Appearance
Email deliverability
PackEdge sends transactional email through Amazon SES. When AWS reports that a message bounced or was marked as spam, the recipient's profile is flagged and future sends to that address are silently blocked. This keeps a single bad address from torching the sending domain's reputation for everyone else.
States
profiles.email_status carries one of three values:
| Value | Meaning |
|---|---|
ok | Default. Sends proceed normally. |
bounced | A permanent bounce was reported (mailbox doesn't exist, domain refuses, address blocklisted). Hard-blocked. |
complained | The recipient hit "report spam" in their mail client. Hard-blocked. |
Soft bounces (mailbox full, greylisting, transient DNS) are logged but do not flip the flag — that would punish the recipient for their provider's transient state.
What you see in the console
The system admin user list shows a small badge next to any non-ok address. Your own profile shows a banner with the diagnostic AWS provided, so you can update + reverify your email before the next license alert or receipt is silently dropped.
Email log
Email log in the console lists every email PackEdge sent to your customers (license keys, receipts, expiry reminders) with its outcome: sent, failed, blocked, or not sent because a preference was off. Filter by status or email type, or search by recipient or subject.
Click a row to open its details in a drawer on the right:
- Delivery: status and any error, recipient, date, whether it was automatic or a manual resend (and who resent it), and links to the related license and order.
- Attachments: the file exactly as it was sent, such as the PDF invoice on a receipt. Open it in a new tab or download it.
- Preview: the email as the customer received it. Links in this copy are disabled, and any link printed as text shows as
[link removed]. Sign-in and download links grant access to the customer's account, so they can't be reused from the log.
Emails logged before PackEdge kept a copy of each email are rebuilt from the license or order they belong to, and marked as rebuilt. Anything that changed since, such as a renewed expiry date, shows its current value rather than what the customer received. Emails that weren't sent because a preference was off have no preview.
How it works
- Each
SendEmailcall captures the SESMessageIdand stashes amessageId → recipientmapping in Redis with a 30-day TTL. - SES delivers bounce + complaint notifications to an SNS topic which posts to
POST /webhooks/ses. - The handler verifies the SNS signature against the AWS-published certificate (RSA-SHA1 against
*.amazonaws.comcert hosts), then parses the embedded SES envelope. - The original recipient is looked up via the Redis map; the
profiles.email_statusrow is updated. - The next
email.Client.Sendcall to that address pre-checks the status and returns early without invoking SES.
Operator setup
The AWS side of the wiring is out of band:
- Create an SNS topic, configure SES to publish bounce + complaint notifications to it.
- Add an HTTPS subscriber for
https://api.packedge.dev/webhooks/ses. PackEdge handles theSubscriptionConfirmationautomatically — no manual confirm step needed. - Keep the cert URL set to the SNS default (a
*.amazonaws.comhost). PackEdge rejects any cert URL outside that hostname suffix.
Recovering a blocked address
The block is per-address, not per-account. To restore delivery, change the profile's email to a working address through Settings → Profile. The new address starts in ok state and receives mail immediately. There's no need to delete + recreate the account.
