Webhook Payload
Each inbound email is sent as compact JSON. String fields that are empty are omitted; arrays are always present.
{
"type": "Inbound",
"logicalAccount": "50025f6a-d4fd-4a23-9e2e-bbee1cf67d2b",
"fromName": "Jane Doe",
"cc": [],
"bcc": [],
"subject": "Order #1234",
"date": "Thu, 08 Oct 2026 11:41:07 +0200",
"textBody": "Hello…",
"htmlBody": "<p>Hello…</p>",
"headers": [
{ "Name": "X-Mailer", "Value": "Example" },
{ "Name": "X-CM-Raw-Rfc822-Url", "Value": "https://…" }
],
"attachments": [
{ "name": "invoice.pdf", "contentType": "application/pdf", "inline": false, "content": "JVBERi0xLjQK…" }
]
}
Fields that surprise integrators
dateis the rawDateheader, not ISO 8601.messageId,inReplyToandreferencesare as received (often with angle brackets). Use thecm-message-idheader for the canonical form.tois the rawToheader.originalRecipientis the envelope recipient that matched your domain. Route on this one.headersuse PascalCaseNameandValue, unlike the rest of the payload.- Fields the pipeline does not model are not forwarded.
Attachments
Attachment fields:
| Field | Description |
|---|---|
name | File name as sent by the sender. Treat as untrusted. |
contentType | Declared media type. |
inline | true for inline images referenced by cid:. |
contentId | Content-ID, for matching cid: references in htmlBody. |
content | Base64 file bytes. Inline mode only. |
url | Download link. Download-link mode only. |
urlExpiresAt | ISO 8601 expiry of url. |
There is no size field.
- Inline (default). Each attachment carries
content.contentis omitted when the file could not be included: it was never stored, was not found, or did not fit the payload size budget. The attachment is still listed with its metadata. - Download links. Every attachment carries
urlandurlExpiresAtinstead ofcontent, regardless of size, so you never have to branch per attachment. Links expire after the webhook'spresignedUrlExpiryHours(default 24, at most 168). Download the files before they expire.
Payload size
The whole JSON body is capped at 30 MB. Inline attachments are base64, so they add about a third to their file size. Attachments are included in order while they fit; those that do not are sent without content. If the finished body still exceeds the cap, no webhook call is made for that message. It stays stored and visible in the Email App and is held for replay by CM.com.
Use download links if you expect large attachments.
Field limits
Fields are bounded before delivery. When a field is cut, the message still delivers.
| Field | Limit | When exceeded |
|---|---|---|
subject | 2,000 characters | Truncated |
fromName | 500 characters | Truncated |
from | 320 characters | Dropped |
to | 8,000 characters | Cut at an address boundary |
cc, bcc | 100 addresses of 320 characters each | Truncated |
messageId, inReplyTo, each references entry | 512 characters | Truncated, keeping the angle brackets |
references | 500 entries | Newest 500 kept |
headers | 200 entries; names 256 and values 8,000 characters | Extra entries dropped, long text truncated |
attachment name | 255 characters | Truncated |
textBody | 2 MiB | Dropped; HTML and metadata still deliver |
htmlBody | 2 MiB | Dropped; text and metadata still deliver |
HTML sanitisation
htmlBody is sanitised once, and the stored copy and the webhook copy are identical. Never render it outside a sandboxed frame on a separate origin with a restrictive Content-Security-Policy.
| Aspect | Rule |
|---|---|
| Tags | Allow-list suited to table-based mail (a, table, img, div, span, blockquote, headings, lists, …). Everything else, including script, style, link, iframe, form and svg, is removed with its content. |
| Attributes | Allow-list (for example href, src, alt, style, width, height, align, bgcolor). class, id and type are kept, so reply and forward boundaries such as gmail_quote or <blockquote type="cite"> stay detectable. Event handlers such as onclick are removed. |
| CSS | Property allow-list (colour, border, font, margin, padding, width/height, text, …). At-rules are removed. |
| URL schemes | http, https, mailto, tel, cid. javascript:, vbscript: and data: are removed. |
cid: | Kept only if an attachment with that Content-ID exists. |
| Remote images | Left intact. |
| Control characters | NUL stripped from bodies; NUL, CR and LF stripped from single-line fields (subject, from, headers, …). |