Skip to main content
Any SMTP client or library can send mail through Inbound with a managed Mailbox + SMTP or SMTP only credential. Messages submitted over SMTP go through the same sending pipeline as the send email API, so the same account sending limits and domain checks apply. If you don’t have a credential yet, follow Create a mailbox credential. Choose SMTP only if the application never needs to read mail.

Connection settings

Both ports require TLS 1.2 or later. On port 587, the server only offers AUTH after STARTTLS has completed, and authentication attempted before TLS is rejected with 538. Keep certificate verification enabled. Ordinary account API keys and your dashboard password cannot authenticate to SMTP.

Allowed senders

Each credential has a sender policy. The gateway checks both the envelope sender (MAIL FROM) and the address in the message’s From header against it: An empty envelope sender (MAIL FROM:<>) is accepted, but the From header must still be allowed. If the message has no From header, the envelope sender is used as the From address. A disallowed sender is rejected with 553. The display name comes from the From header you send. The dashboard’s Display name field does not change outgoing messages. See SMTP sender policies for how scopes and sender policies interact.

Recipients and Bcc

The envelope recipients (RCPT TO) decide who receives the message:
  • Addresses in the To and Cc headers are delivered and shown only if they are also envelope recipients. Header addresses that are not envelope recipients are removed.
  • Envelope recipients that don’t appear in To or Cc are delivered as Bcc and are not visible to other recipients.
  • A Bcc header in the message is ignored.
Nodemailer and Python’s send_message build the envelope from To, Cc, and Bcc automatically, so Bcc works as expected with both.

How messages are rebuilt

Inbound parses each submitted message and sends it again through the email API; it does not relay the raw bytes. The delivered message keeps:
  • From, To, Cc, Reply-To, and Subject
  • The plain-text and HTML bodies
  • Attachments, including inline images referenced by Content-ID
  • In-Reply-To, References, and custom X- headers (except X-SES-*)
Other headers, such as your own Message-ID or Date, are not preserved. Line breaks and control characters are removed from header values.

Limits

The size limit applies to the complete MIME message. Base64 encoding makes attachments about a third larger than the original files. If the client sends a SIZE parameter above the limit, the message is rejected before DATA. When a login is throttled, further attempts from that address fail with 421 until the 15-minute window ends, even with the correct password. Authentication requests are also rate-limited by the API. SMTP sends count toward your account’s sending limits and API rate limits. SMTP does not save a copy in the IMAP Sent folder; see Sent mail is not saved automatically.

Supported extensions

The server advertises PIPELINING, 8BITMIME, SIZE, STARTTLS (port 587, before TLS), and AUTH PLAIN LOGIN (after TLS). SMTPUTF8, DSN, and ENHANCEDSTATUSCODES are not supported:
  • Addresses must be ASCII. A non-ASCII local part is rejected with 553. Non-ASCII display names, subjects, and bodies work normally when MIME-encoded.
  • MAIL FROM accepts only the SIZE, BODY, and AUTH parameters, and RCPT TO accepts none. Others, such as the DSN parameters RET, ENVID, NOTIFY, and ORCPT, are rejected with 555. In Nodemailer, leave the dsn option unset.
After STARTTLS, send EHLO again before AUTH. SMTP libraries do this automatically.

Reply codes

Reply text includes an enhanced status code, such as 5.7.8, even though ENHANCEDSTATUSCODES is not advertised. Inbound derives an idempotency key from the credential, envelope sender, recipients, and exact message bytes. If a client resubmits an identical message that was already sent, for example after a dropped connection, Inbound returns the original result instead of sending it twice. Libraries that generate a new Message-ID or Date for each attempt produce a different message, so this only covers retries of the same bytes.

Examples

Store the credential as INBOUND_MAILBOX_LOGIN and INBOUND_MAILBOX_PASSWORD. Replace support@example.com with an address your sender policy allows. The TypeScript example uses Nodemailer (bun add nodemailer); the Python example uses only the standard library.
For port 465 in Python, use smtplib.SMTP_SSL("smtp.inboundemail.com", 465, context=context) and skip starttls().

Mail client settings

Set the account’s email address to an address your sender policy allows. To receive mail in the same client, add the IMAP settings.

Test the connection

Check TLS and the advertised extensions without sending credentials:
After the handshake, type EHLO example.com. The reply should list AUTH PLAIN LOGIN and SIZE 3145728. Type QUIT to close the connection.