Automation

Making an audit report email hold up in Gmail

An automated website audit delivered by email, checked against how Gmail treats message size, dark mode on phones and embedded images. What was measured, what could be confirmed and what is still open.

Pixedi AI Lab
  • 5 min read

SummaryUnder a minute

The short version

An automated website audit sends its result by email, so the email is designed around what Gmail handles poorly. It weighs 15 KB against a 102 KB clipping limit, uses no SVG, web fonts or background images, and keeps red to the score bar. Dark mode is checked on a real phone, and a separate signature test showed data-URI images arriving as embedded attachments.

Key takeaways

  1. The audit email is 15 KB, well under the 102 KB point where Gmail clips messages.
  2. Gmail's phone app force-inverts colors in dark mode, so that check has to happen on a real phone and a desktop preview cannot stand in for it.
  3. In a separate signature test, Gmail turned data-URI images into embedded attachments at send time and all 5 loaded for the recipient.
  4. Sending waits for a correct score, because a late email does less harm than one with a wrong score.
A woman checks her phone at a kitchen counter in the evening.

The question

An automated website audit is most useful when its result arrives by email while the request is still fresh. A typical audit of this kind runs about 50 checks in 8 categories and takes 10-60 s on a normal site, so the report can be ready within a minute or so. The email that carries it is the fragile part, because Gmail clips long messages and its phone app repaints colors in dark mode. The question here is whether a report email can stay under the clipping limit and hold up in dark mode on a phone. A smaller side question is whether small images can travel inside the message itself, with no outside server to load them from.

A small office desk with a closed laptop, a notebook and coffee in morning light.

The setup

The audit is an automated check of a public website. It reads the page, follows redirects, checks the certificate and 6 security headers, walks 12 internal links and queries the domain's mail records for 13 common DKIM selectors (a DKIM selector is the label a mail provider uses to publish the key it signs messages with). It also tests speed on phone and desktop and produces a weighted score from 0 to 100 with a plain label: Strong, Good, Needs work or Poor. Every finding carries a short note on why it matters and how to fix it.

The full detail lives on a private report page that opens from a link in the email, and the reader can save that page as a PDF from the browser. That page has its own test, which captures it on desktop and phone and checks the browser console for errors. The same test produces a PDF of the page, so the printed version can be inspected too.

Printed report pages lie on a wooden desk beside reading glasses and a pen.

That leaves the email with a short job: show the score with the main findings and hand over the link to the full report.

A few rules were fixed before the first send. The email uses no SVG, no web fonts and no background images, and red appears in one place only, the score bar. Limiting red to one element is a design judgment that makes the important number easier to spot, and it has no test result behind it. Size was tracked from the start, because Gmail clips messages over 102 KB.

There is also a second, smaller email: the automatic reply that confirms the request. It greets the requester by first name and repeats nothing typed into the form, which keeps the form from being used to push arbitrary text into a stranger's inbox, and the same address gets that reply once a day at most.

Images were the open question. Small pictures written straight into the HTML as text, known as data URIs, may or may not show up for the recipient. A separate signature test sent an email signature built that way and looked at what arrived.

Measurement

Each yardstick is tied to what the recipient sees. For size, the weight of the finished message is compared with Gmail's clipping limit. For dark mode, the check happens on a real device, because Gmail's phone app force-inverts colors in dark mode and a desktop browser can't reproduce that. A laptop preview shows the colors chosen in the template and leaves out the ones the app picks on its own. For images, the measure is what actually arrived on the other end of the signature test.

The form receiver that takes the audit request was tested before going public: 36/36 checks passed on the server side and 9/9 passed end to end in a browser. Those counts belong to the form receiver. The report page test above has no recorded pass count, so none is given here.

The limits are plain. Only Gmail was tested, so nothing here applies to other email apps. Gmail's dark mode behavior may shift when the app updates, so any phone check is tied to the day it was done. The data-URI result comes from a signature, which is a different message from the audit email, so it is reported as its own finding.

Results

The audit email is 15 KB, and Gmail's clipping point is 102 KB, so the message sits well under it.

Dark mode is the one check a desktop can't help with. The procedure is recorded (a real phone with dark mode switched on), but no written outcome exists, so none is described here.

The signature test gave the clearest result. Gmail turned the data-URI images into embedded attachments at send time, and all 5 loaded for the recipient. The same behavior hasn't been confirmed on the audit email itself, so for now it is a result from a related message.

A hand holds a glowing phone in a dim living room at night.

Timing turned out to matter as much as layout. On one heavy site on managed hosting, the phone speed test went past 100 seconds. A site like that now gets one more try with 300 seconds to work with, and the email goes out only when the results come back, since an email with a wrong score does more harm than one that arrives later. The request is saved before any email is sent, and a failed send is retried on a schedule that starts at 1 minute and stretches to 24 hours. The same address gets at most 3 reports in 24 hours, and a report is deleted after 180 days.

Takeaways

The most reusable habit is deciding up front what Gmail handles poorly, leaving it out of the design, and then measuring the finished message against the 102 KB limit. Size is easy to check, so there is no reason to learn about clipping from a recipient.

Dark mode needs a phone in hand. Gmail's forced inversion doesn't show up in a desktop preview at all, so a laptop preview is only good for checking the template's own colors. Each phone check should be logged with the date and app version, which didn't happen consistently here.

Data-URI behavior is worth testing on the actual report email from the start. A signature result is useful, but it is a different message, and the outcome was a clear answer for the signature and an open question for the email that matters.

The audit side had its own small trap. The first pattern used to read a site's robots.txt file could fall into catastrophic backtracking, where the matcher keeps retrying combinations and stalls, and that kind of slowdown quietly delays an email. Text parsing is worth testing against odd real-world files early. Saving the request first and waiting for a correct score before sending is a sound rule for any form that promises a result by email.

Current state

As of October 1, 2026, the form receiver has passed its documented tests (36/36 on the server side and 9/9 end to end in a browser), and the audit flow is not yet running in public.

Ask AI about this AI Lab note

Opens the assistant in a new tab with this page as the source.

Keep reading

Want this handled for your business?

Start with the free site audit: speed, search, mobile, security, local presence and email, in plain English.