Webhooks
Receive a signed POST at your endpoint the moment something happens to a lead — replies, interest, bounces, unsubscribes, sends, opens and clicks.
Where: Settings → API & webhooks → Webhooks (lower half of the page)
How to do it
- Open Settings → API & webhooks and scroll to Webhooks.
- Enter your Endpoint URL (e.g. https://your-app.com/webhooks/mailfleet).
- Tick the events you want: Email sent, Email opened, Link clicked, Reply received, Reply — interested, Reply tagged (Interested, Meeting request, Question…), Email bounced, Lead unsubscribed. Reply received, Reply — interested, Email bounced and Lead unsubscribed are pre-ticked.
- Click Add webhook.
- On the webhook card, copy the signing secret (copy icon next to "signing secret whsec_…") into your receiver, then click Test to send a sample event — the result shows as ✓ 200 or ✗ with the error.
- Use Disable / Enable to pause an endpoint and the trash icon to delete it. Expand Recent deliveries to see the last 30 deliveries with their outcome and a Retry button on anything not delivered.
Good to know
- Available on every plan.
- Every POST is JSON: { id, event, workspaceId, occurredAt, data }. When the event concerns a lead, data.lead (id, email, first name, last name, company, title, status) and data.leadEmail are filled in; when it concerns a campaign, data.campaign (id, name) is added. Other fields depend on the event (step, sendId, subject, fromEmail, url, intent, preview, tag, kind).
- Headers: X-MailFleet-Event, X-MailFleet-Delivery (same as the body id), X-MailFleet-Attempt (1-based), X-MailFleet-Timestamp (unix seconds), X-MailFleet-Signature (hex HMAC-SHA256 of the raw body using your secret), User-Agent MailFleet-Webhooks/2.
- Your endpoint has 10 seconds to answer with a 2xx. Otherwise MailFleet retries with the same body and id after 1 min, 5 min, 30 min, 2 h, 6 h and 24 h (7 attempts in total), so dedupe on id.
- An endpoint whose events fail every retry 20 times in a row is switched off automatically with the message "Disabled after N events failed every retry… Fix the endpoint, then enable it again." Clicking Enable resets the failure count.
- The delivery log is kept for 30 days. Test events are one attempt only.
- Email bounced on a hard bounce at send or a bounce message received (for a received bounce message data.kind is bounced or blocked)
- Email opened fires on an email's first open and Link clicked on its first click that passes the human check; either can come from a mail-security scanner in the first minutes after sending — the campaign's numbers count such an open but leave out such a click.
- Endpoint URLs must be http(s); addresses on private or internal networks are refused.
- The secret is stored encrypted; the card shows its first 12 characters and the copy button gives you the full value.