1:"$Sreact.fragment"
2:I[60379,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"default"]
3:I[44345,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"default"]
5:I[96237,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"OutletBoundary"]
6:"$Sreact.suspense"
9:I[96237,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"ViewportBoundary"]
b:I[96237,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"MetadataBoundary"]
d:I[3222,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"default",1]
:HL["/_next/static/chunks/13rko6h92.kz_.css","style"]
0:{"P":null,"c":["","guide","how-to-audit-an-email-tracker-blocker",""],"q":"","i":false,"f":[[["",{"children":["guide",{"children":[["slug","how-to-audit-an-email-tracker-blocker","d",null],{"children":["__PAGE__",{}]}]}]},"$undefined","$undefined",16],[["$","$1","c",{"children":[[["$","link","0",{"rel":"stylesheet","href":"/_next/static/chunks/13rko6h92.kz_.css","precedence":"next","crossOrigin":"$undefined","nonce":"$undefined"}],["$","script","script-0",{"src":"/_next/static/chunks/12b9~mg3o6lnh.js","async":true,"nonce":"$undefined"}],["$","script","script-1",{"src":"/_next/static/chunks/0xs8ni7jz0o1p.js","async":true,"nonce":"$undefined"}]],["$","html",null,{"lang":"en","className":"h-full antialiased","children":["$","body",null,{"className":"min-h-full bg-ink-800 text-ink-50 font-sans","children":[["$","header",null,{"className":"border-b border-ink-600 bg-ink-800","children":["$","div",null,{"className":"container-x flex items-center justify-between gap-4 py-4","children":[["$","nav",null,{"aria-label":"Primary","className":"flex items-center gap-5 text-sm font-medium","children":[["$","a",null,{"href":"/","className":"text-ink-50 hover:text-brand-500","children":"Mailshade"}],["$","a",null,{"href":"/compare/","className":"text-ink-200 hover:text-brand-500","children":"Compare"}],["$","a",null,{"href":"/guide/","className":"text-ink-200 hover:text-brand-500","children":"Guides"}],["$","a",null,{"href":"/platform/","className":"text-ink-200 hover:text-brand-500","children":"Platforms"}]]}],["$","a",null,{"href":"https://mailshade.org/","className":"rounded-md bg-brand-500 px-4 py-2 text-sm font-semibold text-ink-900 hover:bg-brand-600","children":"See mailshade.org"}]]}]}],["$","$L2",null,{"parallelRouterKey":"children","error":"$undefined","errorStyles":"$undefined","errorScripts":"$undefined","template":["$","$L3",null,{}],"templateStyles":"$undefined","templateScripts":"$undefined","notFound":[[["$","title",null,{"children":"404: This page could not be found."}],["$","div",null,{"style":{"fontFamily":"system-ui,\"Segoe UI\",Roboto,Helvetica,Arial,sans-serif,\"Apple Color Emoji\",\"Segoe UI Emoji\"","height":"100vh","textAlign":"center","display":"flex","flexDirection":"column","alignItems":"center","justifyContent":"center"},"children":["$","div",null,{"children":[["$","style",null,{"dangerouslySetInnerHTML":{"__html":"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}"}}],["$","h1",null,{"className":"next-error-h1","style":{"display":"inline-block","margin":"0 20px 0 0","padding":"0 23px 0 0","fontSize":24,"fontWeight":500,"verticalAlign":"top","lineHeight":"49px"},"children":404}],["$","div",null,{"style":{"display":"inline-block"},"children":["$","h2",null,{"style":{"fontSize":14,"fontWeight":400,"lineHeight":"49px","margin":0},"children":"This page could not be found."