Inbound
The inbox your agent reads safely.
Every message that arrives is judged before your agent reads it: if it carries instructions written for the machine, the event says so — and the mailbox can hold it until a person releases it. Signed webhook, Telegram, Slack or forwarding, with a record of everything.
Inbound included on every plan · Received messages do not count against the sending quota
01 · Three steps
Get started in three steps.
Point the MX and create the mailbox
Under Domains, turn on inbound for the domain: the wizard shows the MX record to publish and checks it live. Then create the mailboxes — named addresses (agent@, invoices@) or a catch-all. An address that does not exist is refused at the door.
Choose where it goes
Signed webhook, Telegram, Slack or forwarding to another address — one mailbox delivers to as many channels as you want. A webhook is only saved after your endpoint answers the challenge:
{
"type": "url_verification",
"challenge": "Zk3qP0…",
"url": "https://agent.yourdomain.com/hook",
"sentAt": "2026-10-08T14:00:00.000Z"
}
← your endpoint answers 200 with
Zk3qP0… or {"challenge":"Zk3qP0…"}
Choose what the verdict does
In the safety block of each mailbox: «Notifies only» delivers with the verdict attached; «Holds» keeps the dangerous message without firing the channels and sends the notice at once.
"quarantine": {
"reason": "agent_safety_dangerous",
"agentSafety": { "verdict": "dangerous", "score": 65 },
"release": {
"panel": "https://app.oveyon.com/app/recepcao/entregas"
}
}
02 · The five levels
The five levels you would have to build yourself, ready here.
What others tell your agent to build on its own is switched on here, per mailbox, in production.
Allowlist
On your ownKeep the list of who may write to the agent and discard the rest before it reads — in your code, mailbox by mailbox.
HereAllow and block lists on inbound — by address, by domain or by
*.domain, for the whole account or for one domain —, applied at the door, before acceptance. Whoever is left out shows under Messages → Refused at the door. Under Protection → Rules, or throughPOST /v1/policies.Domains and authentication
On your ownCheck SPF, DKIM and DMARC on every message and decide what to do with whoever fails.
HereSPF, DKIM and DMARC checked on every message, and the result travels in the event (
authentication). A mailbox policy acts on it — «DMARC is fail → hold» —, and the sender can be matched by domain (*@supplier.example).Content filter
On your ownScan the body for hidden instructions, invisible characters, homoglyphs and malicious links — and keep the scan up to date.
HereThe safety verdict on every message: text hidden from humans in imperative mood, the Unicode Tags block, direction overrides, mixed scripts in one word, a link on a threat list — with a 0–100 score and the signals in plain language, next to the spam score. Policies read the body, the subject and the attachments’ names and types.
Holding area
On your ownA place where a suspicious message waits without reaching the agent, with a notice and a way to release it.
HereThe «Holds» switch of each mailbox: the dangerous message is accepted (the sender sees 250), archived and recorded, but the channels do not fire — and the
inbound.quarantinednotice arrives at once. Policies also hold or mute, with a simulator that says what each rule would do before it applies.Human in the loop
On your ownAn approval queue, the notice to the right person and a record of who decided what.
HereA person releases the held message under Inbound → Deliveries or through
POST /v1/inbound/{uid}/release; on the way out,"hold": truewaits for approval under Messages → Approvals. The notice goes by webhook, Telegram or Slack, and every decision goes into the trail — with who and when.
03 · Where it goes
The notice in the right place, and the proof it arrived.
Signed webhook
HMAC-SHA256 with a timestamp on every POST, a challenge before the URL is saved, retries and an eventId to deduplicate. Three modes: summary, full, full with attachments.
Telegram, Slack and email
One mailbox delivers to as many channels as you want, at the same time. A held message sends a notice without the body: we never hold without telling you.
The trail you see
Who released, who approved, who changed the policy — including our support. Under Account → History, never purged.
Point your MX today. The verdict comes with it.
Inbound included on every plan, the free one too. Received messages do not count against the sending quota and stay readable by API for 30 days.