Spam & security
Every incoming message is checked before it reaches your inbox — sender authentication, spam scoring, and virus scanning all run automatically. Here’s what those checks mean for you.
Sender authentication
Section titled “Sender authentication”Knobs verifies each message against the standard email authentication checks (SPF, DKIM, and DMARC — the mechanisms that prove a message really came from the domain it claims). When a message fails these checks, you’ll see a warning banner above the message body so you can treat it with appropriate suspicion.
Spam filtering
Section titled “Spam filtering”Messages that score as spam are routed to the Spam folder instead of your inbox. The filter is deterministic — it combines the authentication results above with signals like mailing-list headers, so the same message is always treated the same way.
If something legitimate lands in Spam, open the Spam folder to read it — the warning banner explains why it was flagged.
Virus protection
Section titled “Virus protection”Attachments are scanned on arrival. Messages that fail the virus scan are quarantined and never reach your inbox.
Mail to addresses that don’t exist
Section titled “Mail to addresses that don’t exist”When someone mails an address on your domain that doesn’t exist (a typo, or a person who left), Knobs doesn’t silently eat the message:
- The sender gets a standard bounce (“address not found”) — but only when their mail passed authentication, so forged senders can’t use your domain to spray bounces at victims.
- The message itself is shelved for 30 days and listed in an admin-only Undelivered view under Settings → Domains.
Recover an undelivered message (admins)
Section titled “Recover an undelivered message (admins)”- Open Settings → Domains and find the Undelivered section.
- Review the shelved message — sender, intended recipient, and why it wasn’t delivered.
- Either create the address (as a mailbox or alias) and re-deliver, or deliver it anyway to an existing mailbox.
This is how you rescue mail sent to jhon@ instead of john@ without asking the sender to
resend.
How message bodies are displayed
Section titled “How message bodies are displayed”Formatted (HTML) messages keep the layout, spacing, and colors their sender set on the message itself. What never survives is anything that could act on your behalf: scripts and event handlers are removed before the message is stored, and the body is displayed in an isolated frame that cannot run code or reach the rest of Knobs. Style information is checked property by property, so a message lays itself out inside its own frame and can’t reposition itself over the app or stretch that frame without limit.
A few consequences worth knowing:
- Text a sender hid stays hidden. Most marketing mail carries an invisible “preheader” line meant only for the inbox preview. Knobs respects that, so you see the message, not its scaffolding.
- Some messages look plainer than in other mail apps. Style rules kept in a separate block at the top of a message are discarded rather than trusted, so a sender that relies on them instead of styling the message directly loses that polish. Most mail is unaffected, because mail is normally built to survive exactly this.
- Remote images behave differently on the web and on iPhone. On the web they load with the message, which is how senders can tell their mail was opened; a setting to block them isn’t available there yet. On iPhone they’re blocked by default — open a message and you’ll be offered Load remote images for that message, with a global toggle in the Account sheet.
- Older messages keep the formatting they arrived with. Bodies are processed once, on delivery, so improvements to how mail is displayed apply to new mail rather than to your existing inbox.
Who can read your mail
Section titled “Who can read your mail”Your mailbox is yours. Mail is scoped to you within your workspace — other members, including admins, don’t see your inbox. Messages you send to other members of your workspace are delivered internally to their mailboxes.