Email Open Rate Is Broken. Measure Click-to-Open Instead
Published 6/22/2026 · 13 min read · Marketing & SEO tools
Open rate is measured with a one-pixel image: if the image loads, an open is recorded. Since 2021, Apple Mail Privacy Protection has broken that inference for users who enable it, because it routes remote content through Apple's proxy and loads it whether or not the message is ever read. Those loads register as opens, so open rate now moves with what mail software your audience uses rather than with how good your subject line was. Click-to-open rate does not escape this: CTOR is unique clicks divided by unique opens, so the contamination sits in its denominator. On a send of 50,000 delivered with 21,000 unique opens and 1,500 unique clicks, open rate is 42.0%, CTOR is 1,500 ÷ 21,000 = 7.14%, and click-through rate is 1,500 ÷ 50,000 = 3.00%. If only 12,000 of those opens were human, the real CTOR was 12.5% — but CTR stayed at exactly 3.00%, because neither of its terms involves an open. CTR is the number that survives. Track it as your headline engagement metric, keep CTOR as a creative diagnostic on segments with a stable mail-client mix, and stop reporting open rate as performance.
Apple Mail Privacy Protection pre-fetches tracking pixels, so a share of your opens were never opened by a person. Open rate now moves with your audience's mail client. Here is what survives, worked on a single send.
What Mail Privacy Protection actually does
An open is not an event a mail client reports. It is an inference: the email contains a transparent one-pixel image hosted on the sender's tracking domain, and if a request for that image arrives, the sender concludes the message was displayed. The inference was always imperfect — a preview pane could trigger it, a text-only reader could suppress it — but it held well enough to be useful for two decades.
Apple introduced Mail Privacy Protection with iOS 15 and macOS Monterey in 2021, and it attacks that inference deliberately. When a user turns it on, remote content in messages opened in Apple Mail is fetched through Apple's proxy servers rather than by the device, and it is fetched whether or not the person ever reads the message. Three things follow. The tracking pixel loads, so an open is recorded for messages nobody looked at. The IP address the sender sees belongs to Apple's proxy, so location and device inferences from opens become worthless. And the timestamp records when the proxy fetched the content, not when a human read anything, which is why send-time optimisation built on open timing has quietly stopped working for that portion of a list.
Be careful about how large that portion is. Apple does not publish adoption figures, and the share of any given list affected depends entirely on who is on it — a developer-tools newsletter and a retail list in the same country will differ enormously. Numbers circulating in industry commentary are estimates from panels and sender samples, not measurements of your audience. The useful question is not what the market average is; it is what share of your own recorded opens your email provider flags as proxy or machine opens. Several do report this, and if yours does not, that is worth asking about.
And what it does not do
It does not touch clicks. A click is not an inference — the recipient's browser requests a tracking redirect that the sender controls, and that request only happens because a human deliberately activated a link. No proxy pre-fetches your links on the recipient's behalf, so every click in your report corresponds to a person who chose to act. This is the single fact the whole article rests on, and it is why the metrics built on clicks kept working while the ones built on opens stopped.
Three other limits are worth stating plainly, because overclaiming here damages your credibility with anyone who knows the detail. Mail Privacy Protection is a feature of Apple's own Mail app; someone reading mail on an iPhone through a third-party app is governed by that app's behaviour, not by this. It is presented as a choice during setup, so it covers the users who accepted it rather than every Apple device. And other mail providers have long pre-fetched and cached images for their own reasons — image proxying was not invented in 2021, and open counts were never pristine. Apple's change made a pre-existing distortion large enough that it can no longer be ignored; it did not create the problem from nothing.
One send, three numbers
Take a campaign that reached 50,000 inboxes after bounces, recorded 21,000 unique opens and generated 1,500 unique clicks. Open rate is 21,000 ÷ 50,000 = 42.0%. Click-to-open rate is 1,500 ÷ 21,000 = 7.14%. Click-through rate is 1,500 ÷ 50,000 = 3.00%. All three describe the same send, and only one of them is a fact about human behaviour.
