# Webhooks

> HMAC-signed webhooks for every email and resource event, batched and retried for three days. Test events, request logs, one-click retries and payload filters.

Webhooks you can build a business on. Real-time, HMAC-signed events for every email and resource change, delivered in batches and retried for three days until your endpoint says OK.

## At a glance

- **36** event types across emails and resources
- **11** automatic retry attempts with backoff
- **~3 days** retry window before an endpoint is paused
- **25** payload filter rules per endpoint on Pro

## Subscribe to exactly what you need

Twelve email events from accepted to complained, plus created, updated and deleted events for domains, audiences, subscribers, contacts, templates, suppressions and verifications.

- One endpoint or many, per environment
- Payload filters with 12 operators on Pro
- All or any matching rules

## Every request, visible and retryable

See each delivery to your endpoint with its status, response code and body. Retry a single request or every failed one with a click.

- Backoff at 5m, 30m, 2h, 5h, then 12h
- Email alert after three consecutive failures
- Endpoints auto-disable after three days of failures

## Trust every payload

Each request carries X-Emailit-Signature and X-Emailit-Timestamp headers. Verify them with a few lines of code and reject anything that does not match.

- Secrets shown once, rotate any time
- Batched JSON arrays for high volume
- Send test events with sample payloads

## Features

- **Real time**: Events leave within seconds of happening.
- **Batched payloads**: Multiple events per request when traffic spikes.
- **Test events**: Send realistic sample payloads to any endpoint.
- **Secret rotation**: Reset signing secrets without downtime.
- **Failure alerts**: We email you before your endpoint is disabled.
- **Payload filters**: Only receive events that match your rules (Pro and Business).

## FAQ

### How does Emailit retry failed webhooks?

Failed requests are retried with exponential backoff: after 5 minutes, 30 minutes, 2 hours, 5 hours and then every 12 hours, for 11 attempts over about three days. You can also retry manually from the request log.

### How do I verify a webhook signature?

Compute an HMAC-SHA256 of the timestamp and raw body with your webhook secret and compare it with the X-Emailit-Signature header. The docs include examples in several languages.

### How many webhook endpoints can I create?

Pay as you go includes 3 endpoints, Pro 10 and Business 100. Contract plans are flexible.

## Links

- Documentation: https://emailit.com/docs/webhooks/
- Pricing: https://emailit.com/pricing/
- Sign up: https://dash.emailit.com/register

---

Source: https://emailit.com/products/webhooks/
