Limits and timings
Signature limits
Section titled “Signature limits”| Limit | Value | Imposed by |
|---|---|---|
| Rendered signature size | Under 30,000 characters | Outlook |
| Image formats | PNG and JPG. No SVG | Outlook |
| Image delivery | Inline cid: attachments, not hosted URLs |
Outlook |
The size limit applies to the HTML, including any footer. Attached images do not count toward it. A publish that would exceed it is blocked in the portal.
See Outlook constraints.
Designer limits
Section titled “Designer limits”| Limit | Value |
|---|---|
| Blocks per design | 200 |
| Columns per row | 6 |
| Nested rows | 4 deep |
| Canvas width | 100 to 900 pixels |
| Column width | 1 to 100 per cent, or 1 to 900 pixels |
| Text size | 6 to 72, in pixels or points |
| Line height | 6 to 120 |
| Block padding, per side | 0 to 200 pixels |
| Image width and height | 1 to 1000 pixels |
| QR code size | 60 to 400 pixels |
| Profile photo size | 16 to 400 pixels |
| Social icon size | 8 to 128 pixels |
| Gap between social icons | 0 to 60 pixels |
| Built-in social marks | 27, being 24 networks plus website, email and phone |
| Button corner radius | 0 to 40 pixels |
| Button padding, horizontal and vertical | 0 to 60 pixels |
| Divider thickness | 1 to 20 pixels |
| Divider width | 1 to 100 per cent |
| Spacer height | 1 to 200 pixels |
| Border width | 1 to 20 pixels |
| Block minimum height | 1 to 600 pixels |
A design that breaks one of these is rejected at publish with a message naming the block at fault. See the designer.
These are ceilings rather than recommendations. A signature is read in a preview pane a few hundred pixels wide, so the useful range for most of them sits well below the maximum.
Assignment rules
Section titled “Assignment rules”| Item | Value |
|---|---|
| Rules per organisation | 100 |
| Attributes a rule can match on | 10 |
| Values in one attribute rule | No limit, comma separated |
| How a group is named | Its Entra object id, typed or pasted, not checked when saved |
| Roles a rule must set | At least one of new messages and replies |
See assignment rules.
Retention
Section titled “Retention”| Data | Retention |
|---|---|
| Template version history | Last 10 published bodies per template |
| Recently deleted templates | 30 days, then purged by a daily sweep |
| Change log | Indefinite |
| Signature telemetry | Indefinite |
| Daily click totals per tracked link | Indefinite |
| Per-click records behind the analytics splits | 90 days, then purged by a nightly sweep |
| Signature copy kept on a person’s device | 45 days from that address’s last compose, renewed by each one |
| Operator audit log | Indefinite |
| Onboarding attempt records | Indefinite, and kept after a deprovision |
| Sign-up diagnostics held on those records | 90 days, then cleared while the attempt stays |
| Sign-ins from an organisation that never connected | 90 days from the last sighting, then removed in full |
Click totals and the daily chart outlive the per-click records they were built from, so they reach back to the day a link was created. The device, client, referring page and hour-of-day splits are computed from the per-click records and therefore only cover the last 90 days. See link clicks.
How much of the change log you can read at once
Section titled “How much of the change log you can read at once”| Item | Value |
|---|---|
| Entries in the portal’s Audit log view | Most recent 500 of each half, paged |
| Entries a single API request returns | Most recent 500 |
| Entries in a tenant export | Most recent 5,000 |
All three are display limits rather than retention ones. The two halves are fetched separately, so template changes cannot be pushed out of view by a busy week of role changes. Narrowing by who or by action then works on what was fetched, and does not reach further back. See the change log.
Link analytics windows
Section titled “Link analytics windows”| Item | Value |
|---|---|
| Windows offered in the portal | 7 days, 30 days, 90 days, 12 months |
| Shortest and longest window the API accepts | 7 to 365 days, clamped rather than rejected |
| Trend column on the links table | Last 30 days |
| Referring hosts shown before the tail is bucketed | 8 |
| Clicks counted from one address on one link | 60 a minute. Above that the recipient is still redirected and only the record is dropped |
How long changes take to reach users
Section titled “How long changes take to reach users”| Change | Time |
|---|---|
| Template publish | Seconds |
| Staged publish, for the mailboxes in the slice | Seconds |
| Promoting or abandoning a staged rollout | Seconds |
| Scheduled publish | Within 15 minutes after its instant, never before |
| Version restore | Seconds |
| Image upload or replacement | Seconds |
| Footer edit | Seconds |
| Banner window opening or closing | Immediately |
| Pausing or resuming delivery | Next compose |
| Assignment rules change | Next compose |
| Directory change affecting which rule matches | Ten minutes, then one further compose |
| Profile field value saved, by anybody in the organisation | Next compose |
| Directory attribute change in Entra | Up to an hour, without a republish |
Those are the times a change takes to reach what a mailbox is served. The first message somebody composes after a publish can briefly draw the previous signature and then replace it, because the add-in starts from the copy it kept on the device. What is sent is the new version either way. See why it sometimes changes as you watch. | Microsoft 365 profile photo added or changed | Up to a day | | Add-in manifest change | Requires redeploy, plus 6 to 72 hours propagation and fresh consent | | Initial add-in deployment | 6 to 72 hours propagation |
The two rules rows are different events. Saving a rule list changes the version its cached decisions are filed under, so the edit lands on the next compose. A change made in Entra changes nothing in Sigil, so a cached decision has to reach the end of its ten minute freshness window before the new department or group can route somebody differently. The re-check then happens in the background rather than while a message is being written, so the first compose after the window still uses the old decision and the one after it follows the directory.
