Your Open Rate Includes Your Own Team, and the Setting That Stopped It Broke Quietly

Your Open Rate Includes Your Own Team, and the Setting That Stopped It Broke Quietly

Source: a notice sent to Salesflare customers on 18 August 2026 by their co-founder, advising that entries in the Google Workspace Image URL proxy allowlist must be changed to the domain only — trakitd.com/, trailing slash included — because tracking image URLs now use a variable prefix and Workspace no longer matches more specific subdomain entries. What follows is my read on why that particular class of change deserves an executive’s attention.

If your CRM tracks email opens and your team is on Google Workspace, there is a setting in your admin console that decides whether your own staff count as prospects.

Most people reading this do not know whether it is set correctly. A smaller number set it correctly once, some years ago, and have every reason to believe it is still working. As of August, for at least one vendor, it is not — and the entry in the console still looks exactly right.

The mechanism, briefly

Open tracking works by embedding an image. When the recipient’s mail client loads that image, the sender learns the message was opened.

Gmail complicates this by routing images through Google’s own proxy, which is why open tracking in Gmail is approximate at the best of times. Google Workspace administrators can maintain an Image URL proxy allowlist — a list of URLs that bypass that proxy. Vendors ask you to add their tracking domain to it, and one of the things it buys you is the ability to tell your people apart from your prospects. Salesflare’s notice describes the benefit plainly: the allowlist helps it exclude your own and your team’s opens from tracking.

Without that working, an open is an open. It does not matter whose.

What changed, and why it is worse than an outage

The vendor changed how it builds tracking image URLs: they now carry a variable prefix. Google Workspace, meanwhile, does not match more specific subdomain entries any longer. Put the two together and an allowlist entry written as a subdomain stops matching the URLs it was written for.

Neither change broke it alone: variable URL prefixes plus subdomains no longer matching means the entry covers nothing

Note what does not happen when that occurs.

The entry is not deleted. It does not turn red. No validation fails, because the entry is still perfectly well-formed — it simply no longer describes anything that exists. The admin console will show it to you, correctly formatted, for as long as you care to look. Your CRM will keep reporting open rates without interruption, and those open rates will keep being numbers of exactly the kind you are used to seeing.

The only observable change is that a filter stopped filtering. There is no surface anywhere in the stack on which that appears as a fault.

The allowlist entry is still there, still valid, and matching nothing

I have been writing about this shape all month, in contexts that look unrelated. A redirect rule that deployed cleanly every time and never once fired, because the platform matched on a different part of the request than the rule assumed. An analytics setup where a property, an audit tool and a security policy all agreed the tag was working while the tag was absent from the page. This is the third instance of the same thing in a month, from three unrelated vendors: a control whose configuration remained valid while its effect quietly went to zero.

Why the contamination is not random noise

The instinct is to treat internal opens as a small, evenly spread inflation — a few percent on everything, annoying but harmless because it does not change the ranking of anything.

I do not think that holds, and the reason matters more than the size.

Consider who inside your business opens an outbound email. The rep who sent it, re-reading the thread before a call. The colleague who was copied because the deal is significant. The manager reviewing the account. A shared inbox that several people watch. Someone forwarding it internally to ask what to do next.

Who opens your own email: the rep re-reading it, the colleague copied in, the shared inbox, the manager reviewing — all four mean the deal is active

Every one of those is correlated with the deal being active. Internal opens do not spread evenly across your database. They concentrate on the records that are getting attention — which are, by definition, the records you are most likely to act on.

So the bias runs in the worst possible direction. Your most-discussed opportunities acquire the strongest apparent engagement signal, partly from your own staff. If open rate feeds lead scoring, follow-up prioritisation, or the decision about which sequence to keep running, you are being told that the deals your team is already excited about are also the deals the market is most excited about.

That is not noise. That is a feedback loop that agrees with you.

To be clear about what I am and am not claiming: the vendor’s notice establishes that the matching behaviour changed. The correlation argument above is my reasoning about the consequence, not something I have measured. Which is precisely why the next section is about measuring it rather than assuming it.

