this post was submitted on 01 Jun 2026
424 points (99.8% liked)

Privacy

4724 readers
247 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
 

Gmail for android silently overwrites links in your emails, so it can track what you open

I clicked on a link inside an email from a privacy service, and was surprised to see they used google tracking for their stuff, so I opened it in thunderbird and behold, it had no tracking.

But the worst part is... if I went back again and long pressed the link on gmail, it showed the link preview, WITHOUT the tracking. There's some kind of rule, so try it first on a new, unopened email, without long clicking. You'll need something to intercept it because the browser will just redirect to the main link.

Imagine the mailman looking at you, noting down which letters you open, it's crazy.

I noticed this thanks to link eye, an app that intercept all browser links and shows a list of supported apps, so you can redirect to the preferred one. It also displays the link, it's abandoned but still working.

I'm 99% sure I have all the privacy stuff set correctly. I suppose it may also happen on desktop/ios, but I have no way to check it

Also fedia is not showing me a field to set the post title, so I'm sorry if everything ends up in the title or if the title is empty

long press

opened link

all 39 comments
sorted by: hot top controversial new old
[–] pulsewidth@lemmy.world 68 points 3 weeks ago* (last edited 3 weeks ago) (1 children)

Yes, this is shitty and grey pattern behaviour designed to fool even more seasoned email users into giving up more privacy.

However, do not use gmail for anything if you value your privacy. Failing that, there is no need to ever use the Gmail app, can easily use any of a hundred other mail apps on Android.

[–] GottaHaveFaith@fedia.io 8 points 3 weeks ago (3 children)

I already have another service, sadly these are "legacy" accounts that I cannot discard

[–] Zwiebel@feddit.org 13 points 3 weeks ago (1 children)

Then use the thunderbird app!

[–] buffing_lecturer@leminal.space 4 points 3 weeks ago* (last edited 3 weeks ago)

And/or try to change the email address these services use

The issue isn't even which app you read email with anyway; Google is actually modifying your raw email content to embed links within tracking urls. They do it to calendar links as well, and they've been doing this for at least a few years now.

[–] notmeee@lemmy.zip 4 points 3 weeks ago

Then use FairEmail for that account.

[–] Jason2357@lemmy.ca 43 points 3 weeks ago (2 children)

Absolutely everything is tracked in Gmail. Spend an extra second hovering over the send button for Sara's email and it will be in their data model for you. That's the whole point of Gmail for them.

Even without redirect links, it would be entirely possible to use other app mechanisms to track which links are clicked.

[–] HeyThisIsntTheYMCA@lemmy.world 2 points 3 weeks ago

I remember being real excited about the eye tracking software getting better, as it meant we'd likely be able to communicate with my aunt better (we can communicate To just fine) and then thought about how we have these cameras pointed at our faces a lot.

[–] Kissaki@feddit.org 21 points 3 weeks ago (2 children)

Outlook replaces weblinkes in emails as well, to a "safelinks" redirect URL. Certainly a security feature, but man it's annoying. Not just the redirect, and the potential tracking, but when a readable URL to my build server build turns into a multiline cryptic unreadable mess and then pollutes my webbrowser history - fuck.

I already thought about a Thunderbird extension where I can replace them back to their original.

(My workplace uses Outlook.)

[–] LodeMike@lemmy.today 2 points 3 weeks ago

It's literally never done anything except add delay. It shouldn't be showing the fucking link if its dangerous especially because there's ways around it.

[–] Dymonika@beehaw.org 1 points 3 weeks ago* (last edited 3 weeks ago) (1 children)

But does it do this even if you access Outlook from the web at: outlook.office365.com

That's what I do for my work; I don't have the app installed and just check manually.

[–] Kissaki@feddit.org 1 points 3 weeks ago

When I access through Thunderbird via IMAP the emails have been rewritten. It's not local to the Outlook client software.

I think my webmail is outlook.office.com, dunno if that's the same as outlook.office365.com. It may be a org/account setting managed by my org. Maybe you also don't receive emails with unlabeled links, where it's very obvious that they're replaced. On linked text, only if you notice the URL you're opening.

