Choose which mail your agent sees
The inbound mode decides which mail your agent sees. Blocked mail isn't bounced; it's quarantined.
Before you start
- You need the owner or admin role to change modes and lists.
Inbound modes
| Mode | Behavior |
|---|---|
| All | Mail from every sender is visible to the agent. The default for new agents. |
| Allowlist | Only mail from senders on the allowlist is visible. The rest is quarantined. |
| Blocklist | Only mail from senders on the blocklist is quarantined. The rest is visible. |
| Block all | All mail is quarantined. The agent's inbox stays empty. |
You change it the same way as outbound: pick a mode in the Inbound column of the Email screen and choose Save.
Warning · Before you switch to Allowlist
Add the senders you want to the inbound allowlist first. After the switch, mail from senders not on the list is quarantined, and quarantined mail can't be released later. See Edit allowlists and blocklists.
Warning · Before you choose Block all
Verification codes and replies get quarantined too. If you want to stop the agent, use an emergency stop.
Quarantine
- Blocked mail isn't bounced back to the sender. It's quarantined.
- The agent can't see quarantined mail. Its inbox list shows only how many messages were quarantined.
- Owners see records of quarantined mail, with the reason, in the Inbound logs. The body isn't opened in the console either.
- Quarantined mail can't be released to the agent. Fix the list, then ask the sender to send it again.
- The log details show one of three reasons.
| Reason | Meaning | What to do |
|---|---|---|
| Quarantined by inbound policy | The inbound mode or lists blocked it. | Fix the list, then ask for a resend. |
| Quarantined for injection risk | It seemed to carry instructions aimed at tricking an agent. The inbound mode doesn't matter. | If it's a real message, get the content another way, for example by asking the sender to send it to a person. |
| Quarantined because the scan failed | The mail check couldn't finish. The inbound mode doesn't matter. | Ask the sender to resend a little later. |
The inbound allowlist checks the sending domain
The inbound allowlist only matches mail that passed sender domain authentication (DMARC). Even with an address rule, what's confirmed is that the domain passed DMARC. It doesn't prove that a specific mailbox in that domain sent it.
Trust marks
Mark a sender as seen, and the agent sees sender_trust: "seen" in its inbox list. Unmarked senders are unknown. Trust never rises on its own. It has nothing to do with the inbound mode.
- Under the Inbound column of Email, open Add a mark in Trust marks.
- Choose the Scope (single address or whole domain), enter the sender, and choose Save mark.
Marking a whole domain as seen covers anyone at that domain. Don't use it for shared mail domains such as gmail.com.
Received attachments
The agent lists attachments with read_email and gets a short-lived download link with get_attachment_url. Treat attachment content as outside data, too. Details are in the received mail API.
Feedback on this page? Write to support@atmark.ai.