Real-Time Integration: Unlike polling APIs that require you to repeatedly check for updates, webhooks deliver event data instantly as it happens, making your applications more responsive and efficient.
What Are AhaSend Webhooks?
Webhooks are user-defined HTTP callbacks triggered by specific events in AhaSend. When an event occurs—such as an email being delivered or bouncing—AhaSend automatically sends a POST request to your webhook URL with detailed event data. This enables you to:Automate Workflows
Trigger actions in your application when emails are delivered or bounce
Monitor Performance
Track email engagement in real-time without manual checking
Update User Interfaces
Show delivery status updates to users immediately
Handle Errors
Respond to delivery failures or suppression events automatically
How Webhooks Work in AhaSend
Event Occurs
An event happens in your account (email delivered, bounced, opened, etc.)
Webhook Triggered
AhaSend identifies any webhooks configured for that event type
HTTP Request Sent
AhaSend sends a POST request to your webhook URL with event data
Your Application Responds
Your endpoint processes the event and returns a 2xx status code
Delivery Guarantee: AhaSend makes 6 attempts over about 16 minutes, including the first attempt. Only HTTP status codes 200-299 are considered successful.
Which Events Can I Receive?
Choose delivery, bounce, deferral, failure, suppression, open, click and domain-DNS events when configuring your webhook. The event reference lists every event, its filter flag and its payload. Inbound routes use the separatemessage.routing event.
Understanding Message Lifecycle
The message lifecycle helps you understand when different webhook events occur:Successful Delivery Path
- Reception: Email accepted and queued for delivery
- Delivered: Successfully sent to recipient’s mail server
- Opened: Recipient opens email (requires tracking enabled)
- Clicked: Recipient clicks tracked links (requires tracking enabled)
Bounce Scenarios
Hard Bounce (Immediate Failure)
Hard Bounce (Immediate Failure)
Soft Bounce with Recovery
Soft Bounce with Recovery
Soft Bounce with Final Failure
Soft Bounce with Final Failure
delivery_attempt object.Suppressed Email
Suppressed Email
How Do I Create a Webhook?

Access Webhooks Dashboard
- Log in to your AhaSend Dashboard
- Navigate to the Webhooks section from the main menu
- Click the “Add Webhook” button
Configure Webhook URL
Enter Your Endpoint URL:
- Provide the complete URL where you want to receive webhook events
- Must be a valid HTTPS URL (HTTP allowed for development)
- Should respond with 2xx status codes for successful processing
Select Events
Choose which events to receive:Option 1: All Events
- Select “Send all events to this endpoint URL”
- Simplest option, receives every event type
- Good for comprehensive logging or analytics
- Select “I’ll choose which events to send”
- Pick individual event types you need
- More efficient for targeted use cases
Create and Verify
- Click “Create Webhook” to save your configuration
- Note the Webhook Secret displayed on the details page
- Copy and store the secret securely for signature verification
How Do I Test a Webhook Locally?
Use CLI webhook testing to forward events to localhost and trigger sample events. Use sandbox sends to exercise delivery outcomes without real mail. Verify your webhook integration works correctly before going live:Use Test Events
- Go to your webhook details page in the dashboard
- Click “Send Test Event”
- Select which event types to test
- Click “Send Test Events”
message.delivered, message.transient_error, and message.bounced events
include representative delivery_attempt diagnostics; these values are
synthetic and were not observed from a destination mail server.Verify Response Handling
Ensure your endpoint:
- Returns 2xx status codes for successful processing
- Processes requests quickly (under 5 seconds)
- Handles duplicate events gracefully using webhook-id
- Validates webhook signatures for security
How Do I Verify a Webhook?
AhaSend follows the Standard Webhooks specification for secure webhook delivery:webhook-id is the delivery ID used for deduplication. The payload’s webhook_id or route_id identifies the configured endpoint, not the delivery.
Security Headers
Every webhook request includes security headers:webhook-id
webhook-id
Unique event identifier - Use as an idempotency key to prevent processing duplicate events from retries.
webhook-timestamp
webhook-timestamp
Unix timestamp when the webhook was sent - Use to reject old webhook attempts.
webhook-signature
webhook-signature
HMAC signature of the payload using your webhook secret - Verify this to ensure authenticity.
Signature Verification
Use Standard Webhooks libraries for easy verification:Standard Webhooks Libraries: AhaSend webhooks are fully compatible with Standard Webhooks libraries available for Python, JavaScript, Go, PHP, Ruby, Java, Rust, C#, and Elixir.
