Default
Enforce (recommended)
ConnectSMS rejects every request that does not carry a valid Twilio signature. Sending can only be turned on in this mode.
Security, consent and reliability
ConnectSMS runs inside your Salesforce org and talks only to your Twilio account. Here is how it protects that connection, respects opt-outs, and avoids losing or duplicating customer messages.
Is ConnectSMS secure? ConnectSMS checks Twilio's signature on every webhook call, verifies your Twilio credentials before saving them and never shows the Auth Token again. Messages are private and shared only through access to each business number, opt-outs are always enforced, and a message with an unclear outcome is checked with Twilio rather than sent twice.
Security
ConnectSMS is built on the Salesforce Platform, and Salesforce connects directly to your Twilio account with no ConnectSMS servers in between. These controls protect that connection and the messages that travel over it.
Every webhook call is checked against Twilio's signature for the exact address and parameters. In Enforce mode, the default, unsigned or forged requests are rejected, and sending can't be turned on without it.
Credentials are verified with Twilio before they're saved, and webhook requests must match the Account SID of your saved connection.
The Auth Token lives in a protected setting only ConnectSMS can read. Your Twilio Auth Token is never shown in the browser or written to logs.
The Site guest user gets ConnectSMS Webhook Guest, which grants the webhook Apex class and nothing else. It gives no access to your records.
Messages and conversations are private. People read them only through View or Send access to the business number.
Configuration, access and consent changes are recorded in an audit log, with who made each change and when.
In a sandbox copied from an org where sending is on, sending turns off automatically until an admin turns it on in that sandbox.
The only outside service ConnectSMS calls is Twilio's API. No ConnectSMS server stores or relays your messages.
Admins can turn off sending for the whole org at once. A reason is required and recorded in the audit log.
Signature check: three modes, one safe default
Default
ConnectSMS rejects every request that does not carry a valid Twilio signature. Sending can only be turned on in this mode.
Short-term
Requests with a missing or wrong signature are accepted but recorded. Use it briefly while fixing a signature problem, then switch back.
Never in production
No signature check at all. Never use Off in production or in a sandbox that holds real customer data.
Consent
Opt-outs are recorded from the customer's own reply, enforced on every path and checked again at the moment of sending.
Opt-out keywords
STOPSTOPALLUNSUBSCRIBECANCELENDQUITREVOKEOPTOUTOpt back in
STARTYESUNSTOPRecognized when the whole reply is the keyword, in any letter case. HELP and INFO are answered by Twilio, not ConnectSMS.
When someone asks to stop by phone, email or in person, an admin adds the opt-out in ConnectSMS Setup and it applies at once, including to queued and scheduled messages.
Only remove an opt-out when this person has asked to receive messages again, for example by texting START, and you can show that consent. Other opt-outs for the same phone number still apply.
Recreated from the ConnectSMS interface with sample data.
Reliability
Every message is written to Salesforce before ConnectSMS calls Twilio. If Twilio's answer is lost, the message is marked Unknown and checked with Twilio, never blindly sent again.
Sending means Twilio accepted the message. Sent means it was handed to the carrier, and Delivered means the carrier confirmed it.
Normal path
If Twilio's answer is lost
Each message is saved in Salesforce first, so a lost connection can't lose the message or its history.
A timeout, connection error or Twilio server error marks the message Unknown. ConnectSMS asks Twilio what happened and records the matching status, or Failed if Twilio never got it.
Messages sent now go to a background job right away. Scheduled messages, outreach and anything still waiting are picked up by the dispatcher every 15 minutes.
Idempotency keys let Flow, Apex and API callers repeat a request without sending the message twice, and the composer ignores double clicks.
If Twilio answers 429 Too Many Requests, the message goes back to Queued and is tried again after a pause.
A message still waiting on Twilio's answer after 10 minutes is marked Unknown and checked with Twilio.
Failed and Undelivered messages can be retried deliberately as a new message linked to the first, so the history shows both.
Each failure says what went wrong and what to do next, with the Twilio error code.
Before a queued or scheduled message goes out, ConnectSMS re-checks the sending switch, permissions, number access and opt-outs.
| Status | What it means |
|---|---|
| Scheduled | Waiting for its scheduled time; permissions and consent are checked again before sending |
| Queued | Saved and waiting to be handed to Twilio |
| Sending | Twilio accepted it and is sending it to the carrier |
| Sent | Handed to the carrier; delivery not yet confirmed |
| Delivered | The carrier confirmed delivery; this does not mean it was read |
| Read | Reported read by the recipient's app |
| Undelivered | The carrier couldn't deliver it |
| Failed | It couldn't be sent |
| Blocked | A ConnectSMS rule blocked it |
| Canceled | Canceled before it was sent |
| Unknown | ConnectSMS couldn't confirm whether Twilio accepted it; it is being checked and won't be resent automatically |
| Received | Received from the customer |
Permissions
Two things decide what someone can do: a ConnectSMS permission set, and access to specific business numbers.
Everyday texting, the inbox and templates, on the business numbers an admin has granted.
Creates, reviews, launches, pauses and cancels outreach, and manages shared templates. Combine with ConnectSMS User to text one-to-one.
Twilio connection, business numbers, access, policies, opt-outs and operations.
For integration users, agent users and people who run Flow or API messaging from numbers made available to automation.
| Permission set | Custom permissions |
|---|---|
| ConnectSMS User | ConnectSMS: Send Messages |
| ConnectSMS Campaign Manager | ConnectSMS: Manage Outreach ConnectSMS: Manage Templates ConnectSMS: Send from Automation Numbers |
| ConnectSMS Automation | ConnectSMS: Send from Automation Numbers |
| ConnectSMS Admin | All five, including ConnectSMS: Administer |
FAQ
When a customer replies with one of Twilio's standard opt-out keywords, such as STOP, UNSUBSCRIBE or CANCEL, ConnectSMS records the opt-out and stops texting that number; START, YES or UNSTOP opts them back in. Opt-outs are always enforced, checked when a message is requested and again when it is sent, and shown to users in the composer and inbox.
No software can do that on its own. ConnectSMS gives you controls that help your team apply the policies you choose, including opt-out enforcement, quiet hours for outreach and automation, number-level access and an audit log. You remain responsible for consent and for the rules that apply to your messages.
Twilio signs every request it sends. ConnectSMS checks that signature against the exact webhook address and parameters using your Auth Token, and checks that the request names your Twilio account. In Enforce mode, which is required before sending can be turned on, any request that fails is rejected.
The message is marked Unknown instead of being sent again. ConnectSMS asks Twilio whether it received the message: if it did, the real status is recorded; if not, the message becomes Failed and someone can retry it deliberately. Admins can also choose Check with Twilio in Operations.
When a sandbox is copied from an org where sending is on, ConnectSMS turns sending off in the sandbox automatically. An admin has to review the Twilio settings and turn sending on there. We recommend a Twilio test account or a separate subaccount for sandboxes.
Policies, opt-outs, the sending switch and the audit log in ConnectSMS Setup.
How the connection, numbers and signed webhook fit together.
How STOP and START work with Twilio and Salesforce.
Try it now: every feature, free for 14 days
Install ConnectSMS from AgentExchange, connect your Twilio account and give your team the numbers they should text from.
ConnectSMS is published by WorkBridge Solutions. Twilio bills your Twilio account directly for messaging, including during the trial.