}]}]]}]}]],[]],"forbidden":"$undefined","unauthorized":"$undefined"}]]}]}]]}],{"children":[["$","$1","c",{"children":[null,["$","$L2",null,{"parallelRouterKey":"children","error":"$undefined","errorStyles":"$undefined","errorScripts":"$undefined","template":["$","$L3",null,{}],"templateStyles":"$undefined","templateScripts":"$undefined","notFound":"$undefined","forbidden":"$undefined","unauthorized":"$undefined"}]]}],{"children":[["$","$1","c",{"children":[null,["$","$L2",null,{"parallelRouterKey":"children","error":"$undefined","errorStyles":"$undefined","errorScripts":"$undefined","template":["$","$L3",null,{}],"templateStyles":"$undefined","templateScripts":"$undefined","notFound":"$undefined","forbidden":"$undefined","unauthorized":"$undefined"}]]}],{"children":[["$","$1","c",{"children":["$L4",null,["$","$L5",null,{"children":["$","$6",null,{"name":"Next.MetadataOutlet","children":"$@7"}]}]]}],{},null,false,null]},null,false,"$@8"]},null,false,"$@8"]},null,false,null],["$","$1","h",{"children":[null,["$","$L9",null,{"children":"$La"}],["$","div",null,{"hidden":true,"children":["$","$Lb",null,{"children":["$","$6",null,{"name":"Next.Metadata","children":"$Lc"}]}]}],null]}],false]],"m":"$undefined","G":["$d",[["$","link","0",{"rel":"stylesheet","href":"/_next/static/chunks/13rko6h92.kz_.css","precedence":"next","crossOrigin":"$undefined","nonce":"$undefined"}]]],"S":true,"h":null,"s":"$undefined","l":"$undefined","p":"$undefined","d":"$undefined","b":"mailshade-static-v1"}
e:[]
8:"$We"
f:Tb38,{"@context":"https://schema.org","@graph":[{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://mailshade.org/"},{"@type":"ListItem","position":2,"name":"Guides","item":"https://mailshade.org/guide/"},{"@type":"ListItem","position":3,"name":"How to audit an email tracker blocker","item":"https://mailshade.org/guide/how-to-audit-an-email-tracker-blocker/"}]},{"@type":"Article","headline":"How to audit an email tracker blocker","description":"An extension with inbox access should be auditable. Here is how to audit an email tracker blocker — permissions, network calls, source — with Mailshade as example.","inLanguage":"en","image":"https://mailshade.org/og/guide/how-to-audit-an-email-tracker-blocker.png","mainEntityOfPage":"https://mailshade.org/guide/how-to-audit-an-email-tracker-blocker/","author":{"@type":"Organization","name":"Mailshade","url":"https://mailshade.org"},"publisher":{"@type":"Organization","name":"Mailshade","url":"https://mailshade.org"}},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"How can I tell what an email tracker blocker does with my inbox?","acceptedAnswer":{"@type":"Answer","text":"Check Chrome permissions, network calls, local and sync storage, then read the release-matched source. Mailshade exposes its opt-in hosts, local tracker history, Chrome Sync settings, paid auth/Polar calls and optional Hawk crash-report path."}},{"@type":"Question","name":"Does Mailshade send any inbox data to a server?","acceptedAnswer":{"@type":"Answer","text":"Core inbox history is not sent to Mailshade servers. Tracker history stays in local IndexedDB; settings can use Chrome Sync. Paid actions contact Mailshade auth/Polar, and privacy-filtered Hawk crash reports are optional and off by default."}},{"@type":"Question","name":"What permissions should a tracker blocker need?","acceptedAnswer":{"@type":"Answer","text":"A blocker needs DNR and access to the mail clients where it inspects message DOM. Mailshade asks you to opt into each supported client through Chrome instead of taking every inbox host at install; its other permissions are documented in the release source."}},{"@type":"Question","name":"Why does an open-source licence make auditing more trustworthy?","acceptedAnswer":{"@type":"Answer","text":"The published AGPL-3.0 release remains auditable, and modified covered versions carry corresponding-source obligations when distributed or offered over a network. A release-matched archive lets you inspect the exact published version."}},{"@type":"Question","name":"How much does Mailshade cost if I want to audit then buy?","acceptedAnswer":{"@type":"Answer","text":"The source is free to read under AGPL-3.0, and core protection stays free after a 14-day Pro trial. Paid Pro starts at $3.99 per month or $19 one-time for Founders Lifetime."