Matthew Meszaros
1f0c6ca6d6
feat: send each mailbox's reply-to as a Reply-To header on campaign, unibox, test and placement mail (never warmup), record it on every campaign send attempt (tasks.reply_to, migration 000236) and credit a reply landing in that shared reply inbox to the campaign and its sending mailbox across reply attribution, the sync priority lane and copied-contact replies, show the sending mailbox on thread messages, recent activity and the reply webhook, start unibox and inbox-agent replies from the mailbox that emailed the contact, flag an untracked reply-to in mailbox settings, let the sandbox simulator answer Reply-To, and document the shared reply inbox ( #756 )
2026-09-30 05:33:34 -07:00
Matthew Meszaros
a34e1634fc
feat: merge main into the placement comparison branch, keeping both the rendered-copy and the placement-batch sentences in the workspace export guide's placement row
2026-09-30 08:20:58 +02:00
Matthew Meszaros
5fdb2e40a5
feat: keep a refused lead copy from spending the lead's send attempts, drop campaign-wide CC and BCC addresses that bounced on the campaign, resolve copies only for email steps, fail a reply or link unsubscribe when the lead's copies cannot be read instead of guessing, credit a copy's message to a lead only when it replies in a thread, show each copy's status in the Leads CC badge, and close the CC picker on Escape from any focused child
2026-09-29 10:11:17 -07:00
Matthew Meszaros
0ed98a8c55
feat: copy up to two colleagues on every email a campaign sends one lead (campaign_lead_cc, migrations 000230-000231) with a drawer CC editor that suggests same-company contacts, hold a copied contact's own lead so nobody gets two threads, count a copy's reply as the lead's, opt out every copy on a link unsubscribe, drop a bounced or refused copy without bouncing the lead, skip suppressed campaign CC and BCC addresses, and document the endpoints, CLI, skills and OpenAPI
2026-09-29 09:53:27 -07:00
Matthew Meszaros
a772868577
feat: render each seed's copy of a placement tracking comparison once, seal it with the workspace key in placement_renders, and send it from both halves so the pixel and wrapped links are the only difference, with a refusal frozen for the pair, the copy pruned when the comparison ends, excluded from workspace exports, and documented in the placement, export and data-control pages
2026-09-29 09:34:32 -07:00
Matthew Meszaros
a268e3c54a
feat: limit the Warmup plan to the premium pool and uncapped mailboxes by gating sending, the inbox, AI, integrations, placement tests and paid storage on a plan that sends (HasProductPlan, with HasPremiumWarmup for pool placement), report 0 daily sends and refuse non-mailbox limit requests for workspaces that do not send, lock Warmup workspaces in the dashboard like free ones, show only the mailbox meter for them, and show the yearly price on yearly subscriptions
2026-09-28 09:16:42 -07:00
Matthew Meszaros
49e7fec849
Merge pull request #707 from warmbly/feature/campaign-analytics-date-range
...
feat: date range filtering for campaign analytics as a send cohort
2026-09-27 06:16:54 +00:00
Matthew Meszaros
0b809dee40
feat: scope campaign analytics to an optional from/to send cohort (summary, step performance, engagement and the daily chart read the same UTC days, total_contacts and emails_pending stay campaign-wide, date_range reports the resolved period), count the whole last day in campaign compare and daily stats, add a 7d/30d/90d/all-time/custom period picker to the campaign overview and its share image, take the period in get_campaign_stats, the warmbly and warmblyctl CLIs and the Make and Zapier modules, close a date picker's calendar alone on Escape, and document it in the analytics guide, API reference, MCP table and OpenAPI
2026-09-26 22:42:19 -07:00
Matthew Meszaros
2b1a35dfe1
feat: make warmup spam placement only slow a mailbox down (watch at 10%, half-volume throttle at 20%, never quarantine, block or appeal) and judge it only at Google, Microsoft and Yahoo over verified deliveries, keep small-host spam out of the health bands, warmup and cold ramps and the advisor while still showing it beside the headline rate on the drawer and Deliverability, draw small-host partners whose own filter junks warmup mail less often, send each quarantine or block webhook once plus health_changed, release placement-only quarantines in 000220, and update the warmup, deliverability, advisor and API docs
2026-09-26 22:26:58 -07:00
Matthew Meszaros
014ba06b3a
feat: weight warmup partners by the sender's verified spam rate per recipient mail host instead of per address domain, report deliverability warmup placement and the placement_in_spam webhook by mail host, mark IMAP warmup mail not-junk before it leaves Junk, send single-part text mail over SMTP with a fixed header order, and update the warmup, deliverability, analytics, webhook and OpenAPI docs
2026-09-26 06:30:22 -07:00
Matthew Meszaros
c6027fecde
Merge pull request #694 from warmbly/fix/premium-warmup-pool-partners
...
