You are correct — FusionAuth can add SMTP headers under Tenant → Edit → Email → Advanced → Additional headers, but those headers apply to all emails sent for that tenant. There is currently no way to set headers per-user or per-email.
Your two workarounds are both valid approaches:
Option 1: SMTP ProxyRoute FusionAuth's outgoing SMTP traffic through an SMTP proxy or mail-relay service. Your proxy can inspect the recipient, determine their consent state, and inject the required tracking headers before final delivery.
Option 2: Webhooks + External Mailer (Recommended for full control)Disable FusionAuth's built-in email templates and handle all email sending via webhooks to your own backend or third-party mailer. This gives you complete control over templating, state checking, and headers per user.
Webhook-based flow:Disable the built-in email templates in FusionAuth so it doesn't send anything itself. Navigate to Tenants → Edit → Email → Templates and set each template to disabled or leave it unassigned. You can also configure this at the application level under Applications → Your Application → Email → Templates to override tenant-level settings.
Set up webhooks under Settings → Webhooks, pointing to your backend endpoint. Enable the specific events you need.
Your backend listens for events, pulls relevant data from the webhook payload, checks user consent state, and sends the email through your own mailer with appropriate headers.
Key webhook events and payloads: Email Verification: verificationId to build the verification link Forgot Password: changePasswordId to build the reset link Setup Password: check user.password is null to confirm they need setup Breached Password (user.password.breach😞 user.email to notify them to change their password Suspicious Login (user.login.suspicious😞 event.info for device and location details (Enterprise feature) Registration Verification (user.registration.verified😞 verificationId to build the verification link MFA Method Added/Removed: method object with the method type and identifierImportant: If you use the webhook approach, make sure to disable all relevant email templates in FusionAuth. If you leave some templates enabled while your third-party mailer is active, users will receive duplicate emails — one from FusionAuth and one from your mailer.
Related Documentation Configure SMTP - Custom Headers - Information on configuring tenant-level SMTP settings including additional headers Announcing FusionAuth 1.32 - Custom Email Headers - Details on the custom email headers feature added in version 1.32 Events & Webhooks - Complete documentation on FusionAuth's webhook system Email Templates - Managing and disabling email templates Application-Specific Email Templates - Overriding email templates at the application level User Login Suspicious Event - Webhook payload for suspicious login events User Password Breach Event - Webhook payload for breached password events User Registration Verified Event - Webhook payload for registration verification events