribe came from. The unsubscribe link identifies the contact only.
- Test emails and previews. They carry no tracking.
- Single sends. `send_email` and `POST /api/v1/send` add no image, rewrite no links and add no unsubscribe footer, so they record no opens or clicks, and their bounces are not counted in campaign stats. See [Transactional Send](/docs/api/send) and [Sending Safely with AI](/docs/ai/send-safely).

Flomailr stores each open's user agent and a salted hash of the IP address. The raw IP address is never stored.
