Sophos Phish Threat: Check missing images and Open Tracking
A missing campaign image and a missing Open event are two different findings. Sophos Phish Threat embeds visible campaign images in the message, while Open Tracking uses an externally loaded pixel. Sophos can also add a missing Open after a Click.
The key measurement limitation is therefore: An Open is normally generated when the tracking pixel is retrieved, but Phish Threat can also add one after a Click. A reported Open proves neither that the pixel was retrieved nor that a person read the message. Conversely, a missing Open does not prove that the message went unread.
Distinguish between the campaign image and tracking pixel
Sophos describes two types of image:
| Image type | Delivery | What it indicates |
|---|---|---|
| visible campaign images | embedded in the email as Base64 inline images | do not require retrieval from an external image URL; whether they appear depends on the Outlook client in use |
| transparent 1×1 pixel for Open Tracking | loaded from Sophos servers through a unique external URL | a retrieval can trigger an Open event |
The following combinations are therefore possible, among others:
- The campaign image is missing because the Outlook client does not support the embedded display.
- The campaign image appears, but the Open is missing because the external pixel was not loaded.
- An Open appears only together with a Click. It may then be the value added by Sophos rather than evidence that the pixel was retrieved.
During diagnosis, always record separately whether the campaign image, Open, and Click are present.
Documented behavior of Outlook clients
The following table reproduces the matrix documented in the Sophos KBA. The Android and iOS columns refer to the respective Outlook mobile clients, not to arbitrary email apps on those operating systems. In particular, the matrix does not support any conclusion about Apple Mail or Gmail.
| Image type | Classic Outlook for Windows | New Outlook for Windows | Outlook Web (OWA) | Outlook for Mac | Outlook for Android | Outlook for iOS |
|---|---|---|---|---|---|---|
| Campaign images | supported | not supported | not supported | supported | supported | supported |
| Pixel for Open event | supported with the GPO described in the KBA | not supported | not supported | blocked by default | supported | supported |
For New Outlook for Windows and Outlook Web (OWA), Sophos describes inline and URL images as blocked by default. Trust sender allows the user to load images for that specific sender. According to Sophos, an earlier centralized Safe Senders solution is no longer practical: Microsoft requires the complete sender address, for example sender@hr-benefits.site, rather than only the domain. Phish Threat templates use different sender addresses.
In Outlook for Mac, the embedded campaign images appear without an additional step according to the matrix. For the external pixel, the user must select Download external images. For Outlook for Android and Outlook for iOS, the matrix lists both image types as supported. These findings must not be extrapolated to other mobile email apps.
What an Open indicates
When the message is displayed, Outlook can retrieve the unique URL for the transparent pixel. If the request reaches Sophos, Phish Threat can register an Email open. However, the measurement does not show how attentively or for how long someone read the message.
There is also Click backfill: if a Click is registered without a preceding Open, Sophos subsequently adds the missing Open. Such an Open is not evidence that Sophos observed the pixel being retrieved earlier or at the same time. Two rules therefore apply when evaluating the results:
- An Open without a Click may be consistent with a pixel retrieval, but does not prove deliberate reading.
- An Open that appears only with or after a Click must not be documented as a successful pixel test.
Conversely, a person can read the text while Outlook blocks external images, so no pixel retrieval occurs. The Open Rate is therefore a technical signal with client-dependent limitations, not complete proof that a message was read.
Targeted diagnostic procedure
For a comparison test, use an approved test account and the exact Outlook client whose behavior is being tested. Record the client name, version, operating system, and times.
1. Record the initial state
After delivery, check the campaign image, Open, and Click separately. Do not click a campaign link yet. This makes it possible to determine whether an Open was recorded before a Click.
2. Display the message once
On first display, record the following:
- Are the subject and text displayed?
- Does the embedded campaign image appear?
- Does Outlook display a notice about blocked images or an untrusted sender?
- Is an Open reported without clicking a link?
In New Outlook for Windows and OWA, a missing campaign image matches the documented matrix and does not by itself prove that the network blocked it.
3. Test the documented client action
Only in the test account, perform the action described for the client:
- New Outlook for Windows or OWA: Trust sender
- Outlook for Mac: Download external images
Then check whether the campaign image and Open appear. Record the time and continue not to click any link. If the Open appears only after images are loaded manually, the result is consistent with client-side blocking of external images.
4. Test Click backfill separately
Only after completing the image test, click an intended test link. If Open and Click appear together, or the Open appears only afterwards, mark the Open as possible backfill. It must not be retroactively attributed to the earlier display of the message or to a pixel retrieval.
5. Narrow down deviations
If a result differs from the matrix, first verify the client and version and repeat the test with a fresh test case. Local policies or other components in the mail path are then possible causes, but they are not demonstrated by the two Sophos KBAs on which this article is based. Treat proxy, cache, privacy, or scanner behavior only as a hypothesis to be tested. Do not derive an exception or global allow rule without product-specific logs and documentation.
Source status and limits of the GPO information
This article is based on the Sophos articles KBA-000004984 and KBA-000005183. Their complete content was extracted through the public Salesforce Aura interface for editorial review. The stored Salesforce versions are ka0aJ000000UEQXQA4 and ka0aJ000000Cq2rQAC, respectively, and the content hashes match the source inventory.
However, the retrieval evidence has an important limitation: the stored bodies have neither a retrieval time nor a last_published_date. The additional HTTP 200 test confirms only the public loading shell, not that the article content delivered through it is current. The matrix is therefore described here as documented by Sophos, not as a currently confirmed live compatibility matrix.
KBA-000004984 describes a GPO for domain-joined computers running Classic Outlook that assigns tracking destinations to the Trusted Sites zone. These include wildcards in shared AWS namespaces. Because the currency of this information has not been established and these wildcards confer broad trust, this article deliberately provides no deployable list of GPO values.
For New Outlook and OWA, the same KBA does not describe an equivalent centralized solution. The Classic Outlook GPO must therefore not be applied to these clients.
Evaluate the result
A test is reproducible if it includes at least the following information:
- exact Outlook client and version,
- status of the campaign image before and after the documented client action,
- Open and Click times, including the time zone,
- an explicit indication of possible Click backfill,
- any policy change made and its rollback, if one was tested at all.
Open, Click, and training data can be associated with individuals. Unique pixel or campaign URLs must therefore not be included in publicly accessible tickets or screenshots. Do not use open rates alone to assess individuals: the documented differences between clients and Click backfill limit their significance.