Skip to main content
Receiving emails from external sources introduces security considerations. This guide covers best practices for securing your inbound email processing pipeline.

Forwarding URL Security

Verify the Auth Token

Always verify that requests to your forwarding URL come from Lettr, not malicious actors. When you create an inbound domain, or later on the domain’s Mail Forwarding card, set an Auth token. Lettr sends it with every request in the X-MessageSystems-Webhook-Token header. Compare it against your stored value and reject anything that doesn’t match:
Lettr doesn’t store your auth token, so keep your own copy (for example in an environment variable). To rotate it, enter a new token on the Mail Forwarding card and click Save forwarding URL. Leaving the field blank keeps the token that is already set.

Don’t Rely on IP Allowlisting

Inbound mail is posted to your forwarding URL by SparkPost, the mail infrastructure behind Lettr’s inbound servers, and SparkPost publishes no fixed source IP addresses. An IP allowlist can’t reliably identify these requests, so use the auth token instead. If your endpoint sits behind Cloudflare or another firewall/WAF, allow server-to-server POST requests on your forwarding URL’s path. Otherwise the firewall may answer with a challenge page, and a non-2xx response makes the forwarding URL test fail when you create the domain or save a new URL.

Input Validation

Validate Email Addresses

Never trust email addresses from inbound emails:

Sanitize Email Content

Sanitize HTML content before displaying or storing:

Validate and Sanitize Filenames

Never use attachment filenames directly:

Attachment Security

Validate File Types

Never trust the declared content type:

Scan for Malware

Integrate with a virus scanner:

Limit File Sizes

Enforce size limits to prevent resource exhaustion:

Content Security

Prevent XSS in Displayed Emails

When displaying email content in a web interface:

Block Tracking Pixels

Strip tracking pixels from received emails:

Rate Limiting

Protect against email flooding:

Logging and Monitoring

Audit Logging

Log all inbound email processing:

Anomaly Detection

Monitor for suspicious patterns:

Security Checklist

  • Set an auth token and verify the X-MessageSystems-Webhook-Token header on every request
  • Store the token securely in environment variables
  • Use HTTPS for your forwarding URL
  • Allow server-to-server POST requests through your firewall or WAF instead of relying on an IP allowlist
  • Validate all email addresses
  • Sanitize HTML content before storage/display
  • Sanitize filenames before use
  • Validate attachment content types
  • Verify file types from content, not headers
  • Scan attachments for malware
  • Enforce size limits
  • Store attachments outside web root
  • Log all inbound email processing
  • Monitor for rate limit violations
  • Alert on anomalous patterns
  • Track spam score distributions
Never trust any data from inbound emails. Senders can forge headers, spoof addresses, and include malicious content. Always validate and sanitize everything.

Inbound Setup

Set the forwarding URL and auth token

Spam Filtering

Filter spam emails

Attachments

Handle attachments safely

Best Practices

Overall best practices