## Build the webhook ingester
1. Verify the webhook signature on every request before doing anything else, using the signing secret from the dashboard. Reject unsigned or mismatched requests with a 4xx; never process an unverified event. Docs: https://resend.com/docs/webhooks/verify-webhooks-requests
2. Respond 200 fast and process asynchronously. Webhook deliveries retry on slow responses, and a slow handler turns one event into five duplicate deliveries.
3. Deduplicate on the event id. Store processed event ids with a TTL and skip any event you have already seen; retries and replays will redeliver, and your handlers must be idempotent.
4. Persist the raw event payload before running business logic. If your handler crashes mid-processing, the stored event lets you recover without asking Resend to replay. Docs: https://resend.com/docs/webhooks/how-to-store-webhooks-data
5. Subscribe to the full lifecycle set you need: sent, delivered, bounced, complained, opened, clicked, plus suppressions.added and domain events if you onboard tenants. You cannot analyze what you never subscribed to.
6. Route events with tags. The tags array on email events carries your tenant or campaign identifiers; use it to fan events out to the right tenant handler in a shared account.
7. For missed events, use the replay endpoint on the event rather than asking for a resend of the email. Replays redeliver the event payload; they never resend the email itself.
8. Alert on delivery gaps: if your ingester sees sends with no matching delivered or bounced event within your SLO window, page someone. Silent event loss looks exactly like perfect delivery.