> ## Documentation Index
> Fetch the complete documentation index at: https://inbound.new/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# IMAP Behavior

> Folders, supported IMAP features, synchronization, limits, and known limitations

Inbound presents received email through a managed IMAP mailbox rather than a conventional standalone mail store. `INBOX` and scope folders are views of the mail Inbound has received, so some operations behave differently than on a traditional IMAP server.

## Default folders

Each mailbox credential includes these folders:

| Folder | Special-use attribute | Behavior |
| - | - | - |
| `INBOX` | None | Incoming mail from every configured scope |
| `Sent` | `\Sent` | For client-saved sent messages; not populated automatically |
| `Drafts` | `\Drafts` | For client-saved drafts |
| `Trash` | `\Trash` | For client-organized messages |
| `Junk` | `\Junk` | For client-organized messages; incoming mail is not filtered into it |

The personal namespace is `""` and the hierarchy separator is `/`. `INBOX` and the special-use folders cannot be deleted, and `INBOX` cannot be renamed. With a `read_write` credential you can create, rename, and delete other folders. Renaming a folder also renames its subfolders. Creating or renaming onto an existing name returns `NO [ALREADYEXISTS]`.

Folders, flags, and appended messages belong to one credential. Other credentials on the same account don't see them.

### Scope folders

Every configured scope also appears as a folder under `Scopes`:

```text theme={null}
INBOX
Sent
Drafts
Trash
Junk
Scopes/*@example.com
Scopes/support@another-example.com
```

`Scopes` is a non-selectable container (`\Noselect`), and its name is reserved. A domain scope appears as `Scopes/*@example.com`; an address scope appears as `Scopes/support@example.com`.

Scope folders are filtered views of the same messages as `INBOX`. They always open read-only, even for `read_write` credentials. You cannot append, move, or copy messages into a scope folder, change flags in it, or expunge from it. A `read_write` credential can copy messages from a scope folder into a writable folder.

## Capabilities

The server advertises exactly these capabilities:

```text theme={null}
IMAP4rev1 APPENDLIMIT=1048576 AUTH=PLAIN CHILDREN ENABLE ID IDLE MOVE NAMESPACE SASL-IR SPECIAL-USE UIDPLUS UNSELECT UTF8=ACCEPT WITHIN
```

Supported commands:

* Authentication: `LOGIN` and `AUTHENTICATE PLAIN` (with `SASL-IR`). A `PLAIN` authorization identity different from the login email is rejected.
* Folders: `LIST`, `LSUB`, `NAMESPACE`, `SELECT`, `EXAMINE`, `STATUS`, `CREATE`, `RENAME`, `DELETE`, `SUBSCRIBE`, `UNSUBSCRIBE`.
* Messages: `FETCH`, `SEARCH`, `STORE`, `COPY`, `MOVE`, and their `UID` forms, plus `EXPUNGE`, `UID EXPUNGE`, `APPEND`, `CLOSE`, `UNSELECT`, `CHECK`, `NOOP`, and `IDLE`.
* `ENABLE UTF8=ACCEPT`. Other `ENABLE` arguments are ignored.

`COPY` and `APPEND` return `COPYUID` and `APPENDUID`. `MOVE` returns `COPYUID` followed by an untagged `EXPUNGE` for every moved message, and moving a message into the folder it's already in returns `NO`. `EXPUNGE` and `UID EXPUNGE` send an untagged `EXPUNGE` for each removed message.

`SUBSCRIBE` and `UNSUBSCRIBE` succeed but aren't stored; `LSUB` returns every folder.

Extensions that aren't advertised are not supported, including `STARTTLS` (use implicit TLS on port `993`), `CONDSTORE`, `QRESYNC`, `QUOTA`, `COMPRESS=DEFLATE`, `SORT`, `THREAD`, `ACL`, OAuth (`XOAUTH2` or `OAUTHBEARER`), and the Gmail-only `XLIST`. Requests that would enable `CONDSTORE`, such as `SELECT (CONDSTORE)` or `SEARCH MODSEQ`, are rejected.