feat: borrow the best proven free warmup mailboxes whenever a premium mailbox has too few outside-workspace partners, reserve a quarter of every inbox's daily warmup capacity for premium senders, and show the pool and partner cap in the mailbox drawer
2026-09-26 05:07:38 +00:00
Matthew Meszaros
6e62c500c3
feat: borrow the best proven free warmup mailboxes whenever a premium mailbox has fewer outside-workspace partners than max(25, its warmup ceiling) so siblings no longer block borrowing, keep a quarter of every inbox's daily warmup capacity for premium senders, and show the pool and any partner cap on today's target in the mailbox drawer
2026-09-25 21:47:36 -07:00
Matthew Meszaros
caf1852217
feat: keep placement seeds out of warmup pools as recipients too, store a probe's Message-ID before the send, hold queued probes against the sender's day and size a test to what is left, claim due monitors so one replica runs each, write comparison halves in one transaction, scan each seed's mail once per tick, keep test history when a mailbox is deleted, default to 20 seeds a minute apart, and render cloud-panel tests without a real lead by default
2026-09-25 21:46:09 -07:00
Matthew Meszaros
d91b78458b
feat: skip placement probes from a suspended workspace the same way warmup sends are skipped
2026-09-25 20:53:52 -07:00
Matthew Meszaros
7f324a38ac
feat: open inbox placement tests to workspaces with probes rendered like the campaign send and paced as placement tasks, Message-ID matching instead of a subject token and warmup header, instance, workspace and Warmbly Cloud seed panels, a tracking comparison, scheduled campaign monitors with alerts and optional auto-pause, monthly allowances, realtime updates and org transfer registration
2026-09-25 20:48:15 -07:00
Matthew Meszaros
ccb4a3a0cd
feat: take back a campaign pass the task queue refused so the retry that follows a failed hand-off can seed one that runs
2026-09-24 20:12:29 -07:00
Matthew Meszaros
de7a7c9748
feat: take back a replayed campaign pass the task queue refused and keep its dead letter, seed the next pass on a fresh context when the one after a failed hand-off could not be written, resume a campaign whose mailboxes lack a worker at the earliest reopening, and log that wait under its own daily line
2026-09-24 20:09:55 -07:00
Matthew Meszaros
a54e9a3a2f
feat: keep a campaign's pass chain running through every failure (a pass whose hand-off to a worker fails or that errors is followed by another a minute later instead of waiting on the reconciler, retries move their slot, dead-lettered passes replay through the campaign lock), pass over mailboxes no heartbeating worker holds (worker_id now loaded with the sender pool, shown as Reconnecting in the send plan), count a hand-off failure against the lead only when it is the lead's, and try up to 200 due leads per pass with a daily activity line when all are waiting
2026-09-24 19:56:14 -07:00
Matthew Meszaros
79b583bcae
feat: classify a campaign's parked wakeup itself as a sending tick's paced successor (IsPacedSuccessor: the preceding tick sent and completed within a minute of the park) so a reconciler re-seed or deferral recheck is pulled forward when leads arrive, skip cancelled ticks, and qualify the campaigns guide's first-send timing by mailbox window, cap and gap
2026-09-24 01:56:23 -07:00
Matthew Meszaros
87a346f4ff
feat: wake a freshly seeded campaign chain (start, resume, schedule edit, reconciler re-seed) as soon as a lead is due instead of at the paced slot of the send after it, and let leads added to a waiting campaign pull its deferral recheck forward while leaving a sending tick's paced successor alone (scheduler.WakeSlot, CampaignRepository.LastTickSent)
2026-09-24 01:43:58 -07:00
Matthew Meszaros
ee70b7697a
Merge remote-tracking branch 'origin/main' into fix/unibox-forward-original-message
...
