Why are pictures in my HTML e-mails replaced with ugly warning signs?
"This image has been removed for security reasons."
There are two kinds of images that come with your HTML e-mail: the ones that come attached with the e-mail itself, and others that link to remote sites. Images that are linked to remote sites are considered "unsafe" for the following reasons:
- Spammers can abuse this to validate your e-mail address
- The sender can know instantly if you have read their e-mail or not (privacy concern)
- Finding out information about your browser, operating system, and your mailserver (security concern).
Let's look at these issues in more detail:
Validating your e-mail address
Spammers can (and do) include specially-crafted image tags that include a "web bug" (usually a 1 pixel transparant image) used to validate that your e-mail address is a live one and that you actually read e-mail sent to this address. When such image is loaded, a request is sent to the spammer's server and it notes in its database of e-mail addresses that you have, in fact, received and read the spam e-mail they sent. Such addresses are re-sold to other spammers and the amount of spa