[–] cronenthal@discuss.tchncs.de 16 points 3 weeks ago (2 children)

Outlook does this, too. All in the name of security, of course.

[–] iamthetot@piefed.ca 3 points 3 weeks ago

Can confirm.

[–] wyldrstallyns@lemmy.dbzer0.com 1 points 3 weeks ago* (last edited 3 weeks ago)

Yeah, their financial security, and no one else's anything.

[–] Anon518@sh.itjust.works 12 points 3 weeks ago (1 children)

It's not just their mobile app. Gmail on desktop browsers (firefox) does something similar. You can see it in your "history" after clicking a link.

[–] Dymonika@fedia.io 1 points 3 weeks ago

Thanks for the reminder to ditch it for Thunderbird!

[–] slazer2au@lemmy.world 12 points 3 weeks ago

Not shocking as how else does google pay for Gmail if it can't build a better advertising profile on you?

[–] ramenshaman@lemmy.world 9 points 3 weeks ago

Within the last week or two I started fully committing to Tuta and I don't give out any of my gmail addresses for anything. I wish I'd done it sooner.

Soon (maybe this week) I'm going to buy a device to use as an Immich server. People online say they've had good performance with a Raspberry Pi 5 so I'll probably try that first.

Fuck Google.

[–] foxfell@lemmy.ml 6 points 3 weeks ago (1 children)

Hi, just tested and it's not doing this to me. Links are showing, copying, and opening correctly.

[–] crandlecan@lemmy.zip 8 points 3 weeks ago (2 children)

May I ask how you checked for any redirects?

[–] foxfell@lemmy.ml 2 points 3 weeks ago* (last edited 3 weeks ago)

Sorry, probably I had outdated app version, now I clearly see google.com loading first. Disgusting.

[–] HubertManne@piefed.social 4 points 3 weeks ago (1 children)

gmail does this in general. whats really annoying is you can use the browser copy clean link and im not sure if they are not following standards or what but you still get the google encapsulated link.

[–] Flagstaff@programming.dev 1 points 3 weeks ago (1 children)

That useless "feature" has never worked for me, I think literally once. I use my own AutoHotkey link-cleaning script that I have yet to find out how to port over to Linux.

[–] HubertManne@piefed.social 1 points 3 weeks ago

I should do something like that but im lazy and just mannually delete the begininig part.

[–] beeng@discuss.tchncs.de 2 points 3 weeks ago (1 children)

Do K9 or thunderbird mail on Android do this? (even if you use gmail as backend?)

[–] CallMeAl@piefed.world 13 points 3 weeks ago

No, only the official google clients do link hijacking. Thunderbird doesn't do it.

[–] KuroiKaze@lemmy.world 1 points 3 weeks ago (2 children)

Did you think an amazing system like Gmail was free? I know when I use stuff like that what the cost is but I get virtually nothing important in email anyway.

[–] Footer1998@crazypeople.online 7 points 3 weeks ago (1 children)

until google decides that your online behavior is bad and blocks your access to your gmail account because you criticised fascism

[–] mirshafie 4 points 3 weeks ago

That is why I, as a citizen, am always on my best behavior.

[–] Flagstaff@programming.dev 7 points 3 weeks ago (1 children)

... like banking alerts, your vehicle registration renewal notices, and tax e-filing updates? What world do you live in for email to not be critical?

[–] KuroiKaze@lemmy.world 0 points 3 weeks ago (1 children)

They mostly just say, log into blah blah to read a message. Not exactly a treasure trove of data

[–] Flagstaff@programming.dev 1 points 3 weeks ago

I suppose, but some of them show your actual balance, etc.

[–] Taleya@aussie.zone 1 points 3 weeks ago

Does the same thing from gsheets. Cracks me up seeing it try to track an Aspera ssh tunnel that's literally only accessible from one IP.

[–] Blackmist@feddit.uk 0 points 3 weeks ago (1 children)

Like they're not just tracking it in the browser and OS anyway.

[–] ayush@reddthat.com 8 points 3 weeks ago

@Blackmist@feddit.uk - I have heard people make comments on the same lines before. Generally my response is - "oh, so that makes it ok?"

But I want to do better. Could you please help me understand what's the underlying point you were trying to make? Thank you!-