# Conflicts:
# docs/content/docs/api/reference/unibox.mdx
# docs/content/docs/guides/unibox.mdx
# docs/public/openapi.json
# web/src/components/app/unibox/ReplyComposer.tsx
# web/src/components/app/unibox/replyComposerDraft.test.tsx
2026-09-23 21:48:54 -07:00
Matthew Meszaros
bbd7942313
feat: unibox forward requires READ_UNIBOX alongside WRITE_UNIBOX, restores click tickets in a forwarded Warmbly send to their destinations, fills an empty-placeholder HTML note from its text, previews an empty-note forward in the Scheduled view, keeps a reply's leading blank lines, shares the stored-body read with GET /unibox/:id, and shows the Reply/Forward bar when a forward's message is no longer in the thread
2026-09-23 21:38:59 -07:00
Matthew Meszaros
a544847fcb
feat: resolve a Unibox reply's Gmail thread per sending mailbox (its own copy of the conversation, or the thread its earlier reply started, and none for other providers or on a failed lookup keeps the handle), honour an API key's mailbox allowlist on scheduled list and cancel, fall back from a saved mailbox that is gone and block Send until the sender can send, fetch From candidates only when the picker opens, and fix the Unibox threading and drafts docs
2026-09-23 21:29:24 -07:00
Matthew Meszaros
6c4931c28a
feat: unibox forward carries the original message, attached server-side from a new forward_message_id on POST /unibox/reply and stored on the queued task (migration 000208) so it goes out under the note and signature with its From, Date, Subject, To and Cc lines, sanitized HTML and text part; the composer allows an empty note and previews the forwarded message ( #668 )
2026-09-23 21:22:17 -07:00
Matthew Meszaros
ce5eb4fd25
feat: let a Unibox reply or forward choose its sending mailbox in From (the shared MailboxPicker without Auto, kept in the draft and the undo-send), send the provider thread handle only from a mailbox that holds the thread so a switched reply threads on In-Reply-To alone, and scope scheduled sends, their cancel, count and cap to the organization whose mailboxes send them ( #670 )
2026-09-23 21:18:20 -07:00
Matthew Meszaros
1c734411a3
feat: keep warmup out of Unibox notifications and the unread badge: tie reply notifications to their unibox message (notifications.unibox_email_id, migrations 000202-000204) so they are removed with it and read when it is read, link them to the conversation, count the badge as unread Inbox conversations without snoozed ones and refetch it instead of incrementing, hold a live arrival from the sender of an unconfirmed warmup send until its id is known, and never send warmup without a token ( #659 )
2026-09-23 07:30:09 -07:00
Matthew Meszaros
d6384d3c0e
feat: make cross-tier warmup an exchange so a proven free mailbox writes back to the paying mailboxes that wrote to it, favour the inbox owed the most on every draw, cap what any inbox receives per day inside WarmupPartnerCandidates so a thin tier is neither starved nor flooded, and surface received counts in the mailbox drawer, warmup analytics and the API ( #633 )
2026-09-20 09:42:53 -07:00
Matthew Meszaros
1497762d66
feat: add live regression tests proving replies to a campaign rotating across several mailboxes stamp each lead as replied and reach the campaign reply count, with and without thread headers, and document in the analytics guide that each lead's reply is expected in the mailbox that wrote to them
2026-09-19 04:05:34 -07:00
Matthew Meszaros
e668a2a36b
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
Matthew Meszaros
79bd4f62e3
feat: hold a warmup send whose send-time budget reports the mailbox not warming instead of letting it through, because a failed campaign read produces that sentinel and let a health-check mailbox send uncapped, and cover both held-status writes with a test that a hold whose write fails is retried rather than acknowledged
