Help CenterUnderstand StramaHow Strama tells human email opens from bots

    How Strama tells human email opens from bots

    Security scanners and mail-privacy proxies open more of your emails than people do. Here is how Strama classifies every open and click at the moment it happens, which ones count toward your metrics, and what the Automated badge on an activity means.

    Updated today8 min read

    Open tracking has a dirty secret: a large share of "opens" are not people. Before Strama started filtering, roughly four in ten opens recorded across the platform came from software, not prospects. This article explains where those phantom opens come from, how Strama separates them from real reads, and what that means for the numbers you see on a step, a campaign, and your hot-leads list.

    Where phantom opens come from

    An email open is detected with a tracking image: a tiny picture embedded in the message that is fetched from Strama's servers when the email is displayed. Anything that renders or inspects the message will fetch that image, and a lot of software does exactly that before a person ever sees the email.

    • Pre-delivery security scanning. Google and Microsoft both open incoming mail, load its images, and follow its links to check for malware and phishing. This happens within seconds of the send, long before the recipient looks at their inbox.
    • Email security gateways. Tools like Proofpoint, Mimecast, and Barracuda, common at mid-size and enterprise companies, detonate every link and image in a sandbox.
    • Apple Mail Privacy Protection. Apple Mail prefetches images through Apple's own servers on the recipient's behalf, sometimes hours before (or without) an actual read.
    • You. Reading your own sent message inside Strama's inbox view would load the image too.

    None of these is a prospect reading your email. Left unfiltered, they inflate open rates, make dead leads look warm, and can trigger hot-lead alerts for people who never saw your message.

    Note: Filtering matters for more than vanity metrics. In Strama's own data, emails whose only opens were automated replied at a lower rate than emails that were never opened at all. An automated-only open is often a sign the message was quarantined, not read.

    How Strama classifies each open

    Every open and link click is classified the instant it is recorded, using a fixed set of rules. The first rule that matches wins.

    Who fetched it

    The fetch carries a browser signature, and the biggest sources identify themselves if you know what to look for.

    • Real Gmail reads always come through Google's image proxy, which labels itself. Strama treats those as genuine, no matter how fast they arrive or which network they come from.
    • Google's pre-delivery scanner uses a frozen browser signature from 2015 that no real person still runs. Any fetch carrying it is a scanner.
    • Microsoft Defender's link checker uses a specific frozen browser version too. Because a small number of real Windows users still run that version, Strama only calls it a scanner when the timing or the source network confirms it.
    • Named security gateways and command-line tools (Proofpoint, Mimecast, Barracuda, Zscaler, curl, Python clients, and so on) are always scanners.
    • Apple Mail Privacy Protection presents a bare, product-less signature that Strama recognises as a prefetch.
    • A fetch with no browser signature at all is never a person.

    When it happened

    Strama compares the fetch time to the moment the email was sent. A fetch within 60 seconds of sending cannot be a human reading the message, so it is classified as a fast open even when nothing about the signature gives it away. This catches scanners that are not on any list.

    The window is deliberately short. Real people do open emails within a minute or two, and Strama would rather count a few borderline scanners than throw away genuine reads.

    Where it came from

    Network location is used only as a tie-breaker, never on its own. Every real Gmail open arrives from a Google server, so blocking Google's network would erase your Gmail opens entirely. Strama consults the source network in one situation: a Defender-style fetch where no send time is available to check.

    Your own views

    When you read a sent message inside Strama, the image request is tagged as an internal view and is not recorded at all.

    The four classifications

    ClassificationWhat it meansCounts toward metrics?
    GenuineA person opened or clicked, as far as Strama can tellYes
    ScannerSecurity scanning, link detonation, or a programmatic clientNo
    Fast openFetched within 60 seconds of sending, no other tellNo
    PrefetchApple Mail Privacy Protection loading images on the recipient's behalfYes, as a weak signal

    Prefetches are counted on purpose. An Apple prefetch confirms the email was delivered to a real Apple Mail inbox and cleared spam, and prefetch-only emails reply slightly more often than never-opened ones. It is not proof the person read the email, so treat it as delivery confirmation rather than engagement.

    What you see in Strama

    Step and sequence counts. The open and click numbers on each step, and the engagement totals derived from them, include only genuine and prefetch activity. A step that was scanned five times and never read shows zero opens.

    Campaign stats and hot leads. The Engaged number on a campaign and the hot-leads list on your dashboard both use the filtered counts. A lead will not show up as heating up because a security gateway followed a link.

    The activity timeline. Open the tracking details on any sent email and you will see every event Strama recorded, including the automated ones. Automated events are greyed out and carry an Automated badge, and they are excluded from the headline Opens and Link clicks counts at the top of the panel. Nothing is hidden; it is just not counted.

    Tip: If a lead's timeline shows several Automated opens and nothing else, the message very likely landed in a security quarantine or a filtered folder. That is worth knowing before you send the next step.

    What open tracking still cannot tell you

    Opens are a soft signal even after filtering, and two blind spots remain.

    • Blocked images hide real reads. Many corporate mail clients and privacy-minded prospects never load images, so a message can be read carefully and register zero opens. Open counts undercount as well as overcount.
    • A prefetch is not a read. Apple's proxy fetches images whether or not the person ever scrolls to your email.

    The reliable signals are replies and link clicks. Repeated genuine opens do correlate with replies, so a lead who keeps coming back to an email is worth a look, but a single open should never change how you sell to someone.

    FAQ

    Why does a lead show opens in the timeline but zero opens in the count?

    Because every open on that email was classified as automated. The timeline lists all recorded events so you can see what happened; the counts, campaign stats, and hot-lead detection only include genuine and prefetch activity.

    My email was opened seconds after I sent it. Is that a bot?

    Almost certainly. Google and Microsoft scan incoming mail within seconds of delivery, before the recipient ever sees it. Strama classifies any open within 60 seconds of the send as a fast open and leaves it out of your counts.

    Are opens from Google or Microsoft networks always bots?

    No. Every real Gmail open is served through Google's image proxy, which runs on Google's network. Strama distinguishes real Gmail reads from Google's scanner by the browser signature each one presents, not by the network they come from.

    Do clicks get filtered the same way?

    Yes. Link clicks go through the same classification, which matters because link-detonation gateways follow every link in a message. An Automated click in the timeline means a scanner followed the link, not a person.

    Why did my open counts drop?

    When this filtering was introduced, historical activity was reclassified and counts were corrected. Around 40% of previously recorded opens turned out to be automated, so campaigns that ran before the change saw their open numbers fall. The new numbers are the honest ones.

    Can a real person ever be marked as automated?

    It is possible but rare. The fast-open rule could catch someone who reads an email within a minute of receiving it, and the Defender rule could catch a real user on a very old Windows browser who opens within a few hours of the send. Both cases are uncommon, and the trade-off was chosen deliberately: a slight undercount is far less misleading than counting scanners as interest.

    Was this article helpful?