Skip to main content

Webhook Payload

Each inbound email is sent as compact JSON. String fields that are empty are omitted; arrays are always present.

{
"type": "Inbound",
"logicalAccount": "50025f6a-d4fd-4a23-9e2e-bbee1cf67d2b",
"from": "[email protected]",
"fromName": "Jane Doe",
"originalRecipient": "[email protected]",
"cc": [],
"bcc": [],
"subject": "Order #1234",
"date": "Thu, 08 Oct 2026 11:41:07 +0200",
"messageId": "<[email protected]>",
"inReplyTo": "<[email protected]>",
"references": ["<[email protected]>"],
"textBody": "Hello…",
"htmlBody": "<p>Hello…</p>",
"headers": [
{ "Name": "X-Mailer", "Value": "Example" },
{ "Name": "X-CM-Raw-Rfc822-Url", "Value": "https://…" }
],
"attachments": [
{ "name": "invoice.pdf", "contentType": "application/pdf", "inline": false, "content": "JVBERi0xLjQK…" }
]
}

Fields that surprise integrators​

  • date is the raw Date header, not ISO 8601.
  • messageId, inReplyTo and references are as received (often with angle brackets). Use the cm-message-id header for the canonical form.
  • to is the raw To header. originalRecipient is the envelope recipient that matched your domain. Route on this one.
  • headers use PascalCase Name and Value, unlike the rest of the payload.
  • Fields the pipeline does not model are not forwarded.

Attachments​

Attachment fields:

FieldDescription
nameFile name as sent by the sender. Treat as untrusted.
contentTypeDeclared media type.
inlinetrue for inline images referenced by cid:.
contentIdContent-ID, for matching cid: references in htmlBody.
contentBase64 file bytes. Inline mode only.
urlDownload link. Download-link mode only.
urlExpiresAtISO 8601 expiry of url.

There is no size field.

  • Inline (default). Each attachment carries content. content is omitted when the file could not be included: it was never stored, was not found, or did not fit the payload size budget. The attachment is still listed with its metadata.
  • Download links. Every attachment carries url and urlExpiresAt instead of content, regardless of size, so you never have to branch per attachment. Links expire after the webhook's presignedUrlExpiryHours (default 24, at most 168). Download the files before they expire.

Payload size​

The whole JSON body is capped at 30 MB. Inline attachments are base64, so they add about a third to their file size. Attachments are included in order while they fit; those that do not are sent without content. If the finished body still exceeds the cap, no webhook call is made for that message. It stays stored and visible in the Email App and is held for replay by CM.com.

Use download links if you expect large attachments.

Field limits​

Fields are bounded before delivery. When a field is cut, the message still delivers.

FieldLimitWhen exceeded
subject2,000 charactersTruncated
fromName500 charactersTruncated
from320 charactersDropped
to8,000 charactersCut at an address boundary
cc, bcc100 addresses of 320 characters eachTruncated
messageId, inReplyTo, each references entry512 charactersTruncated, keeping the angle brackets
references500 entriesNewest 500 kept
headers200 entries; names 256 and values 8,000 charactersExtra entries dropped, long text truncated
attachment name255 charactersTruncated
textBody2 MiBDropped; HTML and metadata still deliver
htmlBody2 MiBDropped; text and metadata still deliver

HTML sanitisation​

htmlBody is sanitised once, and the stored copy and the webhook copy are identical. Never render it outside a sandboxed frame on a separate origin with a restrictive Content-Security-Policy.

AspectRule
TagsAllow-list suited to table-based mail (a, table, img, div, span, blockquote, headings, lists, …). Everything else, including script, style, link, iframe, form and svg, is removed with its content.
AttributesAllow-list (for example href, src, alt, style, width, height, align, bgcolor). class, id and type are kept, so reply and forward boundaries such as gmail_quote or <blockquote type="cite"> stay detectable. Event handlers such as onclick are removed.
CSSProperty allow-list (colour, border, font, margin, padding, width/height, text, …). At-rules are removed.
URL schemeshttp, https, mailto, tel, cid. javascript:, vbscript: and data: are removed.
cid:Kept only if an attachment with that Content-ID exists.
Remote imagesLeft intact.
Control charactersNUL stripped from bodies; NUL, CR and LF stripped from single-line fields (subject, from, headers, …).