Understand Letter Manager read-receipt tokens
Know how the hidden tracking pixel is created and linked to the letter.
Exact navigationOutgoing Letter Manager email → hidden 1×1 image
Before you begin
- Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
- Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.
What this guide covers
Know how the hidden tracking pixel is created and linked to the letter. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.
Exact step-by-step process
- Send a controlled letter.
- Open Internal Full View and confirm an email-open token exists only through authorised diagnostics.
- Open the email in a client that loads remote images.
- Confirm the open count and timestamps update.
Fields, choices and supported possibilities
Action scopeKnow how the hidden tracking pixel is created and linked to the letter.
Module version1.0.0
Exact routeOutgoing Letter Manager email → hidden 1×1 image
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.
Code-backed validations and workflow rules
- A 24-byte random token is hex-encoded when random_bytes succeeds, with a SHA-1 fallback.
- The pixel URL is letter_manager/email_open/{token}.
- The endpoint strips non-alphanumeric characters and requires a token length of at least 20.
Expected result and verification
- The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
- The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
- Any warning, missing file or failed send is investigated rather than bypassed.
Security, privacy and operational checks
- Apply least privilege and verify recipient identity before sending or exposing public links.
- Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
- Test configuration and deployment changes with controlled records before production-wide use.
- Interpret email opens and e-signatures according to their documented technical limitations.
