Remote image URLs often contain a recipient or campaign identifier. Loading one tells its server that the resource was requested from your IP address at a particular time, even when scripts are disabled. Fonts and CSS imports can create similar requests. This preview removes linked styles and blocks external resources in both sanitization and Content Security Policy by default.

If you choose to enable remote resources, only visual image and font destinations are added to the frame policy. Scripts, connections, frames, objects, forms, and media remain prohibited. The iframe is sandboxed without same-origin or navigation privileges, and referrer information is suppressed.

A safe preview is not a deliverability test

Browser rendering is useful for spotting layout, copy, missing alt text, and obvious responsive problems, but email clients are not browsers with one shared feature set. Outlook desktop, Gmail, Apple Mail, and mobile clients can each transform CSS and markup differently. Test production campaigns in representative clients before sending.

To investigate where a received message traveled, use the email header analyzer. To decode an encoded subject or suspicious display name without rendering a body, use the email header decoder.