Broaden the current Content Security Policy for assets required by web-based version of emails

While our charity client was initially advised that Blackbaud's system matches its competitors, we're encountering notable limitations, particularly with the advanced mass email setup in eTapestry.

For the web-based version of the email, a number of image assets are being blocked by the current restrictive Content Security Policy, which is primarily favouring US-centric domains (.com and .net). Our UK-based charity client, who use a .uk domain, faces challenges in serving custom email headers and footers. For the time being, we've had to rely on a .net domain, which isn't ideal. To truly cater to global partners, Blackbaud should consider a more inclusive domain policy. I was very surprised to see that at least the primary country specific TLD's aren't covered (i.e. .co.uk, .fr, .es, etc).

  • Dan Tulloch
  • Aug 18 2023
  • Attach files
  • Admin
    Kimberly Hammer commented
    September 22, 2023 14:12

    Hi Dan,

    Could you please provide an example URL, or two, of the web-based versions of your emails that won't render images? And are you using a Drag-n-Drop or Classic email template?

    We'd like to investigate this issue and work on resolving it. Feel free to post a comment or you can send me an email.

    Thanks!

    Kim

    kimberly.hammer@blackbaud.com