# Reliable email and SMS webhook processing

Use webhooks to start processing when an email, SMS, attachment or AI result arrives. MailSlurp delivers events at least once, so a successful receiver needs durable processing and duplicate handling in addition to a reachable URL.

## Receive, verify and queue

1. Parse the supported event type and retain its `messageId` and source resource IDs.
2. Verify `x-signature` with `x-message-id` using MailSlurp's signature verification endpoint.
3. Atomically insert the event into a durable queue or inbox table with a unique constraint on `messageId`.
4. Return a 2xx response after the insert succeeds. An already-recorded duplicate can also return 2xx.
5. Let a worker fetch the source message or result, process it and record completion.

[API endpoint: `verifyWebhookSignature`](/docs/api/#verifyWebhookSignature)

Do not acknowledge before durable storage: a crash after acknowledgement can lose work. Do not use an in-memory set as the only duplicate store because it disappears on restart and is not shared between workers.

## Make downstream actions repeatable

A worker can crash after writing to a CRM or sending a reply but before recording success. Use a destination idempotency key or transaction keyed to the logical action, not just a local boolean. Keep the source event, extracted result and destination record associated for recovery.

For [AI extraction results](/docs/ai-results/), validate the value before writing it. For [agent replies](/docs/agent-workers/), use claims, freshness guards and the completion endpoint's idempotency key. Apply the same principle to SMS processing.

## Inspect failures and redrive

MailSlurp retries unsuccessful webhook deliveries with backoff for up to 24 hours. Inspect the delivery result and HTTP response to distinguish an unreachable endpoint, authentication failure and application error. Fix the receiver, then redrive the affected result.

[API endpoint: `getWebhookResults`](/docs/api/#getWebhookResults)

[API endpoint: `redriveWebhookResult`](/docs/api/#redriveWebhookResult)

Redrive repeats delivery of the original payload, so the receiver must still deduplicate it. Redrive does not repair a downstream worker failure after your endpoint already returned 2xx; recover those jobs through your own queue.

## Test before enabling the workflow

Send the API's test payload and confirm signature handling, queue insertion and event routing. Exercise duplicate delivery, receiver failure, worker restart and a downstream timeout. Check that only one business action occurs when an event is replayed.

[API endpoint: `sendTestData`](/docs/api/#sendTestData)

[API endpoint: `waitForWebhookResults`](/docs/api/#waitForWebhookResults)

Continue with [webhook event schemas and setup](/docs/webhooks/), [forwarding](/docs/forwarding/) or [AI transformer mappings](/docs/ai-transformers/), depending on whether your destination needs the original email or structured fields.
