# Get one received message and its history

`GET /v1/inbound/messages/{messageId}`

- Authentication: required (Bearer token)
- Required scope: `api.inbound.view`

The message's latest state plus every state it passed through, oldest
first. `history` is the answer to "it says delivered now, but did
something go wrong first?", which the folded list row cannot answer by
construction.

A message addressed to two configured receiving domains is two
deliveries with two histories; pass `domain` to narrow to one.

A message id unknown to your org is a 404 and never confirms that some
other org received one with that id.

## Path parameters

- `messageId` (string, required) — The SES message id. An opaque string, NOT a UUID — it is also the raw object's key suffix in your own landing bucket.

## Query parameters

- `domain` (string, optional) — Narrow to one receiving domain's delivery of this message.

## Example request

```bash
curl 'https://api.sendops.dev/v1/inbound/messages/string' \
  -H "Authorization: Bearer $SENDOPS_API_KEY"
```

## Responses

### 200 — The message and its history

Content type: `application/json`

```json
{
  "message_id": "string",
  "domain": "string",
  "recipient": "string",
  "recipients": [
    "string"
  ],
  "from": "string",
  "subject": "string",
  "received_at": "2026-05-17T20:00:00Z",
  "outcome": "delivered",
  "reason": "string",
  "detail": "string",
  "verdicts": {
    "spam": "",
    "virus": "",
    "spf": "",
    "dkim": "",
    "dmarc": ""
  },
  "webhook_status": 0,
  "attempts": 0,
  "is_auto_reply": true,
  "is_reply": true,
  "history": [
    {
      "message_id": "string",
      "domain": "string",
      "recipient": "string",
      "recipients": [
        "string"
      ],
      "from": "string",
      "subject": "string",
      "received_at": "2026-05-17T20:00:00Z",
      "outcome": "delivered",
      "reason": "string",
      "detail": "string",
      "verdicts": {
        "spam": "",
        "virus": "",
        "spf": "",
        "dkim": "",
        "dmarc": ""
      },
      "webhook_status": 0,
      "attempts": 0,
      "is_auto_reply": true,
      "is_reply": true
    }
  ]
}
```

### 401 — Missing, malformed, or unknown API key

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 403 — Key lacks the required scope or plan limit violated

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 404 — Resource not found

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 429 — Per-org rate limit exceeded

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 500 — Unexpected server-side failure. The `code` is `internal_error`. The
`request_id` field can be quoted to SendOps support to investigate.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```
