Connection settings
Both ports require TLS 1.2 or later. On port
587, the server only offers AUTH after STARTTLS has completed, and authentication attempted before TLS is rejected with 538. Keep certificate verification enabled.
Ordinary account API keys and your dashboard password cannot authenticate to SMTP.
Allowed senders
Each credential has a sender policy. The gateway checks both the envelope sender (MAIL FROM) and the address in the message’s From header against it:
An empty envelope sender (
MAIL FROM:<>) is accepted, but the From header must still be allowed. If the message has no From header, the envelope sender is used as the From address. A disallowed sender is rejected with 553.
The display name comes from the From header you send. The dashboard’s Display name field does not change outgoing messages. See SMTP sender policies for how scopes and sender policies interact.
Recipients and Bcc
The envelope recipients (RCPT TO) decide who receives the message:
- Addresses in the
ToandCcheaders are delivered and shown only if they are also envelope recipients. Header addresses that are not envelope recipients are removed. - Envelope recipients that don’t appear in
ToorCcare delivered as Bcc and are not visible to other recipients. - A
Bccheader in the message is ignored.
send_message build the envelope from To, Cc, and Bcc automatically, so Bcc works as expected with both.
How messages are rebuilt
Inbound parses each submitted message and sends it again through the email API; it does not relay the raw bytes. The delivered message keeps:From,To,Cc,Reply-To, andSubject- The plain-text and HTML bodies
- Attachments, including inline images referenced by
Content-ID In-Reply-To,References, and customX-headers (exceptX-SES-*)
Message-ID or Date, are not preserved. Line breaks and control characters are removed from header values.
Limits
The size limit applies to the complete MIME message. Base64 encoding makes attachments about a third larger than the original files. If the client sends a
SIZE parameter above the limit, the message is rejected before DATA.
When a login is throttled, further attempts from that address fail with 421 until the 15-minute window ends, even with the correct password. Authentication requests are also rate-limited by the API.
SMTP sends count toward your account’s sending limits and API rate limits. SMTP does not save a copy in the IMAP Sent folder; see Sent mail is not saved automatically.
Supported extensions
The server advertisesPIPELINING, 8BITMIME, SIZE, STARTTLS (port 587, before TLS), and AUTH PLAIN LOGIN (after TLS).
SMTPUTF8, DSN, and ENHANCEDSTATUSCODES are not supported:
- Addresses must be ASCII. A non-ASCII local part is rejected with
553. Non-ASCII display names, subjects, and bodies work normally when MIME-encoded. MAIL FROMaccepts only theSIZE,BODY, andAUTHparameters, andRCPT TOaccepts none. Others, such as the DSN parametersRET,ENVID,NOTIFY, andORCPT, are rejected with555. In Nodemailer, leave thedsnoption unset.
STARTTLS, send EHLO again before AUTH. SMTP libraries do this automatically.
Reply codes
Reply text includes an enhanced status code, such as5.7.8, even though ENHANCEDSTATUSCODES is not advertised.
Inbound derives an idempotency key from the credential, envelope sender, recipients, and exact message bytes. If a client resubmits an identical message that was already sent, for example after a dropped connection, Inbound returns the original result instead of sending it twice. Libraries that generate a new
Message-ID or Date for each attempt produce a different message, so this only covers retries of the same bytes.
Examples
Store the credential asINBOUND_MAILBOX_LOGIN and INBOUND_MAILBOX_PASSWORD. Replace support@example.com with an address your sender policy allows. The TypeScript example uses Nodemailer (bun add nodemailer); the Python example uses only the standard library.
465 in Python, use smtplib.SMTP_SSL("smtp.inboundemail.com", 465, context=context) and skip starttls().
Mail client settings
Set the account’s email address to an address your sender policy allows. To receive mail in the same client, add the IMAP settings.
Test the connection
Check TLS and the advertised extensions without sending credentials:EHLO example.com. The reply should list AUTH PLAIN LOGIN and SIZE 3145728. Type QUIT to close the connection.