Mailgun Webhooks
Email delivery service. Receive events for deliveries, bounces, complaints, opens, and clicks.
Connecting Mailgun to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Mailgun. Then:
- 1Go to Mailgun Dashboard → Sending → Webhooks
- 2Click "Add Webhook" and select the event type
- 3Paste your Hookbase ingest URL
- 4Use the Webhook Signing Key from API Keys for verification
Signature verification
Mailgun signs its webhooks with HMAC-SHA256 in signature (in POST body), and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Mailgun can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Mailgun Dashboard → Settings → API Keys → Webhook Signing Key.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Mailgun event types
8 of the events people route most often. Hookbase accepts every event Mailgun sends, whether or not it is listed here.
delivered
A message was delivered
opened
A message was opened
clicked
A link in a message was clicked
bounced
A message bounced
complained
A recipient marked message as spam
unsubscribed
A recipient unsubscribed
failed
A message delivery failed permanently
stored
A message was stored (inbound)
What a Mailgun webhook looks like
A delivered payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"signature": {
"timestamp": "1678901234",
"token": "abc123def456",
"signature": "hmac-hash-here"
},
"event-data": {
"event": "delivered",
"timestamp": 1678901234,
"id": "msg-abc123",
"recipient": "user@example.com",
"tags": [
"welcome"
],
"message": {
"headers": {
"message-id": "msg-id-123@mailgun.org",
"subject": "Welcome!"
}
},
"delivery-status": {
"code": 250,
"message": "OK"
}
}
}Start receiving Mailgun webhooks
Create a source, paste the URL into Mailgun, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free