InboxDays

Email Account Settings

Security & MFA · Jump to passkeys, security keys, and authenticator apps

HomeLegalDelete rulesAuto-forward

Configure accounts, select one or more from the checklist, then run bulk actions.

Configured accounts: 0

    Contact address book routing

    When InboxDays extracts a signature contact from incoming mail, choose where confirmed contacts are saved. Re-auth connected mailboxes after enabling Contacts scopes if sync fails.

    Security & MFA

    Protect your InboxDays login with a passkey, a hardware security key, or an authenticator app. Credentials are stored by your device / Keycloak — InboxDays never sees biometrics or TOTP secrets.

    Passkey (passwordless)

    Sign in with Touch ID, Face ID, Windows Hello, or a FIDO2 key — no password step.

    Security key (2FA)

    After password, Keycloak will ask for this WebAuthn key when you sign in.

    Authenticator app (TOTP)

    Use Google Authenticator, 1Password, Authy, or similar for a 6-digit code after password.

    Manage registered credentials
    • Enrollment opens Keycloak (kc_action). Stay on the same browser profile that holds your InboxDays session.
    • Use Manage registered credentials to rename or remove keys / OTP devices.
    • After enrollment, sign out once and sign back in to confirm MFA or passkey login works.

    Spam & phishing rules

    Explicit allow/block overrides for senders and domains. Marking Spam / Not Spam in the reader also logs a training event and updates these rules automatically.

    Blocked

    No blocked senders or domains.

    Allowed

    No allowed senders or domains.

    Auto-forward invoices

    Match invoices or receipts and InboxDays forwards a copy (with attachments) to your accountant. Each send is logged, and you can email yourself a receipt so you know it happened.

    Manage auto-forward rules

    Rolling auto-archive

    Each day around 02:00 UTC, InboxDays removes eligible mail from your Inbox (Gmail: drop INBOX label · Microsoft: move to Archive · IMAP: move to Archive). Age is evaluated live as now − threshold. Important / starred, WORM-locked, and optionally unread messages are skipped. This is not WORM Vault (immutable S3) and not Vault encrypted send.

    Loading…

    WORM Vault & retention policies

    Long-term compliance archive with AWS S3 Object Lock (COMPLIANCE). This is separate from Important (star in the mailbox) and from tag TTL “retention” under Tags. Retrieve locked copies below, or open Important in the sidebar to find starred mail still in your provider inbox.

    Policies

    Loading policies…

      Locked emails (audit log)

      Download the immutable .eml copy from the WORM vault. Glacier Instant Retrieval applies after 90 days; Object Lock still allows immediate reads.

      No emails locked yet. Open a message → shield action → Retain in WORM Vault.

      Billing

      Manage your InboxDays plan. Upgrades open the Paddle checkout; cancellations use the customer portal when available. See the cancellation policy.

      Loading plan…

      About this build

      Confirm which API image and web UX build are currently deployed.