Webhook Payload Structure
All AhaSend webhooks follow the Standard Webhooks payload format:Message Event Example
Delivery Attempt Diagnostics
message.delivered, message.transient_error, and message.bounced can include
an optional data.delivery_attempt object describing the SMTP exchange behind
the event:
smtp_codeis always present when the object is present. A value of0means AhaSend recorded diagnostic text without an SMTP code.enhanced_status_codeis the enhanced status code, such as5.1.1, when one was recorded.responsecontains human-readable diagnostic text. Do not parse identifiers from it.descriptioncan contain a clearer translation of a complex response. Its wording may change, so use it only for display.classificationis the machine-readable failure category. Treat it as an open set and keep a fallback for values your integration does not recognize.commandis the normalized SMTP command name, such asRCPT TOorDATA.
null value is normal for retry
exhaustion, out-of-band bounces, non-SMTP routing, and attempts with no recorded
response. In particular, retry exhaustion is reported as message.failed,
which has no specific attempt to report.
Test webhooks and sandbox sends use representative diagnostics rather than an
observed SMTP exchange. A sandbox classification may not agree with its sample
SMTP code and response, so test classification-based behavior with production
events or fixtures you control.
Suppression Event Example
Best Practices
Reliability and Performance
Reliability and Performance
Handle Retries Gracefully:
- Use
webhook-idas an idempotency key to prevent duplicate processing - Store processed webhook IDs to detect and skip duplicates
- Return 2xx status codes quickly (under 5 seconds)
- Acknowledge receipt immediately with 200 OK
- Queue heavy processing for background workers
- Avoid database operations that could timeout
- Log webhook processing times and errors
- Set up alerts for failing webhooks
- Track webhook-related application metrics
Security Implementation
Security Implementation
Always Verify Signatures:
- Use Standard Webhooks libraries for verification
- Reject requests with invalid or missing signatures
- Check timestamp to prevent replay attacks
- Use HTTPS URLs for production webhooks
- Don’t expose webhook URLs publicly
- Consider IP whitelisting if needed
- Store webhook secrets in environment variables
- Never commit secrets to version control
- Rotate secrets periodically
Error Handling
Error Handling
Graceful Failure Handling:
- Return appropriate HTTP status codes
- Log webhook processing errors for debugging
- Implement circuit breakers for external dependencies
- Handle unexpected event types gracefully
- Validate event data before processing
- Don’t assume all fields will always be present
- Test webhook handlers with various event types
- Monitor webhook delivery success rates in dashboard
- Set up alerts for consecutive webhook failures
Why Did My Webhook Fail?
Webhooks Not Being Received
Webhooks Not Being Received
Check Your Configuration:
- Verify webhook URL is correct and accessible
- Ensure your server returns 2xx status codes
- Check firewall settings aren’t blocking AhaSend IPs
- Use “Send Test Event” feature in dashboard
- Test with tools like curl or Postman
- Verify your endpoint handles POST requests
- Check webhook delivery attempts in your dashboard
- Look for error messages and status codes
- Monitor retry attempts and failure patterns
Authentication Errors
Authentication Errors
Signature Verification Issues:
- Ensure webhook secret is correctly configured
- Use raw request body for signature calculation
- Check Standard Webhooks library implementation
- Using wrong webhook secret
- Modifying request body before verification
- Incorrect header name extraction
- Log incoming headers and payload
- Verify webhook secret matches dashboard
- Test with Standard Webhooks library examples
Performance Issues
Performance Issues
Timeout Problems:
- Reduce processing time in webhook handler
- Move heavy operations to background jobs
- Return 200 OK before processing starts
- Implement proper queuing systems
- Scale webhook processing horizontally
- Monitor resource usage during peak times
- Cache frequently accessed data
- Use database connection pooling
- Implement proper logging levels
Webhook Disabled
Webhook Disabled
Automatic Disabling:
- AhaSend disables webhooks after more than 100 consecutive failed attempts
- You’ll receive an email notification when this happens
- Fix underlying issues before re-enabling
- Identify and resolve the root cause
- Test your endpoint is working correctly
- Re-enable the webhook in your dashboard
- Monitor webhook success rates regularly
- Set up alerts for webhook failures
- Implement proper error handling and logging
Advanced Integration Patterns
Event-Driven Architecture
Use webhooks to trigger microservices, update user interfaces, and orchestrate complex workflows based on email events.
Real-Time Analytics
Stream webhook events to analytics platforms for real-time email performance dashboards and reporting.
Customer Support Integration
Automatically create support tickets from bounce events and delivery failures to keep your team informed.
Marketing Automation
Trigger marketing campaigns, update customer segments, and personalize user experiences based on email engagement.

