January 28th, 2026

Webhook signature verification

From now on, all Mailtrap webhooks will include cryptographic signatures, so you can verify that incoming requests genuinely come from us and haven't been tampered with.

If you use webhooks for deliverability monitoring, CRM sync, or auditing, this adds an extra layer of security using industry-standard cryptographic verification.

Notes:

  • Every webhook request is signed automatically

  • You can confirm the request originated from Mailtrap before processing it

  • No action needed to enable it β€” all existing webhooks will include signatures

To find your signature key, simply navigate to the webhook you want to configure, and it will be displayed in the webhook details.