Workspace, billing & integrations6 steps

Webhooks

Receive a signed POST at your endpoint the moment something happens to a lead — replies, interest, bounces, unsubscribes, sends, opens and clicks.

Where: Settings → API & webhooks → Webhooks (lower half of the page)

How to do it

  1. Open Settings → API & webhooks and scroll to Webhooks.
  2. Enter your Endpoint URL (e.g. https://your-app.com/webhooks/mailfleet).
  3. Tick the events you want: Email sent, Email opened, Link clicked, Reply received, Reply — interested, Reply tagged (Interested, Meeting request, Question…), Email bounced, Lead unsubscribed. Reply received, Reply — interested, Email bounced and Lead unsubscribed are pre-ticked.
  4. Click Add webhook.
  5. On the webhook card, copy the signing secret (copy icon next to "signing secret whsec_…") into your receiver, then click Test to send a sample event — the result shows as ✓ 200 or ✗ with the error.
  6. Use Disable / Enable to pause an endpoint and the trash icon to delete it. Expand Recent deliveries to see the last 30 deliveries with their outcome and a Retry button on anything not delivered.

Good to know

  • Available on every plan.
  • Every POST is JSON: { id, event, workspaceId, occurredAt, data }. When the event concerns a lead, data.lead (id, email, first name, last name, company, title, status) and data.leadEmail are filled in; when it concerns a campaign, data.campaign (id, name) is added. Other fields depend on the event (step, sendId, subject, fromEmail, url, intent, preview, tag, kind).
  • Headers: X-MailFleet-Event, X-MailFleet-Delivery (same as the body id), X-MailFleet-Attempt (1-based), X-MailFleet-Timestamp (unix seconds), X-MailFleet-Signature (hex HMAC-SHA256 of the raw body using your secret), User-Agent MailFleet-Webhooks/2.
  • Your endpoint has 10 seconds to answer with a 2xx. Otherwise MailFleet retries with the same body and id after 1 min, 5 min, 30 min, 2 h, 6 h and 24 h (7 attempts in total), so dedupe on id.
  • An endpoint whose events fail every retry 20 times in a row is switched off automatically with the message "Disabled after N events failed every retry… Fix the endpoint, then enable it again." Clicking Enable resets the failure count.
  • The delivery log is kept for 30 days. Test events are one attempt only.
  • Email bounced on a hard bounce at send or a bounce message received (for a received bounce message data.kind is bounced or blocked)
  • Email opened fires on an email's first open and Link clicked on its first click that passes the human check; either can come from a mail-security scanner in the first minutes after sending — the campaign's numbers count such an open but leave out such a click.
  • Endpoint URLs must be http(s); addresses on private or internal networks are refused.
  • The secret is stored encrypted; the card shows its first 12 characters and the copy button gives you the full value.

Try it in your own workspace

7-day free trial · unlimited mailboxes · cancel anytime.