@lacspace/track
Privacy-respecting open and click tracking for email campaigns: compact HMAC-SHA256 signed base64url tokens (WebCrypto) carrying campaign, message, a hashed recipient and issue time with TTL expiry; signed click redirects with the destination URL inside the token so there is no open redirect; constant-time verification; HTML injection of a 1x1 pixel and link rewriting that skips mailto/tel/anchors/unsubscribe/data-no-track/template links; plus open and click classification heuristics for Apple Mail Privacy Protection, Gmail image proxy and security-scanner bots. Zero dependencies, isomorphic.
npm i @lacspace/trackUsage
import { createTracker, classifyOpen, classifyClick, PIXEL_GIF } from "@lacspace/track";
const tracker = createTracker(process.env.TRACK_SECRET!, { ttlDays: 180 });
// When sending
const html = await tracker.injectHtml(campaignHtml, {
campaignId: "dashain-2026",
recipient: "sita@example.com",
messageId: "<a1b2@mail.lacspace.com>",
}, "https://t.lacspace.com", { unsubscribeUrls: ["https://lists.lacspace.com/u/9f8e"] });
// GET /o/:token (open pixel)
const open = await tracker.verify(token); // null if forged, tampered or expired
if (open?.kind === "open") {
const c = classifyOpen({ userAgent: req.headers["user-agent"], ip, at: new Date(), sentAt });
// record { ...open, ...c }
}
// always answer with the GIF, even for bad tokens
res.type("image/gif").send(PIXEL_GIF);
// GET /c/:token (click redirect)
const url = await tracker.resolveClick(token); // only a signed http(s) URL, else null
if (!url) return res.status(404).end();
res.redirect(302, url);Exports 5
PIXEL_GIFclassifyClickclassifyOpencreateTrackerfindTrackableLinksKeywords
More in Mail Kit
Compose bulletproof, responsive, dark-mode HTML emails from simple blocks, plus 13 ready-made transactional templates (OTP, verify, password-reset, magic-link, receipt, order, shipping, invitation, digest, announcement). Ships plaintext generation, preheaders and {{var}} i18n interpolation. Zero-dependency, isomorphic.
@lacspace/email-validateSmart, network-free email validation — RFC-5322 syntax (incl. quoted local parts & IP-literal domains), disposable/temp-mail & role-account detection, free-provider flags, Gmail normalization and 'did you mean?' typo suggestions. Zero-dependency, isomorphic.
@lacspace/email-verifyBest-effort email deliverability for Node — syntax + disposable/role, MX lookup with priority ranking, an optional SMTP RCPT probe (no mail sent), catch-all detection, a 0-100 confidence score, and de-duped batch verification. All DNS/SMTP injectable; zero npm dependencies.
@lacspace/mailerA tiny zero-dependency SMTP client for Node — send email over raw net/tls with STARTTLS & AUTH, plus a fluent MIME builder (inline images, attachments, alternatives), RFC 5322 address + RFC 2047 helpers, batch send with retry, and no-network test transports. Provider presets (Hostinger, Gmail, Outlook, Zoho…) make setup one line.
@lacspace/imapZero-dependency IMAP4rev1 client for Node (RFC 3501 + IDLE, MOVE, UIDPLUS, CONDSTORE, SPECIAL-USE, LIST-EXTENDED, LITERAL+, SASL-IR, QUOTA, ID). Implicit TLS and STARTTLS with verification on, LOGIN / PLAIN / XOAUTH2 / OAUTHBEARER, streaming byte-accurate parser, async-iterable FETCH, envelopes with RFC 2047 decoding, BODYSTRUCTURE trees shared with @lacspace/mime, modified UTF-7 mailbox names, special-use detection (incl. Gmail XLIST and localised names), IDLE with NOOP fallback. Works with Hostinger (Dovecot), Gmail, Outlook/Exchange, GoDaddy.
@lacspace/mimeIsomorphic RFC 5322 / RFC 2045-2049 MIME parser and builder for webmail. parseMime() turns raw mail (string or bytes) into from/to/cc/subject/date/text/html/attachments/inline cid images/priority/List-Unsubscribe one-click and the part tree; handles nested multipart (mixed, alternative, related, report, signed), message/rfc822 forwards, base64 and quoted-printable (tolerant), RFC 2047 encoded words (split multibyte, adjacent whitespace), RFC 2231 parameters, 30+ charsets and malformed input without ever throwing. parseBodyStructure() parses IMAP BODYSTRUCTURE (literals, extension data) into the same tree with IMAP partIds, plus findTextParts / listAttachments / decodePart for lazy fetching. buildMime() writes CRLF messages with encoded-word headers, QP/base64 bodies, mixed/alternative/related nesting, Message-ID generation and header-injection guards; replyHeaders() / forwardSubject() for threading. Pairs with @lacspace/imap and @lacspace/mailer. Zero dependencies; Node 18+, edge runtimes and browsers.