Cold Email Open Rates Are Lying to You: Bots, Scanners, and What to Measure Instead

The Sendvanta Team · September 12, 2026 · 9 min read

A client once sent me a screenshot of a campaign at a 71% open rate and asked why nobody was replying. The answer was in the timestamps: 340 of the 500 "opens" happened within four seconds of delivery, and 90 of them came from the same two /24 IP blocks. That wasn't a campaign with great subject lines. That was a security appliance reading her mail for her.

Cold email open rate accuracy has been degrading for years, and at this point the number at the top of most dashboards is closer to a measure of how much security tooling your prospects' employers bought than a measure of human interest. If you're optimizing subject lines, send times, or whole campaigns against that number, you're optimizing against noise — and sometimes against inverted signal.

Here's what actually broke, how to detect the garbage in your own reports, and what to track instead.

What broke the open pixel

An "open" is just an image request. Your sending tool embeds a 1x1 pixel with a unique URL, and when something fetches that URL, the tool logs an open. Three separate forces now fetch that pixel constantly without a human being involved.

Apple Mail Privacy Protection. Since iOS 15 in September 2021, Apple Mail pre-fetches remote images through a proxy for users who enable MPP — which is the default prompt, and most people tap accept. Every message is registered as opened, immediately, from a proxied IP that hides the recipient's real location. On B2B lists this matters less than in consumer email, but plenty of founders, contractors, and sales leaders read work mail in Apple Mail on an iPhone.

Gmail's image proxy. Google has cached remote images through googleusercontent.com since 2013. It doesn't fabricate opens the way MPP does, but it does strip most of the metadata people used to infer from opens — device, IP, location — and it can cache a first load in a way that mangles repeat-open counts.

Corporate link and content scanners. This is the big one for B2B. Microsoft Defender for Office 365 Safe Links, Proofpoint URL Defense, Mimecast, Barracuda, and a dozen others detonate every URL in an inbound message in a sandbox — including your tracking pixel, your CTA link, and your unsubscribe link. Some scan on delivery. Some scan again later, or again when the message is forwarded to a colleague.

The net effect: a meaningful share of your opens and clicks are machines. On heavily-filtered enterprise lists, I've seen accounts where the majority of recorded clicks came from scanners.

How to spot fake engagement in your own data

You don't need a vendor to tell you this is happening. Export a campaign's raw event log and look for these patterns:

  • Sub-10-second opens. A human does not open a 2:14 a.m. cold email 1.8 seconds after it lands. Cluster your open events by seconds-since-delivery and look at the shape of the curve. A spike in the first five seconds is scanner traffic.
  • Open and click with identical timestamps. Real people read, then click. Machines fire both in the same request burst.
  • Every link clicked in one session — including unsubscribe. No prospect clicks your calendar link, your case study link, and your unsubscribe link in the same second. A sandbox does exactly that. This one also quietly corrupts your suppression list if your unsubscribe is a bare GET link with no confirmation step.
  • Clustered by employer. If 14 of 20 contacts at the same company all "opened" within the same minute, you found their mail gateway, not their interest.
  • Datacenter user agents and IP ranges. Azure, AWS, and known security-vendor ranges. Real readers come from residential ISPs, mobile carriers, and corporate egress IPs that don't rotate every hit.
  • Opens with no follow-on behavior, forever. A 60% open rate paired with a 0.4% reply rate isn't a copy problem. It's a measurement problem.

Not all signals are equally corruptible

Here's how I'd rank the common metrics by how much you can trust them on a cold list in 2026:

SignalCorrupted byTrust levelUseful for
Raw open rateMPP, image proxies, scannersVery lowAlmost nothing on its own
Raw click rateSafe Links, URL Defense sandboxesLowNothing without filtering
Verified page visit (time-on-page, JS, scroll)Some headless browsersMedium-highReal interest, retargeting timing
Reply rateAuto-responders, OOOHigh (after classification)Copy, offer, and list quality
Positive reply rateLittleVery highThe metric that maps to pipeline
Bounce rateNothing meaningfulVery highList and verification quality
Complaint / unsubscribe rateScanner clicks on unsub linksHigh if confirmedDeliverability risk
Meetings bookedNothingVery highThe only number finance cares about

What to measure instead

Rebuild your campaign dashboard around four tiers, in this order:

1. Delivery health. Hard bounce rate (keep it under 2-3%; if it's higher, your verification is failing — see email verification for cold email), soft bounce trends, spam complaint rate, and inbox placement from seed tests. These are the numbers that determine whether anything else is even possible. They're also nearly impossible to fake.

2. Verified engagement. Not "clicked," but "a browser session that rendered JavaScript, stayed on the page more than a couple of seconds, and behaved like a person." A scanner fetches a URL; it doesn't scroll your pricing page for 40 seconds. If your tool can't distinguish those two events, treat all click data as directional at best.

