Document audit · research date 26 Sep 2026
Mautic campaign-operation boundary audit.
Mautic Community 7.2.1 documents contacts, preferences, forms, segments, campaigns, mail transport, queues, cron commands, webhooks, roles, and reports. Those features require an operator to provide the infrastructure and governance around them.
Decision
Use Mautic only when someone can operate the whole path.
The documented features support an operated marketing workflow. They do not make campaign activity safe, approved, compliant, deliverable, monitored, or recoverable by themselves.
- Best fit
- A team that needs owned contact and campaign state and can own database, transport/DNS, scheduler or worker, credentials, roles, monitoring, retention, and tested recovery.
- Not for
- Zero-operations drafting, unattended outbound marketing, a substitute for consent or legal review, or a team that cannot operate its mail and recovery boundary.
- Evaluation boundary
- Isolated local environment; fictional data only; no external send, tracking, CRM mutation, public webhook, production credential, or unattended scheduler or worker.
What the checked material establishes
| Surface | Documented fact | Not established by that fact |
|---|---|---|
| License and release | The 7.2.1 tag's composer metadata declares GPL-3.0. The release record labels 7.2.1 Latest at the audit date. | A license conclusion for every plugin, transport, provider, queue, CRM, or hosted service; or a recommendation to upgrade without testing. |
| Contacts, preferences, and DNC | Preference-center settings document channel DNC, preferred channel, frequency, and temporary pause. Roles can grant permission to send to unsubscribed contacts. | Valid consent, legal compliance, immutable consent evidence, all-channel suppression, or a rule that a privileged user cannot override a control. |
| Forms, segments, and campaigns | Forms can map fields and execute actions. The campaign builder documents actions, decisions, conditions, active state, and scheduled activation. | Legal wording, real-person consent, suitable segment criteria, or an out-of-the-box two-person approval gate before a send or contact change. |
| Mail and queue | Settings document Symfony Mailer transport configuration, immediate delivery, optional queueing, retries, and failure queues. A queue consumer processes queued mail. | Valid sender identity, DNS, provider acceptance, deliverability, reputation, capacity, safe retries, or message reconciliation. |
| Scheduled execution | Cron documentation says operators must add campaign update and trigger jobs; it also documents queue and webhook processing commands. | That a job is installed, supervised, monitored, or operating safely in any deployment. |
| Access, reports, and recovery | Roles are granular; reports expose campaign, queue, email, form, segment, and DNC sources. The update guide requires a tested files-and-database backup before update. | Least privilege, dual control, tamper-resistant audit logging, retention, a successful restore, or a particular deployment's patch and monitoring state. |
A campaign does not operate itself
Documented fact. Campaign membership needs mautic:campaigns:update; campaign events need mautic:campaigns:trigger. If queueing is configured, email remains in a queue until a consumer such as messenger:consume email runs. The documentation requires the operator to add and manage those commands.
Inference. Actual delivery requires a configured transport/provider/sender and an execution path that reaches a send action. A campaign graph, queue setting, DNC field, role, or activation switch does not independently provide either. This audit did not test delivery, suppression in a live send, provider acceptance, timing, or non-delivery.
Smallest no-delivery evaluation proposal
- Use an isolated, non-production local environment and fictional records only. Do not attach public domains, production credentials, or a real mail provider.
- Do not configure a send action, external form action, webhook, connector, tracking script, scheduled broadcast, queue consumer, campaign trigger, or cron entry.
- If a local form, segment, or inactive campaign shell is used to inspect the interface, keep it non-public and inactive. Stop before any external call.
- Have a named reviewer check that the data are fictional and no external transport, connector, webhook, worker, or scheduler is configured. This is an operator policy, not a Mautic feature.
- Delete the fictional records and isolated environment under the evaluator's local procedure. This does not establish secure deletion, restore success, or production readiness.
Material uncertainty
The checked material did not establish a current 7.2 runtime/database matrix; complete retention or audit-log semantics; immutable consent; all-channel or cross-system suppression; a two-person approval gate; secret/key-management guarantees; exact connector scope or security; message reconciliation or rollback; deliverability or performance; or whether any deployment is patched, backed up, monitored, or recoverable.
Before a real campaign, an operator must separately select a supported runtime, protect secrets, define contact provenance and suppression policy, validate transport and DNS, supervise cron or workers, constrain integrations, configure monitoring and retention, test restore and incident handling, and establish human launch review.
Primary sources checked
- Mautic 7.2.1 release and tagged composer metadata
- 7.2 configuration settings and cron jobs
- Forms, campaign builder, preference center, and roles
- Reports, update guidance, and security policy
This report is not legal advice, a security audit, a deliverability test, or a production recommendation.