Skip to main content
Upload a file, get an attachment ID, and reference it when sending. Inbound attachments are scanned for threats and downloadable through temporary signed URLs.

Upload an attachment

Upload a file for later use when sending emails. Files are sent as base64-encoded content.

Parameters

Response

Limits

  • Max file size: 10 MB per attachment (after base64 encoding)
  • Max per email: 40 MB total across all attachments
  • Storage quota: Varies by plan tier

Send with attachments

After uploading, reference the attachment_id in your send call:
Multiple attachments are supported — pass an array of IDs.

Get attachment metadata

Retrieve metadata for an attachment (from sent or received emails).

Response


Get download URL

Generate a temporary signed URL to download an attachment.

Parameters

Response


Inbound attachments

When emails arrive with attachments, they’re automatically stored and included in the webhook payload:
Your agent can then download each attachment using the get_attachment_url endpoint.

Attachment scanning

All inbound attachments are automatically scanned for threats:
  • ClamAV antivirus (when configured) — checks against virus signature database
  • Heuristic scanning — detects suspicious file types, double extensions, and known threat hashes
  • Quarantine — flagged attachments are quarantined and not delivered to your webhook
This happens transparently — your agent only receives safe attachments.

Storage types

The storage type is chosen automatically based on file size and configuration. Your code doesn’t need to handle the difference — the download URL endpoint works for both.

What’s next?

Messages

Send emails with attachments and full message reference.

Webhooks

Receive inbound attachments in your webhook payload.

Security Overview

Learn how attachments are scanned for malware before delivery.

Data Deletion

GDPR-compliant deletion of messages and attachments.
Last modified on March 19, 2026