3. Reply outcomes. Split replies into categories the moment they land: positive, referral/routing, not-now, hard no, auto-reply, bounce-shaped-as-reply. A 6% "reply rate" that's 40% out-of-office is really a 3.6% reply rate. For what normal looks like by industry and list size, see our cold email reply rate benchmarks.

4. Meetings and pipeline. Sends → positive replies → meetings held → opportunities. If you can only track one funnel, track this one backwards from revenue.

How to A/B test when you can't trust opens

The old workflow was: test subject lines on open rate because you get significant results fast, then test body copy on replies. The first half of that is dead. Subject line tests judged on open rate now mostly measure which variant looks more suspicious to a scanner.

Test on replies instead, and accept that you need more volume. Rough math: if your baseline reply rate is 3% and you want to detect a lift to 4.5% with reasonable confidence, you need somewhere around 2,000-3,000 sends per variant. Below that, you're reading noise. That means most small teams should test big swings — a different offer, a different segment, a different first line — not three flavors of the same subject line.

Two practical rules:

  • Run tests at the sequence level, not the email level. Total replies across all steps is the outcome you care about.
  • Don't declare a winner before your full follow-up cadence has finished. Step 3 replies routinely change the ranking.

Opens still have exactly one good use

Turn tracking off entirely and you lose a useful canary. Aggregate open rate, compared against itself over time, is a decent early warning for deliverability trouble. If a mailbox that consistently logs 45% opens drops to 12% over three days with no copy change, something moved — placement, reputation, or a filter rule. The absolute number is meaningless; the delta is informative.

The caveat: tracking pixels and custom tracking domains have their own deliverability cost. Open-tracking pixels are a known spam-filter signal, and a poorly-warmed custom tracking domain can drag your whole sending domain down. If you're running small volumes and care most about placement, turning off open tracking and monitoring inbox placement with seed mailboxes instead is a completely defensible choice.

Where Sendvanta lands on this

This is the problem Sendvanta was built around. Engagement events are classified before they hit your reports: scanner and prefetch traffic gets separated from human behavior using timing, user-agent, IP, and behavioral signals, so a verified visit means someone actually looked at your page and a reply means a person wrote back. Reply handling is unified across mailboxes, with auto-responders and bounces sorted out of your reply rate instead of inflating it.

The same signal quality feeds the deliverability side: layered health scoring across mailbox, domain, DKIM, and IP, seed-mailbox inbox-placement tests so you're measuring placement instead of guessing from opens, and automatic slow-down or pause when risk thresholds are crossed. One-click unsubscribe and suppression are on by default, and confirmed so a sandbox click doesn't silently opt out a live prospect.

You can run it on the free plan — $0 forever, 1,000 active leads, 3,000 emails a month, up to 10 of your own SMTP mailboxes — and compare the classified numbers against whatever your current tool reports. Paid plans start at $29/mo. Connecting your own Gmail, Microsoft 365, or SMTP mailboxes is free on every plan. More detail on the features page.

The short version

Stop reporting open rate to anyone who makes decisions. Report bounce rate, verified visits, classified replies, and meetings. Keep opens on an internal deliverability dashboard as a trend line, not a KPI. And the next time a campaign shows 70% opens and no conversations, check the timestamps before you rewrite the copy.

How accurate are cold email open rates in 2026?

Not accurate enough to make decisions on. Apple Mail Privacy Protection registers opens for messages nobody read, and corporate scanners like Microsoft Safe Links and Proofpoint URL Defense fetch tracking pixels and links automatically. Depending on your list's composition, anywhere from a large minority to a majority of recorded opens can be non-human.

Should I turn off open tracking for cold email?

For most small senders, yes — or at least stop reporting on it. Tracking pixels are a mild spam-filter signal and the data is unreliable. The exception is keeping aggregate opens as an internal trend line to catch sudden deliverability drops, which works even when the absolute number is wrong.

What is a reliable replacement for open rate?

Bounce rate and complaint rate for delivery health, verified page visits for real interest, classified reply rate (with auto-responders removed) for copy and offer quality, and meetings booked for outcome. Positive reply rate is the single best day-to-day metric for a cold campaign.

How do I tell a scanner click from a real one?

Look at timing and breadth. Clicks within seconds of delivery, multiple different links clicked in the same second, unsubscribe links hit alongside CTA links, datacenter IP ranges, and clusters of identical behavior across contacts at the same employer are all scanner fingerprints.

Can I still A/B test subject lines without open rate?

Yes, but judge them on replies, not opens. That requires roughly 2,000-3,000 sends per variant to detect a meaningful lift at typical reply rates, so test large differences — offer, segment, angle — rather than minor subject-line variations.

Ready to send outbound that lands?

Create your free Sendvanta workspace — no credit card required.

Start free