Forwarding URL Security
Verify the Auth Token
Always verify that requests to your forwarding URL come from Lettr, not malicious actors. When you create an inbound domain, or later on the domain’s Mail Forwarding card, set an Auth token. Lettr sends it with every request in theX-MessageSystems-Webhook-Token header. Compare it against your stored value and reject anything that doesn’t match:
Lettr doesn’t store your auth token, so keep your own copy (for example in an environment variable). To rotate it, enter a new token on the Mail Forwarding card and click Save forwarding URL. Leaving the field blank keeps the token that is already set.
Don’t Rely on IP Allowlisting
Inbound mail is posted to your forwarding URL by SparkPost, the mail infrastructure behind Lettr’s inbound servers, and SparkPost publishes no fixed source IP addresses. An IP allowlist can’t reliably identify these requests, so use the auth token instead. If your endpoint sits behind Cloudflare or another firewall/WAF, allow server-to-serverPOST requests on your forwarding URL’s path. Otherwise the firewall may answer with a challenge page, and a non-2xx response makes the forwarding URL test fail when you create the domain or save a new URL.
Input Validation
Validate Email Addresses
Never trust email addresses from inbound emails:Sanitize Email Content
Sanitize HTML content before displaying or storing:Validate and Sanitize Filenames
Never use attachment filenames directly:Attachment Security
Validate File Types
Never trust the declared content type:Scan for Malware
Integrate with a virus scanner:Limit File Sizes
Enforce size limits to prevent resource exhaustion:Content Security
Prevent XSS in Displayed Emails
When displaying email content in a web interface:Block Tracking Pixels
Strip tracking pixels from received emails:Rate Limiting
Protect against email flooding:Logging and Monitoring
Audit Logging
Log all inbound email processing:Anomaly Detection
Monitor for suspicious patterns:Security Checklist
Forwarding URL Security
Forwarding URL Security
- Set an auth token and verify the
X-MessageSystems-Webhook-Tokenheader on every request - Store the token securely in environment variables
- Use HTTPS for your forwarding URL
- Allow server-to-server
POSTrequests through your firewall or WAF instead of relying on an IP allowlist
Input Validation
Input Validation
- Validate all email addresses
- Sanitize HTML content before storage/display
- Sanitize filenames before use
- Validate attachment content types
Attachment Security
Attachment Security
- Verify file types from content, not headers
- Scan attachments for malware
- Enforce size limits
- Store attachments outside web root
Monitoring
Monitoring
- Log all inbound email processing
- Monitor for rate limit violations
- Alert on anomalous patterns
- Track spam score distributions
Related Topics
Inbound Setup
Set the forwarding URL and auth token
Spam Filtering
Filter spam emails
Attachments
Handle attachments safely
Best Practices
Overall best practices