Webhook endpoint fields
- URL: An HTTPS URL you own, to which webhook payloads are delivered.
- Events: One or more event types to subscribe to.
- Signing key (optional): Included as the
x-webhook-signing-keyheader on each delivery so your handler can verify the request came from Paubox. Endpoints subscribed to inbound mail instead get a generated signing secret (whsec_...), shown once when you create the endpoint. See Verifying webhook signatures. - Active: Whether the endpoint receives deliveries. Defaults to
true.
Available events
Payloads
Every webhook notification includes anevent_name or event key and a payload or data key. The payload structure depends on the event type.
Outbound delivery events
Inbound mail received
Each email that arrives on one of your receiving domains produces oneemail.inbound.received event, usually within seconds. Mail classified as spam is included, with spam: true.
Email (
payload.data)
Attachments
Managing webhook endpoints via the API
Webhook endpoints for outbound delivery events can be managed programmatically. See the API reference for full details. To subscribe toemail.inbound.received, use the Paubox Dashboard.
Retry behavior
Inbound mail events are retried when your endpoint responds with429, a 5xx status, takes longer than 30 seconds, or can’t be reached. Paubox retries after 30 seconds, 2 minutes and 5 minutes, for up to 4 attempts in total. Any other non-2xx response is treated as final and isn’t retried. A 410 Gone response also disables the endpoint. Respond with a 2xx status once you’ve accepted the event. Because a retry can follow a request your endpoint did receive, deduplicate on payload.data.email_id.
Outbound delivery events: Paubox does not currently retry failed webhook deliveries. If your endpoint is unavailable when an event fires, that notification will not be re-sent. Design your endpoint to be highly available, and use the Get message receipt endpoint to poll for status if you need guaranteed delivery tracking.
Verifying webhook signatures
Inbound mail events
Every inbound mail delivery is signed with your endpoint’s signing secret (whsec_...), shown once when you create the endpoint. Each request carries two headers:
X-Paubox-Timestamp: when the request was signed, in Unix seconds.X-Paubox-Signature: a hex-encoded HMAC-SHA256 of<timestamp>.<raw request body>, keyed with the whole signing secret, including thewhsec_prefix.
- Read the raw request body before parsing it as JSON.
- Compute the HMAC-SHA256 of the timestamp, a
., and the raw body, using your signing secret as the key. - Compare it with
X-Paubox-Signatureusing a constant-time comparison. - Reject requests whose timestamp is more than a few minutes old. The timestamp is part of the signed content, so a captured request can’t be replayed with a fresh one.
Outbound delivery events
If you configured asigning_key on your webhook endpoint, Paubox includes it as the x-webhook-signing-key header on every delivery. Compare this value in your handler to verify the request came from Paubox.
For additional protection, use network-level controls such as IP allowlisting.