# Segment mail does not use site\_url for link replacing and tracking

**URL:** <https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608>\
**Category:** Product Support\
**Created:** [May 26, 2021, 5:57am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608 "2021-05-26T05:57:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tpapaj](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tpapaj/32/3198_2.png) [@tpapaj](https://forum.mautic.org/u/tpapaj)\
**Post date:** [May 26, 2021, 5:57am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/1 "2021-05-26T05:57:38Z")

</div>

**Your software**  
My Mautic version is: 3.2.4  
My PHP version is: docker base image php:7.3-apache  
My Database type and version is: MariaDB

**Your problem**  
Hello, because I did not get any reply on github I would like to ask about possible solution here. Here is github issue link:

> <https://github.com/mautic/mautic/issues/10042>
>
> \[//\]: # ( Invisible comment: 
> IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII…I
> Before you create the issue:
> IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
> Search for similar report among other reported issues.
> Learn how to troubleshoot at https://www.mautic.org/docs/en/tips/troubleshooting.html
> Use drag&drop to attach images or other files )
> 
> \## Bug Description
> Mautic does not use site\_url when using Segment mailing in some cases.
> 
> \#### Explanation
> I have a Mautic running on GKE cluster. The access to the Web UI is via K8s Ingress.
> Now, I wanted to make a public Ingress(for tracking and for links without access to login) and internal Ingress(for administration). I set site\_url to address of public Ingress (X). Let say that X address is public Ingress and Y address is internal.
> 
> From infrastructure point, I have Mautic instance as deployment with X ingress and separate deployment, which is a simple NGINX proxy for internal use that redirects to Mautic instance(using internal K8s urls) with ingress Y.(in final form Y would be public Ingress instead but I left it like that for now)
> 
> So, site\_url is set to X and campaigns are using urls X in emails. However in case of segment emails, if I am using address X to log in to Mautic and I am creating segment email, links in email are pointing to address X and when I am using address Y to log in to Mautic, I create segment mail, send them and I see that links inside point to website Y. In case of campaigns address X is always used.
> 
> What is interesting, if I create a simple nginx for address X or Y on my local PC, I access it with "localhost" on my machine, the segment mails are using address X or Y in links depending on which instance I used, so "localhost" url is not used, so the url used in Mautic must be an url seen as request source for segment mail send trigger.
> 
> \#### Expected result
> When using Segment Email option I expect Mautic to use site\_url when creating email links for tracking and redirecting instead of url of request source.
> 
> | Q | A
> | --- | ---
> | Mautic version | 3.2.4
> | PHP version | Docker base image php:7.3-apache
> | Browser | Firefox
> 
> \### Steps to reproduce
> 1. Deploy Mautic as Kubernetes service
> 2. Deploy two Ingresses for Mautic
> 3. Log in to Mautic using both Ingresses and use them to send segment mails, check links in both mails
> 
> 
>  
> \### Log errors
> 
> Mautic does not generate any error logs for this issue
> 
> Here's is example of webserver log of request that I made in my localhost proxy. Site\_url is X, localhost proxy redirects to Y ingress, addresses Y are used in email links.
> \`\`\`
> "10.35.x.x - - \[17/May/2021:07:28:38 +0000\] "POST /s/emails/send/29?mauticUserLastActive=30&mauticLastNotificationId=13 HTTP/1.1" 200 5512 "http://localhost:8091/s/emails/send/29" "Mozilla/5.0 (X11; Ubuntu; Linux x86\_64; rv:88.0) Gecko/20100101 Firefox/88.0"
> "10.35.x.x - - \[17/May/2021:07:28:39 +0000\] "POST /s/ajax?action=email:sendBatch&mauticUserLastActive=30&mauticLastNotificationId=13 HTTP/1.1" 200 844 "http://localhost:8091/s/emails/send/29" "Mozilla/5.0 (X11; Ubuntu; Linux x86\_64; rv:88.0) Gecko/20100101 Firefox/88.0"
> "10.35.x.x - - \[17/May/2021:07:28:40 +0000\] "POST /s/emails/send/29?mauticUserLastActive=32&mauticLastNotificationId=13 HTTP/1.1" 200 5513 "http://localhost:8091/s/emails/send/29" "Mozilla/5.0 (X11; Ubuntu; Linux x86\_64; rv:88.0) Gecko/20100101 Firefox/88.0"
> \`\`\`
> 
> \[//\]: # ( Invisible comment:
> Please check for related errors in the latest log file in \[mautic root\]/app/log/ and/or the web server's logs and post them here. Be sure to remove sensitive information if applicable. )

I described everything in the issue above. This problem makes Mautic Segment Mail completely unusable and dangerous from a business point of view(sending broken links) when logging to Mautic from internal network when logging from public side is disabled for security reasons.