2026-09-18 22:47:09 -07:00
Matthew Meszaros
d46cfad597
feat: check the warmup daily target again at the moment a send executes rather than only when the next one is placed, so a spam placement, health band or partner loss that cuts the target while a send is pending holds it as skipped_daily_limit and parks the chain at the next opening with a reply-back's aim intact, fail closed when that count cannot be read, share one target resolver between the placer and the send-time gate, add the skipped_org_suspended task status the suspended-workspace hold has written since #233 without a migration so its write stops failing and leaving the task pending for the dispatcher to re-fire, and anchor the ramp live fixture in UTC off the day boundary so its assertions no longer depend on the host timezone
2026-09-18 22:39:52 -07:00
Matthew Meszaros
7e6cbd6b1f
feat: count the send in flight on the last-email-of-the-day feed line so a cap-one mailbox is shown at its cap with a budget gate rather than at zero, and put live campaign progress in emails (contacts times steps) with a total_emails field so a six-step campaign no longer reads 100% once every contact has had its first email
2026-09-18 13:54:12 +02:00
Matthew Meszaros
5b96ce903b
feat: count campaign progress from each table on its own so one sent email is no longer multiplied by leads times steps into 378 of 63 contacts at 100%, show the live Sending card only while a named contact's email is in flight and close it on EMAIL_SENT instead of leaving Sending Unknown contact up all day, and write the day's last send and every budget-spent line to the campaign feed with a per-mailbox breakdown of the cap, the clamp that set it, sends today, the gate and warmup health band so a campaign sending one email a morning says why
2026-09-18 13:12:07 +02:00
Matthew Meszaros
e37c5053c2
feat: make warmup refunds atomic, count confirmed partner diversity in local and cloud mailbox views, and document cloud-safe mailbox deletion
2026-09-17 21:15:28 -07:00
Matthew Meszaros
68babc30f3
feat: give the mailbox delete its own cloud revocation that calls the pool before dropping the local row and refuses an unreadable link, so a nil answer is proof the credential is gone rather than proof the local row went, and drive the greylisting evidence guard through the real handler with stub repositories so removing it fails CI where the live test skips
2026-09-17 20:52:54 -07:00
Matthew Meszaros
d2095a8a70
feat: stop a greylisted RCPT reply from being filed as bounce evidence now that the send carries the server's own words, revoke a cloud enrollment after the worker removal and put the mailbox back when the revocation is refused so a failed delete really changes nothing, drop the unenroll-under-Settings advice that makes the same failing call, and only log a within-workspace pairing when there is a sibling to draw
2026-09-17 20:19:46 -07:00
Matthew Meszaros
8ee1c50a1b
feat: make a failed SMTP send name the step and the cause behind it instead of one bare SERVER_UNREACHABLE sentinel, give a refused warmup send its day back so sent_today can no longer climb past the target while the cap frees the slot, revoke a mailbox's Warmbly Cloud enrollment when it is deleted so the pool stops holding its password, and prefer warmup partners outside the sender's own workspace while showing the partner diversity a mailbox is actually getting ( #574 , #575 )
2026-09-17 20:02:37 -07:00
SUMAN JANA
2134c7a143
feat(analytics): report on mail written by hand, with opt-in open and click tracking per mailbox
2026-09-17 10:26:25 +00:00
Matthew Meszaros
f72d1f8d5c
feat: prevent sender views from tracking opens and keep sent messages out of the default Inbox ( #542 )
2026-09-16 03:42:58 -07:00
Matthew Meszaros
dd98187231
fix: shorten recipient unsubscribe links to 22-character, 128-bit stored tickets ( #498 ) ( #525 )
...