Now suppose your provider tells you that only 12,000 of the 21,000 opens came from devices, and the remaining 9,000 were proxy fetches — 42.9% of the recorded opens. The true open rate was 24.0%, not 42.0%. The true click-to-open rate was 1,500 ÷ 12,000 = 12.5%, not 7.14% — nearly double what you reported, and the campaign was far better at persuading readers than your dashboard said. Meanwhile the click-through rate did not move by a hair: 1,500 ÷ 50,000 = 3.00% before and after, because the correction touched a number that appears in neither its numerator nor its denominator. That is the practical test of a robust metric — it does not care what you learn later about the tracking.
Why CTOR is contaminated too, and how the three metrics are locked together
There is an identity worth committing to memory: click-through rate = open rate × click-to-open rate. Check it on the send above — 42.0% × 7.14% = 3.00%, exactly. It follows arithmetically, since (opens ÷ delivered) × (clicks ÷ opens) cancels the opens and leaves clicks ÷ delivered. And it tells you something uncomfortable: CTOR is what you get when you take the clean metric and divide it by the dirty one. Every distortion in the open count passes straight into CTOR, just with the sign flipped.
Send B makes the damage visible. Same list, 50,000 delivered, but 26,000 unique opens and 1,400 unique clicks. Open rate rises to 52.0%, a 23.8% improvement that would be celebrated in most reports as a subject-line win. Clicks fell from 1,500 to 1,400, a 6.7% decline, and click-through rate fell with them from 3.00% to 2.80%. Click-to-open collapsed from 7.14% to 5.38%, a 24.6% drop — much steeper than the 6.7% decline in actual behaviour, because the inflated denominator exaggerated it. Three metrics, three different stories, and the only honest one is that fewer people clicked. If those clicks convert at 4% on an average order of $80, send A produced 60 orders worth $4,800 and send B produced 56 worth $4,480. The send with the better open rate made $320 less.
Rebuilding the report
Promote click-through rate to the headline. It is clicks divided by delivered, it needs no assumption about what a mail client did on someone's behalf, and it is comparable across sends, across years and across the moment a mail provider changes its image handling. If a single number has to represent whether a campaign worked, this is the one that will still mean the same thing next year.
Keep click-to-open, but demote it to a diagnostic and use it only where its denominator is stable. Compared like with like — the same segment, the same month, the same mail-client mix — CTOR still answers a question CTR cannot: given that the message was seen, did the content persuade? A subject line that improves CTR by raising opens and a body that improves CTR by converting more of them are different achievements, and CTOR is how you tell them apart. Just never compare a CTOR across segments whose device mix differs, and never quote it as a benchmark against another company.
Then fix the things quietly broken downstream. Any automation that triggers on an open — a re-send to non-openers, a lead score, a sales alert — is now firing on proxy fetches, so rebuild those on clicks or on site behaviour. Any list-hygiene rule that suppresses subscribers with no opens in six months is now keeping addresses that never had a human behind them, which inflates your list and drags your deliverability. And any send-time optimisation trained on open timestamps is learning from the proxy's schedule. None of these were wrong when they were built; they simply rest on a signal that stopped meaning what it meant.
What a healthy set of email metrics looks like now
Four numbers carry a modern email report. Delivered, because everything else is a fraction of it and a change here explains changes everywhere. Click-through rate, as the engagement headline. Conversion rate on the clicks, because a click that lands on the wrong page is a failure the email cannot be blamed for. And revenue per thousand delivered, which is the only figure that lets you rank a small engaged list against a large indifferent one — $4,800 from 50,000 delivered is $96 per thousand, and that number is directly comparable to any other channel you buy.
