For website and server operators

Kistrl Proxy

Kistrl Proxy fetches images, fonts and media on behalf of email readers. Clear identification, temporary caching and bounded requests help your content reach them while keeping their IP addresses and browser details private.

Our requests retrieve specific resources referenced in email when permitted external content is loaded. Allowing Kistrl Proxy helps readers see the content you sent while protecting their privacy.

User-Agent

Every resource request identifies the proxy with the KistrlProxy/ prefix. The complete User-Agent is:

KistrlProxy/1.0 (+https://kistrl.com/image-proxy/)

Request headers

Origin requests use a fixed service identity and advertise the resource types we accept.

HeaderValue
User-AgentKistrlProxy/1.0 (+https://kistrl.com/image-proxy/)
Acceptimage/*, font/*, audio/*, video/*

We send no reader cookies, authentication, browser User-Agent, Origin, Referer or forwarded IP address. Your server receives a request from Kistrl’s infrastructure.

Expected behavior

How we fetch

  • Specific resources. We make HTTP or HTTPS GET requests for exact URLs referenced in email. Only permitted content is requested.
  • Temporary caching. Successful resources are reused for up to 24 hours, reducing repeated downloads from your server. The bounded cache may evict resources sooner.
  • Coordinated requests. Concurrent requests for the same URL and resource type are coordinated, and successful cached results are reused.
  • Validated content. We check resource size and format, verify TLS certificates, and allow only public destinations on ports 80 and 443.

Boundaries we keep

  • We do not crawl websites, follow page links or index fetched content for search.
  • We do not render web pages, execute scripts or load external stylesheets.
  • We do not bypass access denials, login pages or bot challenges. Redirects are disabled.
  • Known tracking resources are blocked before contacting an origin. Unknown recipient-specific URLs can still reveal who a resource was intended for and when it was fetched.

Our current cache uses a service retention limit. Origin Cache-Control and Expires headers do not set that lifetime, and origin requests do not yet use HTTP validators or conditional requests. Delivery responses use Cache-Control: no-store.

Source addresses

Origin requests come from Kistrl’s infrastructure. Use the documented User-Agent to classify this bot in your traffic rules; we do not currently publish a verified egress IP list or reverse-DNS hostname.

proxy.kistrl.com is the address readers use to receive resources. It is a delivery hostname, rather than a verified source hostname for requests reaching your server.

Rate limits and retries

You can apply your normal rate limits to Kistrl Proxy. We bound origin traffic across the service to 8 concurrent fetches, with at most 4 per hostname.

The proxy does not run a background retry loop for failed resources. A failed fetch leaves that content unavailable to the reader; a later permitted request may try again. The reader’s browser stays behind the proxy.

Origin responseOur response
429 or 5xxTemporarily suppress another fetch for the same URL and resource type. Retry-After sets a delay between 1 second and 1 hour; an absent or invalid value defaults to 1 minute.
403Apply a backoff of at least 5 minutes, extended by a longer valid Retry-After within the 1-hour limit.

Failure state is held in the temporary cache and can be evicted sooner. Network errors and other uncached failures may be retried by a later request.

Resource restrictions

Small, validated resources keep delivery bounded. The following source-size limits apply:

ResourceMaximum source size
Images5 MiB
Fonts2 MiB
Audio and video20 MiB

Accepted JPEG, PNG, GIF and WebP images must fit within 4,000 × 4,000 pixels and 16 megapixels. We reencode them as PNG or JPEG and strip image metadata.

Supported fonts are WOFF, WOFF2, OTF and TTF. Supported media are MP4, WebM, Ogg, MP3 and WAV. Fonts and media are checked for supported file signatures and passed through.

SVG, HTML and JavaScript are rejected. Resource validation is not a comprehensive malware scan or removal of all media metadata.

Identifying requests

To recognize Kistrl Proxy in your logs or bot rules:

  1. Match a User-Agent beginning with KistrlProxy/.
  2. Use the documented Accept header as an additional classification hint.
  3. Allow that bot classification through generic browser challenges while keeping your normal rate limits and access controls.

These headers are identifiers and can be copied by other clients. They are not authentication or cryptographic proof that a request originated from Kistrl.

Why allow Kistrl Proxy?

The proxy helps your email content reach its audience with a small, clearly identified request footprint.

  • Your email displays as intended. Recipients can see the images, fonts and media you included in their messages.
  • Reader privacy stays protected. Your server receives Kistrl’s request without the reader’s IP address, browser details or credentials.
  • Caching reduces repeat downloads. Successful responses are shared from a temporary cache instead of fetched on every view.
  • Your server keeps control. Requests have bounded concurrency, and 429, 5xx and 403 responses trigger the backoff policy above.

Allow the KistrlProxy/ User-Agent prefix in your bot rules so Kistrl readers can receive your email resources. Blocking the proxy leaves those resources unavailable to them.

Operator information

Operator
Kistrl