All skills
resend avatar

/email-best-practices

@376d1c3 official
by resendresend/resend-skills193 stars
28

Use when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM, GDPR, CASL), handling webhooks, retry logic, making emails accessible (alt text, headings, contrast, screen readers), or deciding transactional vs marketing.

Use this Skill: https://skilld.dev/gh/resend/resend-skills/email-best-practices

This session only. Nothing lands on disk.

referenceswebhooks-events.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Webhooks and Events

Receiving and processing email delivery events in real-time.

Event Types

Event When Fired Use For
email.sent Email accepted by Resend Confirming send initiated
email.delivered Email delivered to recipient server Confirming delivery
email.bounced Email bounced (hard or soft) List hygiene, alerting
email.complained Recipient marked as spam Immediate unsubscribe
email.opened Recipient opened email Engagement tracking
email.clicked Recipient clicked link Engagement tracking

Webhook Setup

1. Create Endpoint

Your endpoint must:

  • Accept POST requests
  • Return 2xx status quickly (within 5 seconds)
  • Handle duplicate events (idempotent processing)
app.post('/webhooks/resend', async (req, res) => {
  // Return 200 immediately to acknowledge receipt
  res.status(200).send('OK');

  // Process asynchronously
  processWebhookAsync(req.body).catch(console.error);
});

2. Verify Signatures

Always verify webhook signatures to prevent spoofing.

import { Webhook } from 'svix';

const webhook = new Webhook(process.env.RESEND_WEBHOOK_SECRET);

app.post('/webhooks/resend', (req, res) => {
  try {
    const payload = webhook.verify(
      JSON.stringify(req.body),
      {
        'svix-id': req.headers['svix-id'],
        'svix-timestamp': req.headers['svix-timestamp'],
        'svix-signature': req.headers['svix-signature'],
      }
    );
    // Process verified payload
  } catch (err) {
    return res.status(400).send('Invalid signature');
  }
});

3. Register Webhook URL

Configure your webhook endpoint in the Resend dashboard or via API.

Processing Events

Bounce Handling

async function handleBounce(event) {
  const { email_id, email, bounce_type } = event.data;

  if (bounce_type === 'hard') {
    // Permanent failure - remove from all lists
    await suppressEmail(email, 'hard_bounce');
    await removeFromAllLists(email);
  } else {
    // Soft bounce - track and remove after threshold
    await incrementSoftBounce(email);
    const count = await getSoftBounceCount(email);
    if (count >= 3) {
      await suppressEmail(email, 'soft_bounce_limit');
    }
  }
}

Complaint Handling

async function handleComplaint(event) {
  const { email } = event.data;

  // Immediate suppression - no exceptions
  await suppressEmail(email, 'complaint');
  await removeFromAllLists(email);
  await logComplaint(event); // For analysis
}

Delivery Confirmation

async function handleDelivered(event) {
  const { email_id } = event.data;
  await updateEmailStatus(email_id, 'delivered');
}

Idempotent Processing

Webhooks may be sent multiple times. Use event IDs to prevent duplicate processing.

async function processWebhook(event) {
  const eventId = event.id;

  // Check if already processed
  if (await isEventProcessed(eventId)) {
    return; // Skip duplicate
  }

  // Process event
  await handleEvent(event);

  // Mark as processed
  await markEventProcessed(eventId);
}

Error Handling

Retry Behavior

If your endpoint returns non-2xx, webhooks will retry with exponential backoff:

  • Retry 1: ~30 seconds
  • Retry 2: ~1 minute
  • Retry 3: ~5 minutes
  • (continues for ~24 hours)

Best Practices

  • Return 200 quickly - Process asynchronously to avoid timeouts
  • Be idempotent - Handle duplicate deliveries gracefully
  • Log everything - Store raw events for debugging
  • Alert on failures - Monitor webhook processing errors
  • Queue for processing - Use a job queue for complex handling

Testing Webhooks

Local development: Use ngrok or similar to expose localhost.

ngrok http 3000
# Use the ngrok URL as your webhook endpoint

Verify handling: Send test events through Resend dashboard or manually trigger each event type.

Ingest webhooks for data storage

Related

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a comprehensive knowledge base for email best practices, including deliverability, accessibility, compliance, and reliability. It contains educational content and code examples for developers. No malicious patterns or security risks were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 376d1c3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 months ago
Other metadata
metadata
{
  "author": "Resend",
  "version": "1.0.2",
  "homepage": "https://resend.com/agent-skills",
  "source": "https://github.com/resend/email-best-practices",
  "openclaw": {
    "links": {
      "repository": "https://github.com/resend/email-best-practices",
      "documentation": "https://resend.com/docs/email-best-practices-skill"
    }
  }
}
  • email
  • transactional
  • marketing
  • deliverability
  • spf-dkim-dmarc
  • compliance
  • webhooks
  • accessibility
  • list-management
  • resend

README badge

README badge for resend/resend-skills/email-best-practices

Provides decision trees and reference guides for deliverability (SPF/DKIM/DMARC), compliance (CAN-SPAM/GDPR/CASL), transactional vs marketing email classification, webhook handling, list management, and accessibility (alt text, headings, contrast). Targets teams building email features with Resend or similar transactional email APIs.

Generated from the current SKILL.md.

Does this skill cover setting up SPF, DKIM, and DMARC?
Yes. The Deliverability section covers authentication setup and is the first step recommended for fixing spam issues, as unauthenticated emails are commonly rejected by Gmail and Yahoo.
What compliance standards does this skill address?
It covers CAN-SPAM, GDPR, and CASL requirements, with a dedicated Compliance section for legal obligations around email capture and marketing sends.
Does this skill include guidance on making emails accessible?
Yes. The Accessibility section covers screen reader support, alt text, headings, contrast requirements, and proper HTML structure for inclusive email design.
How does this skill handle bounces and list hygiene?
The List Management section covers bounce handling, suppression list updates, and list hygiene jobs. Webhooks & Events section covers processing delivery events to track bounces and complaints.
Does this skill cover retry logic and idempotent sending?
Yes. The Sending Reliability section covers retry strategy, idempotency, and error handling for production-ready email sending.

Generated from the current SKILL.md. These answers refresh after source changes.