Prompt
How do I test email webhooks locally?
Latest observation
You can test email webhooks locally in a few practical ways, depending on whether you mean incoming email webhooks (e.g. Mailgun/Postmark/SendGrid/Mailchimp “email received” events) or outgoing event webhooks (delivery/open/click events). For most local development, the easiest approach is:
1) Run a local HTTP endpoint
Create a route in your app that accepts POST requests.
Example:
POST /webhooks/email- log the raw body
- return
200 OKquickly
Make sure it can handle the content type your provider sends:
application/x-www-form-urlencodedapplication/json- raw MIME payloads for inbound email
2) Expose localhost to the internet
Email providers need a public URL to reach your webhook. Use one of:
- ngrok
- Cloudflare Tunnel
- localtunnel
- Tailscale Funnel (if available in your setup)
Example with ngrok:
ngrok http 3000
Then set your provider’s webhook URL to:
https://<random>.ngrok.io/webhooks/email
3) Send a real test event from the provider
Most providers have a “Send test webhook” button in their dashboard.
If not, trigger a real event:
- send an email to your inbound address
- request delivery/open/click events by sending yourself a message and opening it
- configure a sandbox/test mailbox if the provider supports it
4) Verify the payload
Check:
- headers/signature
- body format
- retries
- duplicate deliveries
- response time
Log the raw request body before parsing so you can debug signature verification and payload format issues.
5) Use a webhook inspection tool
If you just want to simulate webhooks locally without a real email provider:
- RequestBin / webhook.site
- Pipedream
- Postman mock servers
- a local test script that
POSTs sample payloads to your endpoint
6) Test signature validation
If the provider signs webhooks:
- copy a real test payload
- compute signature using the provider secret
- verify your code rejects invalid signatures
Example workflow
- Start your app locally on port 3000.
- Run
ngrok http 3000. - Paste the ngrok URL into your provider’s webhook settings.
- Send a test email or trigger the event.
- Inspect logs and fix parsing/authentication issues.
Common pitfalls
- forgetting to handle URL-encoded bodies
- not reading the raw body before JSON parsing
- responding too slowly (providers may retry)
- assuming local
localhostis reachable from the internet - ignoring duplicate webhook deliveries
If you tell me which email provider you’re using (SendGrid, Mailgun, Postmark, AWS SES, etc.) and your stack (Node, Python, Rails, etc.), I can give you exact local testing steps and sample code.