}}]}]}4:["$","main",null,{"className":"container-x py-16","children":[["$","script",null,{"type":"application/ld+json","dangerouslySetInnerHTML":{"__html":"$f"}}],["$","article",null,{"className":"prose prose-ink max-w-none","children":[["$","h1",null,{"children":"How to audit an email tracker blocker"}],["$","p",null,{"className":"text-lg text-ink-200","children":"Any extension that can inspect trackers in your inbox deserves a concrete audit. Check the permissions it requests, the network calls it makes, the data it stores and the source that implements those paths. Mailshade publishes release-matched AGPL-3.0 source at mailshade.org/source/. You can verify that each mail client is opt-in; DNR blocks requests to known tracker-pixel domains; DOM scanning detects pixels and tracking links; tracker history stays in local IndexedDB with URLs reduced to origins; and core inbox history is not transmitted to Mailshade servers. You can also see Chrome Sync settings, paid auth/Polar calls and optional privacy-filtered Hawk crash reporting, which is off by default. This guide walks through that audit."}],"$L10","$L11","$L12"]}]]}]
13:T4ba,<h2>Step 1 — Read the permissions</h2><p>Open the extension's details in Chrome and check host access. Mailshade asks you to opt into each supported mail client instead of taking every inbox at install. Its manifest and source show the narrowly scoped mail hosts and the permissions used for DNR, storage, alarms, navigation and context-menu behavior.</p><h2>Step 2 — Watch the network</h2><p>Use DevTools while opening mail, changing settings and trying paid actions. Core inbox history should not be transmitted to Mailshade servers. Settings can use Chrome Sync; checkout, activation and account management contact Mailshade's auth service and Polar. If you explicitly enable crash reports, privacy-filtered errors can go to Hawk.</p><h2>Step 3 — Inspect storage and source</h2><p>The release source archive shows local IndexedDB tracker history with origin-only tracker URLs, sender and opaque message context. It also shows local link-pattern handling with a direct-or-original choice, rather than a remote redirect resolver.</p><h2>Why the licence matters</h2><p>AGPL-3.0 keeps the published source auditable, and release-matched archives let you inspect the version corresponding to a release.</p>10:["$","div",null,{"dangerouslySetInnerHTML":{"__html":"$13"}}]
11:["$","section",null,{"className":"mt-12","children":[["$","h2",null,{"children":"FAQ"}],[["$","details","0",{"className":"my-3","children":[["$","summary",null,{"className":"font-medium","children":"How can I tell what an email tracker blocker does with my inbox?"}],["$","p",null,{"className":"mt-2","children":"Check Chrome permissions, network calls, local and sync storage, then read the release-matched source. Mailshade exposes its opt-in hosts, local tracker history, Chrome Sync settings, paid auth/Polar calls and optional Hawk crash-report path."}]]}],["$","details","1",{"className":"my-3","children":[["$","summary",null,{"className":"font-medium","children":"Does Mailshade send any inbox data to a server?"}],["$","p",null,{"className":"mt-2","children":"Core inbox history is not sent to Mailshade servers. Tracker history stays in local IndexedDB; settings can use Chrome Sync. Paid actions contact Mailshade auth/Polar, and privacy-filtered Hawk crash reports are optional and off by default."}]]}],["$","details","2",{"className":"my-3","children":[["$","summary",null,{"className":"font-medium","children":"What permissions should a tracker blocker need?"}],["$","p",null,{"className":"mt-2","children":"A blocker needs DNR and access to the mail clients where it inspects message DOM. Mailshade asks you to opt into each supported client through Chrome instead of taking every inbox host at install; its other permissions are documented in the release source."