### Search

`SEARCH` supports sequence sets, `UID`, flag and keyword keys (such as `SEEN`, `UNSEEN`, `DELETED`, `FLAGGED`, `KEYWORD`), `BEFORE`/`ON`/`SINCE`, `SENTBEFORE`/`SENTON`/`SENTSINCE`, `LARGER`/`SMALLER`, `OLDER`/`YOUNGER` (`WITHIN`), `HEADER`, `FROM`, `TO`, `CC`, `BCC`, `SUBJECT`, `BODY`, `TEXT`, `OR`, and `NOT`.

* Text searches are case-insensitive substring matches. For received mail they match Inbound's parsed fields: `SUBJECT`, the address headers, and the plain-text body. `TEXT` checks the subject and plain-text body, so text that exists only in an HTML part may not match. For appended messages they match the raw message.
* `HEADER` searches on other header names match the raw message.
* `SENTBEFORE`, `SENTON`, and `SENTSINCE` use the parsed `Date` header of received mail and don't match appended messages. `BEFORE`, `ON`, `SINCE`, `OLDER`, and `YOUNGER` use the internal date, which is when Inbound received the message.
* `\Recent` is never set, so `RECENT` and `NEW` match nothing.
* Search keys the server doesn't implement are ignored instead of rejected, which can return more messages than requested. Filter results in your application when exact matching matters.

## New-message notifications

During `IDLE`, the server sends `EXISTS` as soon as new mail is synchronized into the selected folder. Outside `IDLE`, new messages are reported on the next command, such as `NOOP`. Active sessions are also refreshed about every 60 seconds, which catches messages that don't trigger an immediate notification, such as mail where the scoped address was a secondary envelope recipient.

An `IDLE` command ends after 30 minutes: the server sends `* BYE IDLE terminated` and closes the connection. Reissue `IDLE` before then (most clients restart it every 29 minutes) or reconnect automatically.

## Flags and read state

Writable credentials can set standard flags (`\Seen`, `\Answered`, `\Flagged`, `\Deleted`, `\Draft`) and keywords in writable folders. Fetching message content from a writable folder sets `\Seen` unless the client uses `BODY.PEEK`. Read-only credentials, `EXAMINE`, and scope folders never set `\Seen`. `STORE` without `.SILENT` returns the updated flags.

Flags set on a received message in `INBOX` also apply to the same message in the credential's scope folders. Flags on copies in other folders, such as a custom folder, are independent.

<Note>
  IMAP flags are separate from the dashboard's read state. Marking a message read in an email client does not mark it read in the dashboard, and the reverse is also true.
</Note>

## Known limitations

### Other sessions don't see changes immediately

Only new messages are pushed to other open sessions. If one session expunges, moves, or changes flags, other sessions on the same folder see the change only after they select the folder again. Clients that keep several connections open, or several devices using the same credential, can briefly show stale messages or flags.

### Received-message deletion and moves

<Warning>
  `EXPUNGE` and `MOVE` do not delete the underlying received email. `INBOX` and scope folders are rebuilt from received mail, so a received message expunged or moved out of `INBOX` reappears there, with a new UID, the next time the folder is synchronized (for example, on the next `SELECT` or when new mail arrives). Don't use IMAP deletion as permanent deletion.
</Warning>

Moving a received message into a custom folder, `Trash`, or `Junk` does create a copy there that stays until you expunge it. Messages created with `APPEND`, such as sent copies and drafts, are stored separately and are permanently removed when their last copy is expunged.

### Sent mail is not saved automatically

Sending through SMTP does not create a message in `Sent`. Many email clients save their own copy with `APPEND`, which needs a `read_write` mailbox credential.

