Inbound
More ways to use this page
Read a received message
GET/v1/
TypeScript sendora
Python sendora
Key sk_… a server key
The message with its envelope, parties, headers, text, HTML and attachment descriptors; the attachment bytes and the raw message are downloads of their own. Once the stream’s content window has passed, the content fields are null and contentAvailable is false.
Parameters
idin pathstring (uuid)requiredThe inbound message id.
Responses
200The received message with everything but the attachment bytes.
inboundMessageIdstring (uuid)requiredstreamIdstring (uuid)requiredThe inbound stream that received it.
receivedAtstring (date-time)requiredWhen the message was accepted from the sending server.
envelopeRecipientstringrequiredThe address of yours the message was sent to.
mailboxHashstring or nullrequiredThe text after the plus sign in that address, when the sender used one.
sizeBytesintegerrequiredattachmentCountintegerrequiredhasTextbooleanrequiredhasHtmlbooleanrequiredparseIssuestring or nullrequiredWhat the parser met; null when the message parsed clean. A hard issue empties the parsed parts, and the raw message stays:
no_headers,header_block_too_large,too_many_headers,too_many_parts,nesting_too_deep,missing_boundary,decoded_too_large,parse_timeout,parser_error. A soft issue keeps them and says what was changed or dropped:truncated_multipart,too_many_attachments,unknown_transfer_encoding,undecodable_container,filename_sanitised,control_chars_stripped,multiple_from,duplicate_header,malformed_header_dropped,address_list_truncated,header_value_truncated. A message with several names the hard one, or the first soft one in this order.authenticationobjectrequiredWhat Sendora found when it checked the message; unchecked until the checks have run.
spf"pass" | "fail" | "softfail" | "neutral" | "none" | "temperror" | "permerror" | "unchecked"requiredSPF for the address in MAIL FROM.
spfHelo"pass" | "fail" | "softfail" | "neutral" | "none" | "temperror" | "permerror" | "unchecked"requiredSPF for the name the sending server gave in HELO.
dkim"pass" | "fail" | "none" | "temperror" | "permerror" | "unchecked"requireddmarc"pass" | "fail" | "none" | "temperror" | "permerror" | "unchecked"requireddmarcPolicy"none" | "quarantine" | "reject" or nullrequiredWhat the sender’s domain asks for; told only when DMARC failed.
arc"none" | "pass" | "fail" | "unchecked"requiredcheckedAtstring (date-time) or nullrequiredWhen the checks ran; null until they have.
contentAvailablebooleanrequiredFalse once the stream’s content window has passed; only the reference remains.
contentExpiresAtstring (date-time)requiredWhen the content goes.
fromobject or nullrequiredThe From header; null without it or once the content is gone.
addressstringrequirednamestring or nullrequired
subjectstring or nullrequireddatestring (date-time) or nullrequiredThe sender’s Date header as ISO 8601, when it was a real moment.
envelopeobject or nullrequiredNull once the content is gone.
senderstring or nullrequiredThe MAIL FROM address; null for a bounce.
replyToarray of objectrequiredaddressstringrequirednamestring or nullrequired
toarray of objectrequiredUp to 100 entries; toCount is the whole number.
addressstringrequirednamestring or nullrequired
toCountintegerrequiredccarray of objectrequiredUp to 100 entries; ccCount is the whole number.
addressstringrequirednamestring or nullrequired
ccCountintegerrequiredmessageIdHeaderstring or nullrequiredinReplyTostring or nullrequiredreferencesarray of stringrequiredheadersarray of object or nullrequiredEvery header in order; null once the content is gone.
namestringrequiredvaluestringrequired
textstring or nullrequiredThe plain-text body; null without one or once the content is gone.
htmlstring or nullrequiredThe HTML body as received; null without one or once the content is gone.
attachmentsarray of objectrequiredattachmentIdstring (uuid)requiredpositionintegerrequiredIts place among the message’s attachments, from 0.
namestring or nullrequiredThe filename, sanitised; null once the content is gone.
contentTypestring or nullrequiredThe type the sender declared; every download is served as application/octet-stream.
contentIdstring or nullrequiredThe Content-ID an HTML body refers to with cid:.
sizeintegerrequiredBytes.
inlinebooleanrequiredTrue for a part shown in the body rather than offered as a file.
Example (68 lines)
{
"inboundMessageId": "4d1f8b2e-9c3a-4e7b-8f21-6a5d0c9e7b31",
"streamId": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"receivedAt": "2026-09-19T08:00:02.000Z",
"envelopeRecipient": "7c9e6679742540de944be07fc1f90ae7@inbound.sendora.se",
"mailboxHash": null,
"sizeBytes": 48213,
"attachmentCount": 1,
"hasText": true,
"hasHtml": false,
"parseIssue": null,
"authentication": {
"spf": "pass",
"spfHelo": "pass",
"dkim": "pass",
"dmarc": "pass",
"dmarcPolicy": null,
"arc": "none",
"checkedAt": "2026-09-19T08:00:03.000Z"
},
"contentAvailable": true,
"contentExpiresAt": "2026-10-19T08:00:02.000Z",
"from": {
"address": "anna@example.com",
"name": "Anna Andersson"
},
"subject": "A question about my order",
"date": "2026-09-19T08:00:00.000Z",
"envelope": {
"sender": "anna@example.com"
},
"replyTo": [],
"to": [
{
"address": "7c9e6679742540de944be07fc1f90ae7@inbound.sendora.se",
"name": null
}
],
"toCount": 1,
"cc": [],
"ccCount": 0,
"messageIdHeader": "<question-1@example.com>",
"inReplyTo": null,
"references": [],
"headers": [
{
"name": "From",
"value": "Anna Andersson <anna@example.com>"
},
{
"name": "Subject",
"value": "A question about my order"
}
],
"text": "Hi!\n",
"html": null,
"attachments": [
{
"attachmentId": "9b7e2c41-3f6d-4a8e-b2c5-1d0f7e6a9c58",
"position": 0,
"name": "invoice.pdf",
"contentType": "application/pdf",
"contentId": null,
"size": 46102,
"inline": false
}
]
}Errors
Every error answers error, the code, and message, a sentence for a person. A code that adds fields is shown in full below the table.
| Code | Status | Meaning |
|---|---|---|
unauthorized | 401 | The key is missing, malformed or revoked. |
wrong_ | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
not_ | 404 | No such inbound message of this server. |
content_ | 409 | The stored content of this received message cannot be opened. Sendora has been told. |