}]]}],["$","details","3",{"className":"my-3","children":[["$","summary",null,{"className":"font-medium","children":"Why does an open-source licence make auditing more trustworthy?"}],["$","p",null,{"className":"mt-2","children":"The published AGPL-3.0 release remains auditable, and modified covered versions carry corresponding-source obligations when distributed or offered over a network. A release-matched archive lets you inspect the exact published version."}]]}],["$","details","4",{"className":"my-3","children":[["$","summary",null,{"className":"font-medium","children":"How much does Mailshade cost if I want to audit then buy?"}],["$","p",null,{"className":"mt-2","children":"The source is free to read under AGPL-3.0, and core protection stays free after a 14-day Pro trial. Paid Pro starts at $3.99 per month or $19 one-time for Founders Lifetime."}]]}]]]}]
12:["$","nav",null,{"aria-label":"Related pages","className":"mt-12","children":[["$","h2",null,{"children":"Related"}],["$","ul",null,{"children":[["$","li","/compare/email-tracker-blocker-open-source/",{"children":["$","a",null,{"href":"/compare/email-tracker-blocker-open-source/","children":"Open-source email tracker blocker"}]}],["$","li","/guide/how-email-tracking-works/",{"children":["$","a",null,{"href":"/guide/how-email-tracking-works/","children":"How email tracking works"}]}],["$","li","/guide/are-email-tracking-pixels-legal/",{"children":["$","a",null,{"href":"/guide/are-email-tracking-pixels-legal/","children":"Are email tracking pixels legal?"}]}]]}]]}]
a:[["$","meta","0",{"charSet":"utf-8"}],["$","meta","1",{"name":"viewport","content":"width=device-width, initial-scale=1"}]]
14:I[15637,["/_next/static/chunks/12b9~mg3o6lnh.js","/_next/static/chunks/0xs8ni7jz0o1p.js"],"IconMark"]
7:null
c:[["$","title","0",{"children":"How to audit an email tracker blocker before trusting it"}],["$","meta","1",{"name":"description","content":"An extension with inbox access should be auditable. Here is how to audit an email tracker blocker — permissions, network calls, source — with Mailshade as example."}],["$","meta","2",{"name":"robots","content":"index, follow"}],["$","link","3",{"rel":"canonical","href":"https://mailshade.org/guide/how-to-audit-an-email-tracker-blocker/"}],["$","meta","4",{"property":"og:title","content":"How to audit an email tracker blocker before trusting it"}],["$","meta","5",{"property":"og:description","content":"An extension with inbox access should be auditable. Here is how to audit an email tracker blocker — permissions, network calls, source — with Mailshade as example."}],["$","meta","6",{"property":"og:url","content":"https://mailshade.org/guide/how-to-audit-an-email-tracker-blocker/"}],["$","meta","7",{"property":"og:image","content":"https://mailshade.org/og/guide/how-to-audit-an-email-tracker-blocker.png"}],["$","meta","8",{"property":"og:image:width","content":"1200"}],["$","meta","9",{"property":"og:image:height","content":"630"}],["$","meta","10",{"property":"og:type","content":"article"}],["$","meta","11",{"name":"twitter:card","content":"summary_large_image"}],["$","meta","12",{"name":"twitter:title","content":"How to audit an email tracker blocker before trusting it"}],["$","meta","13",{"name":"twitter:description","content":"An extension with inbox access should be auditable. Here is how to audit an email tracker blocker — permissions, network calls, source — with Mailshade as example."}],["$","meta","14",{"name":"twitter:image","content":"https://mailshade.org/og/guide/how-to-audit-an-email-tracker-blocker.png"}],["$","meta","15",{"name":"twitter:image:width","content":"1200"}],["$","meta","16",{"name":"twitter:image:height","content":"630"}],["$","link","17",{"rel":"icon","href":"/favicon.ico?favicon.0x3dzn~oxb6tn.ico","sizes":"256x256","type":"image/x-icon"}],["$","$L14","18",{}]]
