Every clickable thing in a Leed email is rewritten before the message goes out. The image that reports an open, the unsubscribe link, the link to the page you featured, the links you typed yourself — each one becomes a URL that identifies the send and the individual recipient. That is what makes email the one traffic source that arrives already attached to a named person instead of an anonymous session.
The shape of a tracked URL
Tracked links point at your own site, not at Leed:
https://www.example.com/e/u/batch-9fa2/8c1d…e07.L3ByaWNpbmcv
│ │ │ │ │
│ │ │ │ └─ the destination, base64-encoded
│ │ │ └───────── the recipient hash
│ │ └──────────────────── the batch this send belongs to
│ └────────────────────── the hit type: i, u, f or o
└───────────────────────── the tracking prefixThe recipient hash is a SHA hash of the recipient’s row in the send list — not of their email address — so a tracked URL cannot be reversed into a mailbox, and the same person mailed twice gets two different hashes.
Because the prefix is on your own domain, tracked links inherit your certificate and your reputation. Nothing in the URL identifies Leed to the recipient.
| Path segment | What it is | Destination encoding | Response | Flag it sets | Event recorded |
|---|---|---|---|---|---|
i | The open pixel | the literal png | 200 with a 1×1 transparent PNG | opened | open |
u | A link click | base64 of a path, an absolute URL, or pageid: and a page id | 302 to the destination | clicked | click_page for a pageid: destination, otherwise click_url |
f | A file download | base64 of the asset path | 302 to the file | clicked | click_file |
o with .unsubscribe | The unsubscribe link | the literal unsubscribe | 200 carrying the URL of your site’s unsubscribe page | none | click_unsubscribe |
o with .out | The unsubscribe form’s submission | the literal out | 302 to your confirmation page | unsubscribed | opt_out |
The two o sub-actions are two steps of one flow, described end to end in unsubscribes and opt-outs.
What gets tracked automatically
Six of the variables Leed hands your email layout are already tracked URLs when you receive them — pixel, unsubscribe, homepage, page.href, asset.href and each recommendations[].href. You do not wrap them in anything; put them in the layout and they track.
On top of that, Leed makes one rewriting pass over the HTML you wrote. An anchor is converted into a tracked link when all of these hold:
- it is an
<a>tag with anhrefattribute written in straight double quotes; - the href is an absolute
http://orhttps://URL; - its hostname is your public site domain or the
www.form of it; - its path does not already contain
/e/.
The path, query string and fragment of the original URL are preserved, so https://www.example.com/pricing/?plan=growth#compare still lands exactly there — through the redirect, and with the click recorded.
Everything else is passed through untouched:
- links to other people’s sites;
- relative hrefs such as
href="/pricing/"— the rewriter only recognizes absolute URLs; - hrefs written with single quotes;
- links that are already tracked;
- anything that is not an
<a href>at all: a bare URL typed as text, an<img>on its own, a button built out of a form.
What each hit does
An open
The pixel request returns a 1×1 transparent PNG and sets opened on the recipient’s row. It is a flag, not a counter — the tenth open writes the same true the first one did.
A click
Leed decodes the destination. If it is a pageid: destination, the page’s current path is looked up at the moment of the click and used for the redirect — so a page you moved or re-slugged after sending still resolves, and an email you sent last quarter does not rot. That resolution runs through the same path table described in URL paths and slugs. Then clicked is set and the visitor is 302’d on.
A download
A link to a document behaves like a click — clicked is set — but records a click_file event carrying the asset id, then redirects to the file.
An unsubscribe click
Recorded here as click_unsubscribe, with no flag set. Clicking the link is not opting out; the opt-out happens when the form on the resulting page is submitted.
What every hit also does
Two side effects are shared by all four types:
- The contact is promoted to a verified address. A contact whose source was
formbecomesvalid_email— mail to that address demonstrably reached a human who acted on it. - The browser is bound to the contact. The session that made the request is attached to the contact record, which is why a visitor who arrives from an email is already identified when your site’s own analytics pick them up. That is one of the ways an anonymous visitor becomes a named one — see lead profiles and visitor identity for the others, and how Leed tracks visitors for what happens once they are on the page.
sequenceDiagram
autonumber
participant R as Email client
participant S as Your site
participant D as Leed
participant P as The page
R->>S: GET /e/u/{batch}/{hash}.{destination}
S->>S: Decode the destination
S->>D: If it is a pageid, resolve the page's path as of today
D-->>S: The current path
S->>D: Set clicked on the recipient's row
S->>D: Write a click event (best effort)
S-->>R: 302 to the resolved destination
R->>P: Load the page, already identified as this contact
Where the numbers land
Two stores, written at the same moment, with two different reliabilities.
The flags on the recipient’s row — opened, clicked, unsubscribed, bounced — are set directly and always written. They are what the Sent Emails table rolls up into its Opens, Clicks, Bounces and Unsubscribes columns, and what the Emails panel on a contact record reads to tag each send with the furthest action that person took.
The event rows are the granular feed: one row per hit, carrying the destination, the referrer and the timestamp. They are written best-effort, after the response has been decided, and a hit that cannot be tied to a browser session is skipped rather than stored. Capture never blocks the redirect or the pixel.
The practical consequence: a contact can show as opened in the rollup while the granular feed has no matching row. Do not treat the two as one number, and do not reconcile them.
That panel needs read access to contacts and a contact that is inside your plan’s contact limit — nothing more. The deeper per-reader activity and session history on the same record is a paid feature; contacts covers the record as a whole.
What tracking cannot tell you
Opens are approximate
An open is an image load, so every well-known distortion applies. Clients that block remote images suppress opens from people who did read the message; privacy proxies that pre-fetch images inflate them with opens no human performed. Because the flag is a boolean, neither distortion can compound — a proxy that fetches the pixel fifty times still produces one open.
Read opens as a direction, not a measurement. Clicks are the honest number.
Forwarded email is attributed to the original recipient
Preview sites do not track
Tracking endpoints answer preview requests with 204 and record nothing at all — no flag, no event. That is deliberate: your preview site exists to check how something looks, and rehearsing a send against it must not move real numbers. It also means you cannot verify tracking on preview; you verify it on a live send.
There are no event counts in the CMS
Nothing in the interface reports “opened four times” or “clicked at 09:14 and again at 17:40”. The flags are one-way and the rollups count recipients who did the thing at least once, never total hits. If you need per-hit detail, it is not in the product today.
When a tracking link fails
| Situation | Response | What is recorded |
|---|---|---|
| A normal hit | 200 (pixel), 302 (click, download, opt-out), or 200 with the unsubscribe page’s URL | the flag, plus an event if the hit is tied to a session |
| A preview request | 204 | nothing |
| The batch id or recipient hash is missing from the URL | 400 Malformed tracking URL | nothing |
| The batch or recipient does not exist | 404 Email list entry not found | nothing |
The destination cannot be decoded, or a pageid: destination has no current path | 400 Invalid Dest Request! | nothing |
| The hit cannot be tied to a browser session | the normal response — the pixel or redirect still works | the flag is set; the event row is skipped |
Two things follow. A link only works while the recipient’s row exists, so links in a send whose records have been removed stop resolving. And because Leed refuses to send a second message against a row that already has a send time, a given tracked URL belongs to exactly one message to exactly one person — there is no such thing as a re-used tracking link.