**These errors are showing in the log:**  
None

**Steps I have tried to fix the problem:**  
I tried to run the localhost proxy to check if segment mail will contain localhost in links but they didn’t. I wonder if there is an option to set some headers just before request gets to Mautic to go around this issue.

I would be glad even for pointing where is the code that incorrectly replaces these links so I can think of workaround.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [May 26, 2021, 1:09pm UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/2 "2021-05-26T13:09:15Z")

</div>

Hello!  
SO if I understand right:  
Your mautic is installed on localhost:80. This is your Mautic URL.  
When you ENABLE TRACKING (which is optional) your links in emails will be overwritten by Mautic. By redirecting the links, clicks can be registered. If you are sending from localhost, then you cannot receive incoming information (localhost is not a working domain outside of your network).  
Solution:

1. install Mautic on a qualified domain name
2. remove tracking  
BTW - how would your unsubscribe work?  
Joey

---

<div class="post-metadata">

**Author:** ![dimitri](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/dimitri/32/4437_2.png) [@dimitri](https://forum.mautic.org/u/dimitri)\
**Post date:** [May 26, 2021, 4:58pm UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/3 "2021-05-26T16:58:23Z")

</div>

I think I understand why you didn’t get an answer on github. Even after reading it several times it’s still difficult to understand what you are trying to achieve.

Is security the reason why you are trying to make it so complicated? Sorry for the question, but I am also trying to learn.

Mautic is made to run on an accessible address. All the functionality is connected with that. I think the developers didn’t predict that anyone could make a setup like yours.

---

<div class="post-metadata">

**Author:** ![tpapaj](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tpapaj/32/3198_2.png) [@tpapaj](https://forum.mautic.org/u/tpapaj)\
**Post date:** [May 27, 2021, 6:05am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/4 "2021-05-27T06:05:17Z")

</div>

Mautic is run on docker and localhost:80 is not my Mautic URL.

Let say that my X address is [https://internal.mautic.com](https://internal.mautic.com) and my Y address is [https://public.mautic.com](https://public.mautic.com). I will also make things simpler.

So, Mautic is being run on Kubernetes. There are two Kubernetes ingresses, one which expose mautic on [https://internal.mautic.com](https://internal.mautic.com) and other that exposes mautic on [https://public.mautic.com](https://public.mautic.com).

[https://public.mautic.com](https://public.mautic.com) is made in a way that it only allows tracking links to be accepted. If you go to [https://public.mautic.com/s/login](https://public.mautic.com/s/login) you will be denied.

Now, site\_url is set to [https://public.mautic.com](https://public.mautic.com). I am logging to Mautic via [https://internal.mautic.com](https://internal.mautic.com) which is address accessible in my internal network. I create campaign and “Send Mail” in it. Mautic replaces links. I check the result email on my inbox and I see that all tracking links, tracking pixel etc. begin with “[https://public.mautic.com/](https://public.mautic.com/)…”. Everything works correctly and because [https://public.mautic.com](https://public.mautic.com) is a public domain, everyone else can be tracked.

Now I am logging to Mautic via [https://internal.mautic.com](https://internal.mautic.com) again and create Segment Mail instead of campaign with “Send Mail” in it. I click “Send” on Segment Mail to begin sending and then I check my inbox, I see that all tracking links, tracking pixel etc. begin with “[https://internal.mautic.com/](https://internal.mautic.com/)…” and this is incorrect because my site\_url is still [https://public.mautic.com](https://public.mautic.com) so all links should begin with “[https://public.mautic.com/](https://public.mautic.com/)…” but they aren’t. If I logging in to Mautic via [https://public.mautic.com](https://public.mautic.com)(which won’t be possible after blocking admin URLs publicly) and I create Segment Mail and Send it, I will see that all tracking links, tracking pixel etc. begin with “[https://public.mautic.com/](https://public.mautic.com/)…”.

My point is that Segment Mail shouldn’t use unknown browser data like it is now when replacing links but it should use site\_url, always.

---

<div class="post-metadata">

**Author:** ![tpapaj](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tpapaj/32/3198_2.png) [@tpapaj](https://forum.mautic.org/u/tpapaj)\
**Post date:** [May 27, 2021, 6:20am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/5 "2021-05-27T06:20:50Z")

</div>

I understand. I hope I explained it more clearly above in my reply to Joeyk. I am sorry if the issue is not clear, I hope it’s now better.

Mautic is a PHP application that can contain sensitive data. I want to separate network traffic between publicly available and internal network and allow everything in internal network but only allow tracking URLs on the public internet so the world can’t see any API urls or login pages of Mautic to avoid any kind of bruteforce attack on my login page from the internet.

