SendGrid Email Logs Integration
Overview
SendGrid provides transactional email delivery with comprehensive activity tracking and event webhooks. KYRA MDR collects SendGrid email events for monitoring email delivery, bounce patterns, and potential abuse.
Prerequisites
- A KYRA MDR Collector installed and running
- SendGrid account with API access
- API key with Mail Send and Email Activity read permissions
- Event Webhook URL accessible from SendGrid
Configuration
Configure SendGrid Event Webhook:
- Log in to the SendGrid Dashboard
- Navigate to Settings > Mail Settings > Event Webhook
- Enable the Event Webhook
- Configure:
| Setting | Value |
|---|---|
| HTTP Post URL | https://<collector-url>/webhook/sendgrid |
| Actions | Select all event types |
| Security | Enable Signed Event Webhook |
- Click Save
Alternatively, use the Email Activity API:
sources: - type: sendgrid api_key: <api-key> poll_interval: 300sCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Delivered | Successful email deliveries | Email delivery monitoring |
| Bounced | Failed email deliveries | Infrastructure health |
| Opened | Email open tracking events | Phishing simulation tracking |
| Clicked | Link click tracking events | User behavior monitoring |
| Spam Reports | Spam complaint events | Reputation monitoring |
| Dropped | Emails dropped before delivery | Policy enforcement |
Troubleshooting
Webhook not receiving: Verify the collector URL is publicly accessible and SendGrid can reach it.
Missing events: Ensure all event types are selected in the webhook configuration.
Authentication: Enable Signed Event Webhook for request verification.
Contact kyra@seekerslab.com for support.