Staged rollout defaults
Section titled “Staged rollout defaults”| Item | Value |
|---|---|
| Percentage steps | 10, 25, 50, then everyone |
| Rollouts per template | One at a time |
| Evaluation frequency | Every 15 minutes |
| Apply outcomes needed before any decision | 20 on the new version |
| Soak per step | 60 minutes |
| Failure rate that can trigger a rollback | Above 10% |
| Margin over the current version needed to call it a regression | 5 percentage points |
Both conditions on the last two rows must hold before a rollout is pulled. See staged rollouts.
Scheduled publishing
Section titled “Scheduled publishing”| Item | Value |
|---|---|
| Pending schedules per template | One. Booking a second replaces the first |
| Furthest ahead a publish may be booked | 365 days |
| How often schedules are checked | Every 15 minutes |
| Retries after a failed schedule | None. The failure and its reason are kept |
See scheduled publishing.
Approval and settings
Section titled “Approval and settings”| Item | Value |
|---|---|
| Publish approval | Off by default, per organisation |
| Rejection note | Required, and kept up to 1,000 characters |
| Approving your own submission | Permitted, and recorded as such |
| Profile editing | Off by default, per organisation |
| Health digest | Weekly by default. Weekly, monthly or off |
See publish approval and the health digest.
Profile fields
Section titled “Profile fields”| Item | Value |
|---|---|
| Fields per organisation | 24 |
| Field key | Starts with a lower-case letter, then letters and numbers, up to 32 characters |
| Field label | 60 characters |
| Help text | 200 characters |
| Types | Text, choice, URL, email, phone |
| Options on a choice field | 1 to 24, each up to 100 characters |
| Maximum length of a value | 500, and never above the field’s own maximum |
| Default maximum length | 200 characters |
| Whole profile per mailbox | 8 KB |
| Renaming a field key | Not offered. Delete and re-add |
| Saves per mailbox | Rate limited, well above normal use |
A required field is advisory. One nobody filled in renders empty rather than failing a compose. See profile fields.
Portal actions that cost something
Section titled “Portal actions that cost something”Most of what the portal does is a database read you have already paid for by signing in. A few actions cost more than that: they call Microsoft Graph, render a signature, or send an email. Those carry a ceiling, counted per administrator per organisation rather than per address, so an IT provider working across twenty client organisations is twenty separate callers rather than one.
| Item | Value |
|---|---|
| Actions that render, read the directory or resolve a mailbox | 120 a minute |
| Actions that send an email | 12 a minute |
| What counts in the first group | Preview, previewing an archived version, downloading a mailbox’s signature, saving somebody else’s profile values, simulating assignment rules, syncing an excluded group now |
| What counts in the second | Test email, and sending the health digest on demand |
| Over the limit | 429 with a message saying to wait a moment. Nothing is changed or sent |
| An API key’s share | Its own, so a key cannot spend a person’s allowance |
The figures are set well above what the portal’s own screens can generate by being used. Reaching one means a script, a stuck retry, or a page left refreshing itself.
API keys
Section titled “API keys”| Item | Value |
|---|---|
| Keys per organisation | No limit |
| Key name | 80 characters |
| Expiry | Optional, and must be in the future |
| Times the secret is shown | One, at creation |
| Requests per key | 600 a minute, then 429 until the rate falls back under it |
| Requests presenting a key, per calling address | 2,000 a minute, counting invalid keys as well as valid ones |
| Resolution of “last used” | One hour |
| Effect of revoking | Immediate, and irreversible |
| Endpoints reachable | Only those on the allow-list shown in the portal. Anything else answers 404 |
See API keys.
Trial and billing
Section titled “Trial and billing”| Item | Value |
|---|---|
| Trial length | 14 days |
| Price | £0.70 per licensed mailbox per month |
| Billing period | Monthly |
| Billable seat | A licensed member mailbox that cost management has not kept out of Sigil |
| Free | Shared and resource mailboxes, accounts invited in from outside, disabled accounts, mailboxes kept out of Sigil |
| Longest agreed discount term | 60 months, or open-ended |
| Default invoice terms | 30 days from the invoice date |
| Longest agreed invoice terms | 90 days |
| After a failed payment, before signatures stop | 21 days from the first failure |
| After an invoice goes past its due date, before signatures stop | 21 days from the due date |
| Invoices listed in the portal | The most recent 24 |
| Purchase order reference | 140 characters |
| Seat sync | Daily, with no mid-cycle proration |
| Exclusion suggestion window | 90 days without a successful apply |
| Exclusion note | 200 characters |
Once a trial ends without an active subscription, signatures stop being served. A failed payment on a live subscription is bounded rather than immediate: Stripe retries the card over roughly three weeks, and signatures stop 21 days after the first failure if the invoice is still unpaid. See billing.
On invoice terms the same 21 days are counted from the due date, so net 30 allows up to 51 days from the invoice being issued. See invoices and credits.
Client support
Section titled “Client support”| Client | Automatic on compose | “My signature” pane |
|---|---|---|
| Outlook on Windows, classic and new | Yes | Yes |
| Outlook on the web | Yes | Yes |
| Outlook on Mac | Yes | Yes |
| Outlook for iOS and Android | Yes | No |
Only one event-based add-in runs at a time. If several are deployed, they run sequentially.
Operator session limits
Section titled “Operator session limits”| Item | Value |
|---|---|
| Read-only impersonation session | 30 minutes, expiring on the server |
| Destructive operator actions | Require fresh interactive re-authentication |