Also, Mautic is not GDPR compilant with cookies(lack of tracking cookie consent management) and also because I do not use Mautic tracking outside of emails and specific landing pages, I don’t really need them so I disable Set-Cookie headers on public instance so I don’t need to bother with getting cookie consent for cookies I don’t need in the first place. Email Clicks work correctly as well as Open Pages(they still need tracking pixel however for that) and that’s all I need. Lack of Set-Cookie means that also /s/login does not work properly but I do not want anyone to log to Mautic via publicly available address, so for me it is acceptable.  
At the same time, there’s internal address with everything allowed and only available inside my network where administrators can log in.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [May 27, 2021, 6:53am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/6 "2021-05-27T06:53:25Z")

</div>

Hey,  
Yeah, Consent management comes up from time to time… I think is not the scope of Mautic, there are 10 free solutions for that on Github.

The funny thing is, that Mautic supposed to use site\_url saved in local.php when overwriting tracking links. This is how it works on all my instances. It has nothing to do with your browser URL.  
I’m really confused why this is not the case for you.

Joey

---

<div class="post-metadata">

**Author:** ![tpapaj](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tpapaj/32/3198_2.png) [@tpapaj](https://forum.mautic.org/u/tpapaj)\
**Post date:** [May 27, 2021, 7:08am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/7 "2021-05-27T07:08:29Z")

</div>

Could you tell me which file on github handles link replacing? I would like to look at it closer and find where the issue is.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [May 28, 2021, 6:55am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/8 "2021-05-28T06:55:50Z")

</div>

Sorry, no idea. Maybe you want to create a github issue, that coders can give you a hand instead of me (simple user) giving ideas?

---

<div class="post-metadata">

**Author:** ![tpapaj](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tpapaj/32/3198_2.png) [@tpapaj](https://forum.mautic.org/u/tpapaj)\
**Post date:** [June 7, 2021, 7:32am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/9 "2021-06-07T07:32:35Z")

</div>

I think a found a partial reason and an easier way to make the issue visible.

Wrong address is returned by router-\>generate method in [mautic/AbstractCommonModel.php at a16eb83f6cff0d3c5ea39bc172a5eb262ce2616b · mautic/mautic · GitHub](https://github.com/mautic/mautic/blob/a16eb83f6cff0d3c5ea39bc172a5eb262ce2616b/app/bundles/CoreBundle/Model/AbstractCommonModel.php#L245)

Unfortunately I can’t find any code where that router is created and I do not know what parameter it is using.

Easy way to reproduce:

- Install Mautic on localhost. Note the port. I am using port 8100 in this example.
- Install nginx and put following configuration:

```auto
server {
        listen 8877;

        location / {
                proxy_pass http://localhost:8100; #Assuming that your Mautic instance is on port 8100
     proxy_redirect off;

                proxy_set_header X-Real-IP $remote_addr;
                proxy_set_header Host $host;
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

                proxy_http_version 1.1;
                proxy_set_header Upgrade $http_upgrade;
                proxy_set_header Connection "Upgrade";
       }
}

```

- Set `site_url` in Mautic to `localhost:8877`, it’s the address of nginx proxy
- Run Mailhog docker or any other application to get a “dummy” SMTP server: `docker run --network host -it mailhog/mailhog`. Mailhog UI for checking emails will be accessible at `http://localhost:8025/`.
- Configure Mautic to use MailHog. `Other SMTP server`, address `localhost`, port `1025`.
- Log in to Mautic via original port, in my case it’s `localhost:8100`. This is extremely important.
- Create any contact with any email(it does not matter because MailHog accepts everything), create a segment that contains that contact.
- Create a campaign to the segment above with just `Send Email` step. Email needs to contain any link. Trigger it, check content in MailHog. All links in email should begin with `localhost:8877/...`
- Go to `Channels` and duplicate the email your created for the campaign but create it as `Segment Email`. Set target as the same you used in previous Campaign.
- Sent that Segment Email by clicking `Send` in UI.
- Check that segment email in mailhog. All urls in email will begin with `localhost:8100/...` which is incorrect because `site_url` is `localhost:8877`.

My original issue was closed. Do you think I could open another issue with the content I wrote in this comment?

EDIT: I added few things and made a new issue on github.

---

<div class="post-metadata">

**Author:** ![ilo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ilo/32/1181_2.png) [@ilo](https://forum.mautic.org/u/ilo)\
**Post date:** [May 19, 2022, 6:07am UTC](https://forum.mautic.org/t/segment-mail-does-not-use-site-url-for-link-replacing-and-tracking/19608/10 "2022-05-19T06:07:27Z")

</div>

Hi @tpapaj ,  
Did you manage to find a solution for this? I have a similar issue with Mautic 4, segment mail sent the mails using the reverse proxy url instead of site\_url.
