Platform

Everything between MX and your endpoint.

Six stages run on every email in the time it takes to say it. You get one signed JSON event (or a Slack post, a sheet row, a Zap) and we keep nothing.

  1. 01Receive
  2. 02Verify
  3. 03Scan
  4. 04Understand
  5. 05Extract
  6. 06Route & deliver
01

Receive only what you asked for.

Point your MX at mx.ghostparse.com and list the addresses that may receive: exact ones, patterns like ticket-*, or a catch-all. Everything else is refused at the door.

yourapp.com · addresses
support@→ webhook
orders@→ parser “Orders”
ticket-*@→ signed tags only
anything elserefused
02

Prove who sent it.

We run SPF, DKIM and DMARC ourselves and give you a single verdict, not a header a sender could forge. Enforce a sender's “reject” policy, block senders, or accept only authenticated senders you list.

SPFpass203.0.113.9
DKIMpassd=example.com
DMARCpassp=reject
03

Spam, viruses and robots, caught.

Every message gets a spam score and a virus scan on our own servers. Out-of-office replies and bounces are flagged, so your app never auto-replies to an auto-reply. Choose to reject, drop or simply be told.

SPAM SCORE0.4 / your limit 6.0
virus: cleanauto_submitted: nullbulk: no
04

Understand the message, not just the MIME.

The new part of a reply without the quoted history. A thread_id that stays the same for a whole conversation. Meeting invites as events, bounces with the failed address, attachments with their hash.

"reply_text": "Thanks, that fixed it!",
"thread_id": "thr_9f2c41d07ab3e5c8",
"auto_submitted": null,
"calendar": [ … ],
"attachments": [
  { "filename": "order-1042.csv", "size": 74 }
]
05

Pull out the fields you care about.

Give an address a parser. Rules find text after a label or between two markers. Either way, you get typed fields in data.extracted.

FIELD
TYPE
VALUE
order_number
string
1042
total
number
42.5
tracking
string
TRK-88213
Parser “Orders”
06

Deliver it: signed, retried, never lost.

Routing rules send each email to the right place. Every webhook is signed with Standard Webhooks. If your endpoint is down we retry, try your backup URL, then ask the sender's server to try again later, so nothing is dropped while you recover.

  1. 10:42:07POST yourapp.com/hooks503
  2. 10:42:08retry503
  3. 10:42:09backup.yourapp.com/hooks200
  4. 10:42:09alert emailed to ownerssent
Run it with confidence

Built for the team on call.

Delivery log & alerts

Every email's outcome and why, with an email to your team when a webhook keeps failing or DNS breaks.

Teams, roles & 2FA

Owners, admins, developers and viewers, with two-factor login you can require for everyone.

Audit log

Who changed what, when and from where. Email content never appears in it.

Domains API

Set up domains and addresses from your own product. Ideal for hosting control panels.

White-label

Run customers as sub-accounts under your brand, MX hostname and dashboard address.

Public status

Live checks of receiving, delivery and the API, with incident history. View status →

The details

Specs, plainly.

The numbers your security review will ask for.

Webhook signing
Standard Webhooks · HMAC-SHA256
Delivery attempts
3 per email, then the backup URL, then the sender retries
Largest email
25 MB, attachments included
Attachments
Inline base64, separate files, or left out
Email content stored
None
Data region
United Kingdom

See your first email as JSON in a minute.