Open rate can stay in the report, provided it is labelled honestly and used for the one job it can still do: detecting deliverability accidents. If open rate falls off a cliff across every segment at once, something happened to your inbox placement, and that is worth knowing quickly even from a polluted signal. What open rate can no longer do is tell you whether your subject line was good, whether this month beat last month, or whether you are ahead of a published benchmark. Reporting it as if it could is how a team ends up optimising a number that answers to Apple rather than to them.
| Metric | How it is computed | Send A | Send B | Moved by a machine open? |
|---|---|---|---|---|
| Delivered | Sent minus bounces | 50,000 | 50,000 | No |
| Unique opens | Recipients whose tracking pixel loaded at least once | 21,000 | 26,000 | Yes — this is the polluted counter |
| Open rate | unique opens ÷ delivered | 42.0% | 52.0% | Yes — directly, in the numerator |
| Click-to-open rate | unique clicks ÷ unique opens | 7.14% | 5.38% | Yes — inversely, through the denominator |
| Click-through rate | unique clicks ÷ delivered | 3.00% | 2.80% | No — neither term involves an open |
Worked with our own calculator
Click-to-open rate (CTOR) calculator
Given
- Unique clicks
- 50
- Unique opens
- 200
Result
- Click-to-open rate
- 25%
These figures are produced by the calculator below, not typed in by hand — they are recomputed whenever the tool changes.
Run it on your own figures →Frequently asked questions
- Is open rate completely useless now?
- Not useless, but no longer a performance metric. It still detects sudden deliverability problems: if opens collapse across every segment on the same day, your mail is landing somewhere other than the inbox, and a polluted signal falling to zero is still informative. What it can no longer support is any comparison — this month against last, your subject line against another, your list against a published benchmark — because the number now moves with the mail software your recipients use and with any change those vendors make to image handling. Keep it on the dashboard as a health check and take it out of the section where you report results.
- What is a good click-to-open rate?
- The question has become much harder to answer honestly, because two lists with identical content and identical readers can report very different CTORs purely from a different mix of mail clients. A list with a large share of proxy-fetched opens will show a lower CTOR than one without, for reasons that have nothing to do with the email. Published benchmarks compiled before 2021 are not comparable with today's numbers, and benchmarks compiled since then average across audiences whose device mix is not yours. Use your own trailing median on the same segment as the only reference point, and if you need a number to defend in a meeting, defend the click-through rate instead.
- Should I stop A/B testing subject lines?
- No, but change what you measure. A subject-line test that scores on opens is now partly measuring which variant happened to land in front of more proxy-protected inboxes, which is randomly assigned and therefore adds noise rather than signal. Score the test on click-through rate instead — clicks divided by delivered — because a better subject line that genuinely gets more people to read the message also gets more of them to the link, and that shows up in CTR. The cost is that CTR is a smaller number than open rate, so the test needs more recipients to reach the same confidence. That is the honest price of measuring something real.
- How do I clean an inactive list if opens cannot be trusted?
- Move the definition of active from opens to clicks and to anything else you observe directly. A subscriber who has clicked an email, visited the site from an email, replied, or bought in the last six or twelve months is active by evidence rather than by inference. Everyone else goes into a re-engagement sequence, and those who still do nothing observable get suppressed. This definition is stricter than an open-based one, so expect the active portion of your list to look smaller than it used to — that is the point. A list padded with addresses whose only sign of life was a proxy fetching an image is a list that quietly degrades your sending reputation while you congratulate yourself on its size.
- Do clicks have their own machine-traffic problem?
- A smaller one, and it is worth knowing about rather than ignoring. Corporate security gateways and some spam filters follow links in incoming mail to check where they lead, which can register as a click that no human made. The signature is distinctive: several links in the same message clicked within the same second, often every link, and frequently from the same organisation. Most email platforms filter this pattern out, and you can check yours by looking for recipients who apparently clicked everything instantly. The effect is real but far smaller than proxy opens, and it does not undermine the argument — a metric with a small correctable bias is still enormously better than one whose main input is a machine.
Articles you may find interesting
All guides →Related tools
Sources
Spotted a mistake in this article?