Get a sandbox message

GET/api/v1/sandbox/messages/{id}
Requires anorganization API keywith the scopesandbox:read

The message in full: decoded text and HTML, headers, attachments, the simulated delivery events, and every sandbox webhook attempt it caused with your endpoint's response. The HTML is exactly what your code sent and is not sanitised — render it only in a sandboxed frame.

Parameters

NameInTypeDescription
idrequiredpathstringThe id identifier.

Request

GET/api/v1/sandbox/messages/{id}
curl -X GET 'https://app.mailyte.com/api/v1/sandbox/messages/01JBT8XQ2M9WYC3K4F6R7S8T9V' \
  -H 'Authorization: Bearer mk_live_YOUR_API_KEY'
The key names its own organization, so no X-Organization-ID header is needed.

Response

Success.

  • dataobject
    • idstring

      ULID of the stored message.

    • inbox_idstring
    • subjectstring
    • header_fromstring

      The From header, as written.

    • header_toarray<string>

      The To header addresses.

    • envelope_rcptsarray<string>

      Every address the message was sent to, INCLUDING Bcc: blind recipients are in the envelope, never in the headers, so this is the only place they show.

    • size_bytesinteger
    • attachment_countinteger
    • sourcestringsmtp | api | inbound

      `api` for a test-mode API key send; `inbound` for mail sent to the inbox's `inbound_address`.

    • simulated_outcomestringdelivered | bounce | softbounce | complaint | suppressed

      The outcome simulated for this message (a `@sim.mailyte.com` address or an `X-Mailyte-Simulate` header). Null means the default: accepted, then delivered.

    • spam_scorenumber

      Null until the message has been scored; scoring runs after it arrives.

    • read_atstring

      When it was marked read. Null means unread.

    • received_atstring

      When the sandbox accepted it.

    • headersarray<object>

      Every header in order, repeated names included.

      • namestring
      • valuestring
    • textstring

      The text/plain part, decoded. Null when there is none.

    • htmlstring

      The text/html part, decoded and NOT sanitised: it is exactly what your code sent. Render it only in a sandboxed frame with scripts disabled.

    • attachmentsarray<object>
      • indexinteger

        Pass to GET /sandbox/messages/{id}/attachments/{index}.

      • filenamestring
      • content_typestring
      • sizeinteger
      • content_idstring

        Set for an inline (cid:) part.

    • eventsarray<object>

      The simulated delivery timeline. These exist only in the sandbox: they never reach your suppression list, your live event log or your live webhooks.

      • event_typestring

        e.g. `email.accepted`, `email.delivered`, `email.bounced`.

      • recipientstring
      • detailobject
      • created_atstring
    • webhook_deliveriesarray<object>

      Every sandbox webhook attempt this message caused, with your endpoint's response.

      • idinteger
      • webhook_idstring
      • message_idstring

        The sandbox message that caused it. Null for a `sandbox.test` event.

      • event_typestring
      • attemptinteger

        1 to 5. Retries back off 30 s, 2 min, 5 min, 15 min, 30 min.

      • status_codeinteger

        Null when no response arrived; see `error`.

      • duration_msinteger
      • response_excerptstring

        The first 1 KB of your response body.

      • errorstring

        Why no response arrived (timeout, refused, blocked address).

      • created_atstring

        When the attempt was made.

    • spamobject

      The spam filter's verdict, as a receiving server would score it. Null until `analysed_at` is set; null after that means scoring was unavailable.

      • scorenumber
      • required_scorenumber

        The score at which mail is treated as spam.

      • actionstring

        e.g. `no action`, `add header`, `reject`.

      • symbolsarray<object>

        The rules that fired, largest effect first.

        • namestring
        • scorenumber
        • descriptionstring
        • optionsarray<string>
    • checksarray<object>

      Problems found in the message (missing text part, images without alt text, insecure links, missing List-Unsubscribe on bulk mail...). An empty list means none; null means not analysed yet (see `analysed_at`) or the step failed.

      • idstring
      • severitystringerror | warning | info
      • titlestring
      • detailstring
    • html_supportobject

      How well the HTML is supported across email clients. Null for a message with no HTML part, before `analysed_at` is set, or if the step failed.

      • score_pctinteger

        Market-share-weighted share of clients that fully support every feature used.

      • detected_countinteger
      • clientsarray<object>
        • familystring
        • supportstringfull | partial | none
      • featuresarray<object>

        Features the message uses that fail or are partial somewhere.

        • slugstring
        • titlestring
        • unsupported_inarray<string>
        • partial_inarray<string>
    • analysed_atstring

      When analysis finished. It runs a few seconds after the message arrives; until then `spam`, `checks` and `html_support` are null.

Returned inside the standard envelope.

Errors

StatusWhen
401The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist.
403The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys.
404No such resource in this organization.
422The request was understood but the values were not acceptable.
429Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait.

Every status, with what causes it and what to do, is on the error reference.