The token
Every tracking link carries a signed token holding only id references — which workflow, node, contact and send it belongs to — plus an expiry. No customer data travels in the URL.Open tracking
GET /t/:token/pixel.gif returns a transparent 1×1 image. Fetching it records an open against that message, sets opened on the node’s output so an arrow keyed opened can fire, and adds to the campaign’s open count.
Not every fetch counts. A request is discarded when it arrives within five seconds of the send, when the user agent belongs to a known scanner, when the user agent is missing, or when it looks like a browser pretending to be one. That filters out most of the corporate mail scanners and provider prefetchers that would otherwise report an open before a human saw the message.
Click tracking
GET /t/:token/click records the click and the URL, sets clicked and clickedUrl on the node’s output, and redirects to the real destination. The original URL is carried base64url-encoded so its own query string survives.
Unsubscribe
GET /t/:token/unsubscribe identifies the contact, suppresses them with reason unsubscribe, logs the event, and shows a confirmation page.
Amazon SES notifications
POST /webhooks/ses receives delivery, bounce and complaint notifications from SES:
- A bounce marks the message bounced, fires the matching arrow, and can suppress the contact.
- A complaint suppresses the contact with reason
complaint. - A delivery marks the message delivered, which is what the Delivered stage in analytics counts.
Connecting SES
Create a configuration set
In the SES console, then attach it to the domain your SMTP credential sends from.
Point it at an SNS topic
Add the topic as the configuration set’s event destination, subscribing to Bounce, Complaint and Delivery.