Changelog
What changed in Owlpost. Questions or something broken: hello@owlpost.to.
4 October 2026 · Emails from Owlpost now look like Owlpost
- New look. Sign-in links and the notices we send when an API key, passkey or webhook endpoint changes now come in the site's style, in light and dark mode, with a plain-text version for every message. They have no tracking pixels and no tracked links.
- Sign-in email. The link is a button and also plain text you can paste. The email says it works once, for 15 minutes, and that you can ignore it if you didn't ask for it.
- Webhook notices. We email you when an endpoint is added, its URL changes or its secret is rotated. The endpoint's address is shown as text, never as a link.
4 October 2026 · Email history, inbound mail and webhooks in the dashboard
- Tabs. The dashboard is now in tabs: Overview (usage, passkeys, API keys), Emails, Inbound, Webhooks, Domains and Inboxes. The address bar remembers the tab.
- Email history. Every message the account sent, newest first, with filters for status, live or test, tag and date range, and a search over recipients and subjects. Open one for its timeline (queued, sent, delivered, bounced, complained, opened, clicked, failed), the reason when something went wrong, its headers and size. The body is fetched only when you ask, and HTML is shown as source, never rendered.
- Suppressions. See which addresses Owlpost won't mail and why, and remove one. Removing a complaint asks you to say why.
- Inbound mail. What your inboxes received, with search, an inbox filter and the held queue. Open a message for its screening verdict, attachment names and text, follow its thread, and release held mail.
- Webhooks. Add endpoints for some or all events (the signing secret is shown once), edit them, turn them off and on, rotate the secret, send a test event, read each endpoint's recent deliveries, and replay dead letters. We email you when an endpoint is added or its secret rotated.
3 October 2026 · Passkeys, and the site knows you're signed in
- Passkeys. Add one in the dashboard and sign in at /login/ with Face ID, Touch ID, Windows Hello or a security key: no email needed. Browsers that support it offer your passkey right in the email field. Passkeys require user verification, and we email you whenever one is added or removed. You can rename and delete them.
- A nudge, once. After you sign in with an emailed link and have no passkey yet, the dashboard suggests adding one. Dismiss it and it stays away for 30 days.
- Signed-in header. When you're signed in, every page shows Dashboard and an account menu (your email, Dashboard, Sign out) instead of Sign in and Sign up, and "Start free" becomes "Go to dashboard".
3 October 2026 · Sign up yourself, and production goes live
- Self-serve sign-up. Create an account at /signup/ with an emailed sign-in link (no password), protected by a captcha. The first sign-in creates your account on the Free plan.
- Dashboard. /dashboard/ lists and creates API keys (shown once, and you get an email when one is made), adds sending domains with their DNS records and a Verify button, creates agent inboxes, and shows this month's usage.
- Plan limits are enforced. Free is 100 recipients a day and 3,000 a month, with 3 agent inboxes. Limits are counted atomically, so parallel requests can't slip past them. Up to 10 active API keys per account.
- Domain ownership. A domain can only be added by one account, and Owlpost's own domains are reserved. Errors say a domain is unavailable without saying who has it.
- Production API at api.owlpost.to. Sending through Amazon SES with delivery, bounce and complaint events recorded, so hard bounces and complaints are suppressed automatically. Inbound mail for agent inboxes on agents.owlpost.to arrives as JSON within seconds.
- New endpoints.
GET /v1/emailslists messages with cursor paging and status and tag filters;POST /v1/emails/batchsends up to 100 messages per request, all or nothing. - owlpost CLI, part 1.
login,whoami,send,batchandemail get. - Fixed.
GET /v1/inbound/inboxesnow reports each inbox's realai_footersetting. - Not yet. Amazon still keeps the account in its sandbox, so sign-in mail only reaches addresses we've verified. Sign-up opens to everyone when AWS approves sending.
2 October 2026 · Unsubscribe topics
- Marketing mail can be scoped to a topic: unsubscribing from one topic suppresses only that topic, and the
email.unsubscribedwebhook tells you.
30 September 2026 · Inbound screening
- Inbound mail through Amazon SES receiving carries its virus and spam verdicts, and attachment rules apply on every path.
29 September 2026 · The API, first version (staging)
- Send.
POST /v1/emailsis Resend-compatible and idempotent, withop_live_andop_test_keys (test keys never send real mail). Checked against the official Resend Node SDK. - Domains. Sending domains with DKIM and a custom MAIL FROM, DNS records in Resend's shape, verified on demand and on a schedule.
- Events and suppression. Every SES notification's signature is checked before it's used; one-click unsubscribe (RFC 8058) and a suppression list API.
- Webhooks. Signed, retried, dead-lettered and replayable events for sent, delivered, bounced, complained, opened, clicked and failed mail.
- Agent inboxes. Receive mail into inboxes for AI agents or on your own domain, reply in threads, read one-time codes, with screening.