Message templates and webhook security
Email and SMS templates use the same print-template system through another channel. Webhook settings have a trap: in production, an empty allowlist admits nobody.
Step by step
Find and edit a message template
- Side menu → Configuration → Settings. In the left column choose Email and SMS (faster with Search settings...), then the Email and SMS templates tab. The Templates screen opens.
- Above the list is a channel switch: All, Email, SMS, Print / PDF—each with a template count. This is navigation, not a filter; it remains after clearing the rest.
- Search with Search templates...; there are also About and Active filters. Columns are Template name, Code, Language, System, and Version.
- From a row menu, select Edit (preview without changes: Preview; copy: Duplicate—confirmation “Template duplicated”).
- Create a new template with New template—enter Template name, Code, and channel. Confirmation: “Template created.”
- Email and SMS templates also have Send test. After sending, you will see “Sent as test. See the Sending log.” Check the result there (Sending log — what happened to a message).
Editing, creating, and duplicating require Print templates permission, not Notifications. Previewing and printing from a completed template do not.
Allow access for delivery reports
The tab is called Delivery reports — access and is the last one in the Email and SMS section.
- Find the IP ranges used by your email or SMS provider in its documentation.
- Go to Configuration → Settings → Email and SMS → Delivery reports — access.
- In Email/SMS provider delivery reports, enter a range in the field with hint e.g. 3.5.140.0/22 and click + (or press Enter). The address appears as a marker in Allowed provider IP addresses (single IPs or ranges); click × on a marker to remove it.
- An invalid value produces “This is not a valid IP address or range: <entry>”.
- While the list is empty, a warning appears at the top: “The list is empty, so delivery reports are rejected.” After adding an entry, it turns green: “We accept reports from N IP addresses or ranges.”
- Leave Max reports from one IP address at
120/minunless the provider reports more. Format: number/unit (sec,min,hour,day); invalid format shows “Enter the limit as number/unit, e.g. 200/min.” - In Email open and click tracking, the switch has two labels: “Enabled — we count opens and clicks” and “Disabled — we do not count opens and clicks (the recipient will not notice).” Beside it is Max opens and clicks from one IP address, default
600/min; the field is disabled when tracking is off. - Click Save in the card's upper-right corner. An entry left in the address field rather than added with + is added automatically on save.
- Saving is a sensitive operation—the 2FA verification required window appears. Enter the Verification code and click Confirm. You will not be asked again for the next 15 minutes.
- Confirmation: green “Saved.” Failure: “Could not save.”
The tab itself does not protect anything. Every signed-in company member can read these settings without the Notifications permission; only saving requires 2FA. Hiding the tab in a role is not security (Permission traps — why granting access sometimes changes nothing).
How the provider proves a report came from them
Know this before debugging “webhooks are not arriving.” Security has two layers, and a request must pass both:
- Token—the provider sends it in the
X-Webhook-Tokenheader (or in the URL itself if its dashboard accepts only a URL). Set it on the sending account in Webhook Token (X-Webhook-Token header); the hint says: “Enter it in your provider panel (SES/SendGrid/Mailgun) as a custom header—it proves the webhook comes from you.” On our side the token is encrypted and looked up by hash; it identifies which company the report belongs to. A request without a matching token is refused. - IP allowlist—checked only after the token. In production, an empty list means reject everything; an address outside the list is refused.
Do not email the token to anyone or put it in a task description—it is equivalent to the password for that channel. To rotate it, enter the new token in both places: with the provider and on the sending account.
If the system is behind a proxy or Cloudflare, the allowlist sees the proxy's address until the deployment trusts the X-Forwarded-For header. Symptom: the ranges are correct, but requests are still refused. Contact the person responsible for the deployment.Templates
The Templates tab uses the same mechanism as print templates, but with another channel—email, SMS, or print. The same list also appears in the Documents section.
Practical consequence: editing templates requires Print templates permission, even when you access them from Notifications (Settings access — permission pitfalls).
Printing from a completed template does not require that permission.
Delivery reports — access
This tab configures protection for the public endpoints providers use to report bounces, complaints, opens, and clicks.
| Setting | Purpose |
|---|---|
| Allowed provider IP addresses | Networks from which reports are accepted |
| Max reports from one IP address | 120 per minute by default |
| Email open and click tracking | Main switch for opens and clicks |
| Max opens and clicks from one IP address | 600 per minute by default |
An empty list in production blocks everything
An empty allowed-address list means no incoming report is accepted in production. Not “all”—none.
One rule decides this, with different behavior in two environments:
| Address list | Development | Production |
|---|---|---|
| empty | accepts any address | rejects everything |
| populated | exact range matching | exact range matching |
This is intentional: missing configuration must not silently open production, so instead it stays closed until someone consciously enters ranges. The interface says directly: “Empty whitelist = no incoming webhooks in production.”
Practical result: if webhooks worked in tests and went silent after deployment, check here first. Enter the address ranges published by your provider.
Disable tracking
The main tracking switch stops collecting opens and clicks. After you turn it off, statistics stop increasing—this is not a fault but the result of this setting (Sending log — what happened to a message).
This can be a deliberate privacy choice.
Access note
The tab is shown to users with Notifications permission, but the server does not check this permission for the underlying mechanism—every signed-in company member can read the data, and any can save it with 2FA confirmation.
Keep this in mind when planning access: hiding the tab is not security (Permission traps — why granting access sometimes changes nothing).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo