What EmailConnect does, stated exactly, with the plan each feature needs. The last section lists what it does not do. Last checked against the application on 6 October 2026.
EmailConnect receives email on your domain, turns each message into JSON and posts it to your HTTP endpoint. It is hosted in the EU and keeps what it stores for a short, fixed time. Plans are Free, Maker, Business and Platform; see pricing.
Receiving
| Feature | What it does | Plan |
|---|
| Custom domains | Point your MX records at us and verify the domain by DNS. A catch-all alias or specific addresses route to webhooks. | All plans |
| Shared system domain | Addresses on our own domain, for testing or when you have no domain to spare. | All plans |
| Plus-addressing | name+tag@ is delivered with the tag as its own field in the payload. | All plans |
| Duplicate protection on intake | A message our mail server hands over twice is processed once. | All plans |
| Maximum email size | 10 MB for the whole message, attachments included. Larger mail is refused during the SMTP conversation, so the sender gets the error. | All plans |
Processing
| Feature | What it does | Plan |
|---|
| Parsed message | Sender, recipients, subject, date, text and HTML bodies, headers, as JSON. | All plans |
| Classification | bounce, auto-reply, mailing-list, read-receipt or normal, decided from RFC headers with no machine learning. Comes with a confidence and the headers behind the verdict. | All plans |
| Per-field payload toggles | Switch HTML, text, extracted links, envelope data and attachments on or off per alias. | All plans |
| Link extraction | Every link in the message as its own list. Free gets the URL and domain; Maker and above also get the anchor text and where the link was found. | All plans; full detail Maker+ |
| Spam score | The rspamd score and the symbols that produced it. We report the score, not a spam verdict: you choose the threshold. | Maker+ |
| SPF, DKIM and DMARC results | The authentication results for the message, in the payload. | Maker+ |
| Markdown body | The HTML body converted to Markdown, for feeding language models. Off by default, enabled per alias. | Maker+ |
| Reply parsing | The new text of a reply, with quoted history removed. | Maker+ |
| Integrity hashes | SHA-256 of the content and of the raw message. | Maker+ |
| Attachment metadata | File hash, image dimensions, PDF page count. | Maker+ |
| Custom payload template | Reshape the JSON we send with a template of your own. | Business+ |
| Virus scanning | Attachments scanned with ClamAV; infected files are withheld and marked. Must be switched on in settings. | Business+ |
Attachments
| Feature | What it does | Plan |
|---|
| Inline delivery | Text, document and image files up to 2 MB arrive base64-encoded in the payload (up to 128 KB on Free). | All plans |
| Storage delivery | Larger files, and types that cannot be inlined such as archives and media, are stored in EU object storage and arrive as a download URL. The URL works for as long as the email is retained. | Maker+ |
| Your own storage | Send stored attachments to your own S3-compatible bucket instead of ours. | Business+ |
| Size limit per attachment | 128 KB on Free. On paid plans a setting of your own, 10 MB by default. | All plans |
| Count limit | 20 attachments per email are processed. Any beyond that are listed in the payload as excluded, without their content. | All plans |
| Nothing disappears silently | A file we do not deliver still appears in the payload, with excluded: true and the reason. | All plans |
Rules
| Feature | What it does | Plan |
|---|
| Allow and block rules per alias | Conditions on sender address, sender domain, spam score, and whether or which attachments are present. Up to 10 conditions joined with AND or OR, evaluated left to right. | Maker+ |
| Sender notification on block | Optionally tell the sender their message was not accepted. | Maker+ |
| Undecidable rules deliver | If a rule cannot be evaluated, for example a spam condition on a message that was never scored, the email is delivered. We do not discard mail on evidence we do not have. | Maker+ |
Delivery
| Feature | What it does | Plan |
|---|
| HTTPS POST to your endpoint | JSON body, 30-second timeout. | All plans |
| Automatic retries | Up to 6 attempts when your endpoint answers 5xx or does not answer, at roughly 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours. Retries stop early if the email reaches the end of its retention window. | All plans |
| No retry on 4xx or redirects | A 4xx is treated as your endpoint refusing the request. A redirect is not followed. Both are recorded as failed, with the reason. | All plans |
| Signed webhooks | Standard Webhooks signatures (webhook-id, webhook-timestamp, webhook-signature), verifiable with any Standard Webhooks library. | Maker+ |
| Deduplication key | On signed webhooks, webhook-id is the same on every retry and replay of an email. | Maker+ |
| Custom headers | Add your own headers to every delivery, including Authorization. Stored encrypted. | Maker+ |
| Delivery log | Every email with its status, attempts, response code and the reason for a failure or rejection. | All plans |
| Manual replay | Re-send any delivered or failed email from the log or through the API, for as long as it is retained. | All plans |
| Destination checks | Webhook URLs are checked against private and internal addresses when configured and again at each delivery. | All plans |
Data handling
| Feature | What it does | Plan |
|---|
| Retention | Stored email data is deleted automatically: after 1 hour on Free and Maker; after 24 hours by default on Business (configurable up to 30 days) and Platform (up to 365 days). | All plans |
| Delete on demand | Delete an email through the API as soon as your workflow has finished with it. | Business+ |
| Data residency mode | The message body and attachments are never written to our database; only routing metadata is. | Platform |
| Hosting | Application, database and mail server at Hetzner in Germany; object storage and platform email at Scaleway in France. | All plans |
| Data Processing Agreement | Public to read in full; your own copy is generated and downloadable from your account. | All plans |
API and access
| Feature | What it does | Plan |
|---|
| REST API | Manage domains, aliases, webhooks, rules and settings; read logs; replay deliveries. | All plans |
| Scoped API keys | Each key carries only the permissions you give it. | All plans |
| API rate limit | 60 requests per hour on Free, 600 on Maker, 3,000 on Business, unlimited on Platform. | All plans |
| n8n node | A community node for n8n, with a trigger for incoming email. | All plans |
| Sign-in | Email link, password, passkeys, or GitHub and Google. | All plans |
Limits per plan
| Free | Maker | Business | Platform |
|---|
| Emails per month | 100 | 1,500 | 10,000 | 100,000 |
| Domains | 1 | 1 | 3 | Unlimited |
| Aliases | 3 | 5 | 25 | 100 |
| Webhooks | 3 | 5 | 25 | 100 |
| Storage connections | 0 | 1 | 3 | Unlimited |
| Longest retention | 1 hour | 1 hour | 30 days | 365 days |
What EmailConnect does not do
Stated as plainly as the features, so that nobody has to find out after signing up.
| Not built | What that means |
|---|
| Sending email | EmailConnect receives. It does not send mail on your behalf, and there is no outbound API. |
| Mailboxes | No inbox to log in to, no IMAP or POP, no long-term message store. Mail passes through to your webhook. |
| Redaction or DLP | We do not detect or remove personal data from message content. Spam scoring is not data-loss prevention. |
| Pay-as-you-go billing | Plans have a monthly allowance. Paid plans can buy credits for volume above it; that is not metered per-email billing. |
| ISO 27001 or SOC 2 certification | We hold neither. What we offer is a Data Processing Agreement, EU hosting and a published sub-processor list. |
| Uptime guarantee (SLA) | We publish our status and monitor around the clock, but we do not offer a contractual uptime commitment. |
| IP allowlisting | There is no IP-based restriction, for the dashboard, the API or webhook delivery. |
| Rules on SPF, DKIM or DMARC | The results are in the payload on Maker and above. You cannot yet write a rule that filters on them. |
| Bulk replay | Replay is per email. There is no single call to replay everything that failed in a time range. |
| Official SDKs | There is a REST API and an n8n node. No language SDKs. |
| Threading | Emails are delivered one by one. We do not group them into conversations. |
Where the detail is