* feat: shorten every recipient unsubscribe link from a 96-character signed token to a 22-character stored ticket carrying 128 bits from crypto/rand, minted once per recipient per campaign and reused by every step, so the address the text/plain half of a cold email prints in full fits on one line and cannot be guessed, keeping the signed form working for links already in inboxes and as the fallback when the store cannot be written, and answering a failed lookup with a retryable 'try again shortly' instead of telling the recipient their opt-out is invalid (issue #498 )
* fix: restore the disabled-signer guard in URLOn, which factoring the URL builder moved behind a token mint that dereferences the signing key, so a nil or origin-less signer returns the empty string every caller reads as 'no link can be minted' instead of panicking (PR #525 review)
2026-09-15 00:42:45 -07:00
Matthew Meszaros
8d790ede6c
feat: send from any address Google has verified a Gmail mailbox to send as and import the signature its owner already wrote in Gmail, reading both through gmail.settings.basic at connect and on demand via GET/POST /emails/:id/identity, validating the choice against the provider's own list in the service and again inside the UPDATE, clearing it when the provider stops verifying it, and never applying it to warmup ( #514 )
2026-09-14 10:13:36 -07:00
Matthew Meszaros
13e9ce8e10
feat: hold a lead whose mailbox answers out of office until they are back, resuming at the return date it names, plus a manual per-contact pause in one campaign that unsubscribing and the suppression list were the only stand-ins for
2026-09-14 09:26:06 -07:00
Matthew Meszaros
5ec367de8a
fix: put the mailbox signature and the opt-out footer inside the container an HTML email was laid out in instead of after it, by locating that container with a new offset-keeping outline scan in internal/pkg/mailhtml and splicing into it, and centring the line on the card's own width when a builder export has no single container to sit in, so neither renders hard left in the page background any more (issue #462 ) ( #505 )
2026-09-14 08:11:52 -07:00
Matthew Meszaros
6fafb8bd6a
fix: honour a warmup routing rule of weight 0 as an exclusion, dropping the pair before the draw and refusing it on the reply-back, so a pool of one can no longer smuggle an excluded partner past a weighting ( #501 ) ( #504 )
2026-09-14 03:36:04 -07:00
Matthew Meszaros
2bbd72e758
fix: make cross-tier warmup borrowing real and one-directional: a thin premium tier borrows proven free mailboxes through one repository rule, gates each drawn partner in its own pool, and only reply-backs cross tiers ( #496 )
...
* fix: gate a warmup partner borrowed from the other tier against the pool it is in rather than the sender's, since the thin-tier fallback had rejected every borrowed candidate and a thin tier failed instead of borrowing
* fix: make cross-tier warmup borrowing one-directional and gate borrowed partners in their own pool, so a thin premium tier can actually borrow proven free mailboxes (#495 )
* fix: pin the borrow floor at the exact boundary so a premium tier at the floor including its sender still borrows (#495 )
* fix: put the warmup borrowing rule in one repository method (direction, floor, proven age, workspace standing) that the selector and scheduler both read, pin every drawn partner's gate to its own pool, fall through buckets when a stale row fails the gate, and allow only reply-backs across tiers (#495 )
* fix: end the warmup partner draw by candidate exhaustion instead of a fixed attempt cap, and fail closed when a free mailbox's workspace standing cannot be read before it answers into a paid inbox (#495 )
* fix: end the warmup partner draw by candidate exhaustion instead of a fixed attempt cap, and fail closed when a free mailbox's workspace standing cannot be read before it answers into a paid inbox (#495 )
2026-09-14 02:51:02 -07:00
Matthew Meszaros
40506c4f05
fix: seed the two warmup pools on every instance under fixed ids and make one pool per type structural, since the baseline squash dropped the insert and a fresh self-hosted instance never warmed; move memberships onto the canonical pools, scope the standing mirror trigger to the columns it mirrors so a pool move keeps a retention window, commit the runtime and every seeder to the ids through MoveToPool, assert the pools at boot and in a warmup_pools_missing health check, and drop the guide's claim of cross-tier borrowing the health gate rejects ( #493 )