<Warning>
  SMTP accepts messages up to 3 MiB, but `APPEND` accepts at most 1 MiB. A larger email can send successfully while saving its sent copy fails with `NO [TOOBIG]`. SMTP-only credentials cannot save a sent copy.
</Warning>

### Guard-filtered messages

Messages blocked by Guard are not synchronized, and their content cannot be fetched. If a message is blocked after it was already synchronized, it is removed from the credential's folders the next time the client lists or opens a folder. Email clients may still show content they cached earlier.

## Scope changes and revoked access

When a credential's scopes, permissions, sender settings, enabled state, or password change, its active IMAP sessions receive `* BYE Mailbox credentials or scopes changed` and must reconnect. On the next folder listing or selection, folders for removed scopes disappear, and received messages that no longer match any remaining scope are removed from all of the credential's folders. Appended messages are not affected.

Each login rechecks that the login email's domain is verified, that at least one scope domain is verified, and that an exact sender identity is still covered by a verified scope. If not, authentication fails.

<Note>
  A domain losing its verified status does not disconnect an established IMAP session. To end current access, disable the credential, change its scopes or permissions, rotate its password, or delete it.
</Note>

## Message and storage limits

| Limit | Value |
| - | - |
| Maximum `APPEND` size | 1 MiB (`1,048,576` bytes), advertised as `APPENDLIMIT` |
| Appended storage per account | 250 MiB |
| Appended messages per account | 5,000 |

An `APPEND` over 1 MiB is rejected with `NO [TOOBIG]`. The storage and message-count limits are shared by all of the account's credentials and folders; exceeding them returns `NO [OVERQUOTA]`. For SMTP limits, see [Send with SMTP](/docs/mailboxes/connect-smtp#limits).

## Connection limits and timeouts

| Limit | Value |
| - | - |
| TLS | Implicit TLS on port `993`, TLS 1.2 or later |
| Simultaneous connections per client IP address | 20 |
| Inactivity timeout before login | 60 seconds |
| Inactivity timeout after login | About 30 minutes |
| Maximum `IDLE` duration | 30 minutes |
| Failed logins | 10 per login address and IP address, and 50 per IP address, in a 15-minute window |

Connections over the per-IP limit receive `* BYE Too many connections from this address`. Once a login is throttled, attempts return `NO [AUTHENTICATIONFAILED]` until the window ends, even with the correct password. Authentication requests are also rate-limited by the API, so avoid reconnect loops and retry with backoff.

## Troubleshooting

| Symptom | Likely cause | What to check |
| - | - | - |
| Authentication fails | Wrong login, rotated password, disabled credential, SMTP-only credential, unverified domain, or login throttling | Confirm the login email, current password, credential type, enabled state, and verified domains. Wait 15 minutes after repeated failures. |
| An expected message is missing | Recipient is outside the scopes, the message is Guard-blocked, or the folder hasn't been refreshed | Check the recipient, scope domains, and Guard status, then reselect the folder |
| A scope folder rejects changes | `Scopes/*` folders are always read-only | Change the message in `INBOX` or copy it to a writable folder |
| A received message returns after deletion or moving | `INBOX` is rebuilt from received mail | Don't use IMAP deletion as permanent deletion |
| No sent copy appears | SMTP doesn't populate `Sent`, or the client's `APPEND` exceeded 1 MiB or the storage limit | Enable sent-copy saving in the client, use a `read_write` credential, and check message size |
| Another device shows stale flags or deleted messages | Other sessions only see changes after reselecting the folder | Reselect the folder or restart the client's sync |
| The connection closes after a credential edit | Credential changes end active sessions | Reconnect with the current password and permissions |

<CardGroup cols={2}>
  <Card title="Scopes and Permissions" icon="shield" href="/docs/mailboxes/scopes-and-permissions">
    Understand exact domain matching, sender policies, and read-only scope views.
  </Card>

  <Card title="Manage Credentials" icon="key" href="/docs/mailboxes/manage-credentials">
    Change access levels, replace scopes, rotate passwords, and disable credentials.
  </Card>
</CardGroup>
