Skip to main content
Inbound emails are spam-scored before reaching your agent. Outbound emails pass content validation before sending. Both directions are handled automatically.

Inbound: spam scoring

Every inbound email is analyzed with SpamAssassin-compatible scoring before it reaches your agent.

What’s checked

  • Header analysis — forged headers, missing fields, suspicious routing
  • Content patterns — known spam phrases, excessive capitalization, link density
  • Sender reputation — blacklist checks, domain age, authentication results
  • HTML analysis — hidden text, suspicious scripts, deceptive formatting

Spam score in webhook

The spam analysis is included in every webhook payload and message metadata:

Score thresholds

Using spam data in your agent

Outbound: content validation

Before any email leaves Commune, it passes through content validation that checks for patterns commonly associated with spam and phishing.

What’s checked

  • Phishing patterns — deceptive links, urgency language, credential requests
  • Spam content — excessive promotional language, misleading subjects
  • Link analysis — suspicious URLs, redirect chains
  • Sender consistency — From address matches inbox configuration

Blocked content

Emails that fail content validation are rejected with a 400 error before they’re sent. This protects your sender reputation by ensuring your agent never sends emails that could be flagged as spam by recipients.

Email validation

Before sending, every recipient address is validated:

Validation in send response

Your agent can use validation.rejected to know which recipients were skipped and validation.warnings to flag potentially unreliable addresses.

Suppression lists

Commune automatically maintains per-inbox suppression lists:
  • Hard bounces → immediately and permanently suppressed
  • Soft bounces → suppressed after 3 consecutive failures (expires after 7 days)
  • Complaints → permanently suppressed when a recipient marks email as spam
  • Unsubscribes → permanently suppressed
Sending to a suppressed address is silently skipped — your agent receives a validation.suppressed entry in the response rather than a send error. See Delivery Monitoring for the suppressions API.

What’s next?

Prompt Injection Detection

AI-specific threat detection for inbound emails targeting your agent.

Delivery Monitoring

Track bounce rates, complaint rates, and suppression lists.

Rate Limits

Burst detection, warmup gates, and sending health gates.

Email Authentication

DKIM, SPF, and DMARC authentication for your domain.
Last modified on March 19, 2026