Receiving
With the name's records set, an address under it accepts mail, keeps it, and routes it — to a webhook, a copy, a forward, or a hold. Receiving is never metered by volume and never rate-limited. A mailbox that is held or resting still receives and still keeps, and nothing already held is ever dropped.
Each accepted message is announced to your product as a signed webhook, so your side can verify who is speaking before it acts.
The sending ramp — published, automatic, the same for everyone
| Window | Per day, per name | Burst, per customer |
|---|---|---|
| Day 0–2 | 50 | 10 / min |
| Day 3–6 | 200 | 20 / min |
| Day 7–13 | 1,000 | 40 / min |
| Day 14+ | no daily cap | 60 / min |
Three conditions gate every step: the name is listening, dmarc is published with a policy other than none, and receiver refusals stay under 2% of attempts in the trailing 24 hours. Failing one holds position rather than dropping it, and when the ramp pauses you are told which receivers refused and what they checked.
The exit is a feature
Export everything held — with records set, with a record broken, even unverified. You are the name's registrant, and everything held under the name can leave any day.
Claims we refuse to make
Nobody can promise the inbox. We promise alignment, hygiene, watchfulness — and the evidence. Accepted means our own queue took the message for delivery; nothing past our edge is ours to guarantee.
We publish no uptime figure. There is no operating history to measure one from, so the incident record is what we publish instead.
We will not build a webmail client, and nothing currently foreseen pulls IMAP forward — reading bodies is a never, and we are the layer under the client, not the client.
Not yet listening: JMAP, SMTP submission, CalDAV and CardDAV. Each is named as absent, with no date and no implied one.
Start with a docket
One request opens the conversation; one business day is what we publish for review. Bring the name you own and the product that needs mail under it.