Configuration
Require sender authentication
With this setting on, the trigger accepts a message only when the mail provider reports an SPF pass or a DKIM pass for it. It is on for every new email trigger. While Allowed senders has at least one entry, the switch is locked on and cannot be turned off, because an allowlist without authentication can be defeated by forging the From address. The lock releases as soon as the list is emptied. A workflow saved with the switch off beside a populated allowlist raises a validation error with the same reason: the save goes through, but the workflow is paused and cannot be activated until the setting is fixed. An allowlist is a filter, not proof of who sent a message: a DKIM pass is not tied to the address you listed, so a sender who signs their own mail can still claim a listed address. A user-created inbox carries the same three intake controls and the same authentication rule.Inputs and outputs
Allowed inputs: None. This is a trigger node and starts the workflow. Output: Each attachment, passed to the next connected node individually. If an email contains multiple attachments, each attachment starts a separate run.Related
Email ingestion guide
Set up email-based document ingestion
Webhook trigger
Accept documents via the API instead