What to do this week

Check the entry itself. In the Google Workspace admin console, find the Image URL proxy allowlist. If your CRM’s tracking domain is listed as a subdomain, change it to the domain only, with the trailing slash. If it is not listed at all, that is the more urgent finding: you have never been excluding internal opens. Note that this is an admin-only setting, so the person who needs to make the change is probably not the person who owns the open rate.

Ask your vendor the direct question. Not “do you support open tracking” — every vendor does. Ask: how do you exclude our own team’s opens, what does that depend on, and how would we know if it stopped working? The third part is the one that gets a revealing answer.

Measure the contamination rather than estimating it. Send a tracked message to a colleague, have them open it, and see whether it registers as an open. That single test tells you what your allowlist is currently doing. It takes five minutes and replaces an assumption with an observation.

Then look for the step change. If the matching behaviour changed in August, your own opens re-entered the numbers at a specific point. Pull open rate by week across the last six months. A discontinuity that lines up with nothing you did to your campaigns is the size of the effect, handed to you for free.

Pull open rate by week: a step you did not cause is the size of the effect

Decide what the number is allowed to drive. This is the executive question and it survives whatever you find. An open is a weak signal even when measured perfectly — proxies, image blocking and preview panes all interfere. If a metric this fragile is currently gating follow-up priority or scoring, the problem is not only this month’s allowlist change.

Do these five: check the allowlist entry, ask how it would fail, test with a colleague, look for the step change, decide what it can drive

The general lesson

Software fails loudly. Configuration fails silently, and it fails most silently of all when the failure is a scope change rather than a syntax error.

Nobody deleted your allowlist entry. Nobody typed it wrong. The world moved a boundary underneath it, and a line that used to cover the thing it named now covers nothing, while remaining a perfectly valid line.

How configuration fails: not deleted, not malformed, just no longer matching

The controls in your business most likely to be quietly inert right now are the ones written once, by someone competent, against a third party’s URL scheme. They were correct when written, nothing has touched them since, and nothing will tell you the day they stop applying.

The only reliable test is the one that runs the thing end to end and looks at what comes out. For this particular control, that is one email, one colleague, and five minutes.


For technical deep-dives on the cloud and IT topics I cover strategically, visit Cloud Geeks — our specialist IT infrastructure blog.

Ganda Tech Services is my technology consultancy, bringing together cloud infrastructure, web development, and mobile expertise for Australian businesses.


Frequently asked questions

Does my email open rate include opens by my own team? It does unless something is actively excluding them. For Google Workspace users, that exclusion typically depends on your CRM’s tracking domain being correctly entered in the Image URL proxy allowlist in the admin console. If the entry is missing or no longer matches, internal opens are counted the same as any other.

What is the Google Workspace Image URL proxy allowlist? It is an admin-console setting listing URLs that bypass Google’s image proxy. Gmail routes images through that proxy by default, and vendors ask you to allowlist their tracking domain so open tracking behaves more predictably — including being able to distinguish your own staff’s opens.

Why did my allowlist entry stop working without any error? Because a scope change is not a syntax error. Salesflare’s August notice explains that its tracking image URLs now use a variable prefix and that Workspace no longer matches more specific subdomain entries, so an entry written as a subdomain covers nothing while remaining a valid entry. Nothing in the console reports this.

How do I test whether internal opens are being excluded? Send a tracked email to a colleague, have them open it in Gmail, and check whether your CRM records an open. That single end-to-end test tells you what the setting is doing right now, which no amount of reading the configuration will.

Should open rate drive lead scoring at all? Treat it cautiously. Open tracking is degraded by image proxies, preview panes and image blocking even when configured perfectly, and internal opens concentrate on the accounts your team is already discussing — so the inflation lands on exactly the records you are most likely to act on. Reply and click signals are considerably harder to contaminate.

Free Roadmap · 2026

Digital Transformation Roadmap 2026

A 12-month framework for Australian SMBs ready to modernise — phases, tools, and milestones.

No spam. Unsubscribe any time.