2026-09-13 21:37:17 -07:00
Matthew Meszaros
6b6efca865
fix: campaign follow-ups opened a new conversation instead of replying in the contact's thread, so carry In-Reply-To/References and the Gmail threadId from the previous send, give every step a reply-in-thread switch, and let a threading step inherit the conversation's subject (issue #472 ) ( #489 )
2026-09-13 20:51:41 -07:00
Matthew Meszaros
06b8db5529
feat: report the one silent state a campaign had no words for, a mailbox pool that is part out of budget and part outside its own sending hours, which fell between the 'every mailbox is capped, sending resumes tomorrow' line and the deliberately unlogged closed-hours band and so left an active campaign sending nothing with an empty activity feed; give it its own line under the mailboxes_unavailable event the pool's other refusals already use, naming how many mailboxes are in each state and carrying the moment the pool comes back in metadata rather than promising a day, while leaving daily_cap_reached to mean exactly what it meant before, every usable mailbox spent and nothing coming back until tomorrow
2026-09-12 03:47:36 -07:00
Matthew Meszaros
c4aece241b
feat: scope the tag, category and folder registries and unibox conversation labels to the organization instead of the creating user, so a teammate sees and can edit the labels the owner made, splitting a label two workspaces shared into one copy each and guarding every label write against ids from another workspace ( #457 )
2026-09-12 03:37:31 -07:00
Matthew Meszaros
47defafa09
feat: fix the six self-host defects reported in issue #439 ( #456 )
...
* feat: fix the six defects reported in issue #439 by mapping the IMAP UNAVAILABLE, INUSE and NONEXISTENT response codes to retry-level errors instead of a critical reconnect prompt, synthesising a stable no-msgid key so one message with no Message-ID header can no longer 400 the internal map endpoint and wedge every later sync pass with its cursors held, adding mailhtml.FromText and HasContent so an API or agent-created step with a plain body stops shipping the composer's empty div placeholder as its text/html part (derived on create and plain-only update, exposed as body_html on update_campaign_step, dropped at send and preview time, and refused at campaign start with empty_step_body), honouring sender_strategy='explicit' in ResolveCampaignSenderPool and ValidateCampaignReady so an emptied explicit pool parks the campaign instead of widening it to every mailbox in the workspace, making the paused_no_accounts auto-pause loud with an error log line, an error-level activity-feed entry and an org-scoped CAMPAIGN_PAUSED realtime pulse, gating the admin sign-in's Turnstile widget on GET /v1/auth/config so a self-host with CAPTCHA_PROVIDER=none is not locked out, and parsing NATS_URL down to its host:port so a credentialed bus URL no longer reports NATS down
* feat: act on the self-review of the issue #439 fixes by dropping the campaign wizard's own escapeHtml body_html builder, which entity-escaped the quotes in a conditional and made the template fail to parse at send time, and letting the backend's FromText render that part instead so wizard-written steps also get their bare URLs linked for click tracking, correcting the docs and openapi description that claimed an explicit sender pool never falls back when it still unions its tags as migration 000013 designed, extracting the duplicated blank-HTML-part guard into dropBlankHTMLPart shared by the send path and the preview, and recording why the no-msgid key keeps the folder name despite a RENAME changing it
* feat: address the CodeRabbit review on the issue #439 fixes by holding the admin sign-in's Turnstile widget unmounted until /v1/auth/config resolves so an instance with no route to Cloudflare cannot raise a widget error on a screen nobody submitted, failing StartCampaign closed when the sequence read errors rather than skipping both the malformed-template and empty-body refusals, giving TCPCheck the default port its protocol assumes so a portless NATS_URL is no longer reported down, leaving a URL that carries a merge field unanchored because the send path renders bodies with text/template and a quoted contact value would break out of the href, and correcting the sequences guide and the Campaign and CampaignUpdate openapi descriptions that named the wrong tag field
2026-09-12 03:13:38 -07:00