<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with smtp]]></title><description><![CDATA[A list of topics that have been tagged with smtp]]></description><link>https://fusionauth.io/community/forum/tags/smtp</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 00:43:52 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/smtp.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[What are the outbound IP addresses for a FusionAuth Cloud deployment?]]></title><description><![CDATA[<p dir="auto">For FusionAuth Cloud deployments, you can obtain the outbound IP address list by opening a support ticket in the <a href="https://account.fusionauth.io/account/support/" rel="nofollow ugc">FusionAuth Account Portal</a> and providing your deployment hostname.</p>
<p dir="auto">Key facts about FusionAuth Cloud outbound IPs:</p>


<p dir="auto"><strong>Complete list</strong>: FusionAuth will provide the complete list of outbound IP addresses for your specific deployment. These are the only addresses your deployment will use. Note that IP addresses are not exposed through the user interface—opening a support ticket is the only way to obtain them.</p>


<p dir="auto"><strong>Static addresses</strong>: The outbound IP addresses are static and will not change during:</p>

Upgrades
Maintenance windows
Normal scaling operations

<p dir="auto">For new FusionAuth Cloud deployments, static IP addresses are already configured. If the IP addresses ever need to change, FusionAuth will notify you in advance.</p>


<p dir="auto"><strong>All outbound traffic</strong>: All outbound traffic from your FusionAuth Cloud deployment originates from the same set of IP addresses, including:</p>

SMTP/email traffic
Webhooks
HTTP calls from Lambdas
Any other outbound connections



<p dir="auto">You can safely use these IP addresses to configure firewall rules, SMTP server allowlists, and other security restrictions for services that need to accept connections from your FusionAuth Cloud deployment.</p>
<p dir="auto"><strong>Important</strong>: The provided IP addresses should only be used to allow outbound traffic through firewalls and network control layers. Do not use them for HTTP/API calls, as they won't respond to such requests. In addition to IP allowlisting, consider using custom headers, TLS transport, and client certificates to further secure outbound traffic.</p>
Related Documentation

<a href="https://fusionauth.io/docs/get-started/run-in-the-cloud/cloud#deployment-ip-addresses" rel="nofollow ugc">Deployment IP Addresses</a> - Official documentation on obtaining IP addresses for FusionAuth Cloud deployments
<a href="https://fusionauth.io/docs/get-started/download-and-install/reference/account-portal#support" rel="nofollow ugc">FusionAuth Account Portal - Support</a> - How to access the support portal to request IP addresses
<a href="https://fusionauth.io/docs/get-started/run-in-the-cloud/cloud" rel="nofollow ugc">FusionAuth Cloud Overview</a> - General information about FusionAuth Cloud deployments

]]></description><link>https://fusionauth.io/community/forum/topic/3218/what-are-the-outbound-ip-addresses-for-a-fusionauth-cloud-deployment</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3218/what-are-the-outbound-ip-addresses-for-a-fusionauth-cloud-deployment</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[How to add custom SMTP headers per user for tracking consent?]]></title><description><![CDATA[<p dir="auto">You are correct — FusionAuth can add SMTP headers under <strong>Tenant → Edit → Email → Advanced → Additional headers</strong>, but those headers apply to all emails sent for that tenant. There is currently no way to set headers per-user or per-email.</p>
<p dir="auto">Your two workarounds are both valid approaches:</p>
Option 1: SMTP Proxy
<p dir="auto">Route FusionAuth's outgoing SMTP traffic through an SMTP proxy or mail-relay service. Your proxy can inspect the recipient, determine their consent state, and inject the required tracking headers before final delivery.</p>
Option 2: Webhooks + External Mailer (Recommended for full control)
<p dir="auto">Disable FusionAuth's built-in email templates and handle all email sending via webhooks to your own backend or third-party mailer. This gives you complete control over templating, state checking, and headers per user.</p>
Webhook-based flow:


<p dir="auto"><strong>Disable the built-in email templates</strong> in FusionAuth so it doesn't send anything itself. Navigate to <strong>Tenants → Edit → Email → Templates</strong> and set each template to disabled or leave it unassigned. You can also configure this at the application level under <strong>Applications → Your Application → Email → Templates</strong> to override tenant-level settings.</p>


<p dir="auto"><strong>Set up webhooks</strong> under <strong>Settings → Webhooks</strong>, pointing to your backend endpoint. Enable the specific events you need.</p>


<p dir="auto"><strong>Your backend listens for events</strong>, pulls relevant data from the webhook payload, checks user consent state, and sends the email through your own mailer with appropriate headers.</p>


Key webhook events and payloads:

<strong>Email Verification</strong>: verificationId to build the verification link
<strong>Forgot Password</strong>: changePasswordId to build the reset link
<strong>Setup Password</strong>: check user.password is null to confirm they need setup
<strong>Breached Password</strong> (user.password.breach😞 user.email to notify them to change their password
<strong>Suspicious Login</strong> (user.login.suspicious😞 event.info for device and location details (Enterprise feature)
<strong>Registration Verification</strong> (user.registration.verified😞 verificationId to build the verification link
<strong>MFA Method Added/Removed</strong>: method object with the method type and identifier

<p dir="auto"><strong>Important:</strong> If you use the webhook approach, make sure to disable all relevant email templates in FusionAuth. If you leave some templates enabled while your third-party mailer is active, users will receive duplicate emails — one from FusionAuth and one from your mailer.</p>
Related Documentation

<a href="https://fusionauth.io/docs/customize/email-and-messages/configure-email" rel="nofollow ugc">Configure SMTP - Custom Headers</a> - Information on configuring tenant-level SMTP settings including additional headers
<a href="https://fusionauth.io/blog/announcing-fusionauth-1-32" rel="nofollow ugc">Announcing FusionAuth 1.32 - Custom Email Headers</a> - Details on the custom email headers feature added in version 1.32
<a href="https://fusionauth.io/docs/extend/events-and-webhooks/" rel="nofollow ugc">Events &amp; Webhooks</a> - Complete documentation on FusionAuth's webhook system
<a href="https://fusionauth.io/docs/customize/email-and-messages/email-templates" rel="nofollow ugc">Email Templates</a> - Managing and disabling email templates
<a href="https://fusionauth.io/docs/customize/email-and-messages/configuring-application-specific-email-templates" rel="nofollow ugc">Application-Specific Email Templates</a> - Overriding email templates at the application level
<a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/login/user-login-suspicious" rel="nofollow ugc">User Login Suspicious Event</a> - Webhook payload for suspicious login events
<a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-breach" rel="nofollow ugc">User Password Breach Event</a> - Webhook payload for breached password events
<a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/registration/user-registration-verified" rel="nofollow ugc">User Registration Verified Event</a> - Webhook payload for registration verification events

]]></description><link>https://fusionauth.io/community/forum/topic/3214/how-to-add-custom-smtp-headers-per-user-for-tracking-consent</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3214/how-to-add-custom-smtp-headers-per-user-for-tracking-consent</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>