Preserve the original attempt
Give the intended business action a local identifier before sending. Save its conversation, approved content reference, target, creation time and current state. Keep secrets and unnecessary message content out of broad application logs.
If the provider supports an idempotency key or another documented client reference, use it within the documented scope. Do not assume every messaging API offers the same facility.
Reconcile before repeating the side effect
On timeout, record an uncertain state rather than immediately declaring failure. Use the provider’s documented lookup or event mechanism to determine whether the original attempt was accepted. Preserve any provider message ID you already received.
A blind retry can create a second message when the first request succeeded but its response was lost. If the outcome cannot be established safely, route the case to the defined recovery process instead of silently sending again.
Test a deliberately interrupted response
In an approved test environment, interrupt the client’s receipt of the result while retaining the records needed to investigate. Check what the recipient sees and how the application reconciles the attempt.
Document the decision for each provider and channel. The goal is an explainable result and a controlled next step; do not claim exactly-once delivery unless the entire relevant system actually establishes it.