Free to scan. €4.99 once, only if you decide to clean up. No account, no subscription.

How in-boxed works

What actually happens when you use in-boxed, step by step, in plain English. The technical detail is there too, one click away.

Try the whole thing

Sample data. No inbox is connected, nothing is sent and nothing is charged.

Scanning your inbox…

0

senders found so far

    Going through your messages, reading only the sender lines.

    01

    You connect Gmail or Outlook with read-only access

    When you click "Scan my inbox", Google's or Microsoft's own consent screen opens directly in your browser, depending on which you connect. You grant in-boxed read-only access using the official gmail.readonly OAuth scope (Gmail) or the delegated Mail.ReadBasic scope (Outlook, Hotmail, Live), the same kind of permission each provider uses for its own unsubscribe button. We never see your password, and the access token stays in your browser, it is never sent to our servers.

    The technical version

    Google Identity Services token flow (OAuth 2.0, gmail.readonly) for Gmail; manual OAuth 2.0 authorization-code + PKCE flow (delegated Mail.ReadBasic) for Outlook. In both cases the short-lived access token lives only in the browser, no refresh token, nothing stored server-side.

    02

    We read email headers, never content

    Your browser calls the Gmail API or Microsoft Graph API directly and requests email metadata only: the From header (who sent it), the List-Unsubscribe header (how to opt out), and List-Id and Reply-To (to recognise mailing lists and reach their support). The body, subject line and attachments are technically excluded from the response. The data goes straight from Google or Microsoft to your browser, it never touches our servers.

    The technical version

    Gmail: messages.get with format=metadata and metadataHeaders=['List-Unsubscribe','List-Id','Reply-To','From'], called client-side to gmail.googleapis.com. Outlook: $select=from,replyTo,internetMessageHeaders, called client-side to graph.microsoft.com. No message content, no inbox data through our servers, for either provider.

    03

    We build a deduplicated list of senders

    We search your whole mailbox, up to 1,000 emails including archived mail, and list every unique sender that is a mailing list. If you received 20 emails from the same newsletter, it appears once. You see the full list before paying anything.

    The technical version

    Map deduplication by full sender address. A sender counts as a newsletter if it exposes a List-Unsubscribe or a List-Id header. Sorted by volume, most emails first: that is the order in which you actually make the decision, not our unsubscribe method.

    04

    You decide per sender, then we get to work

    Before anything is sent you see the full list, sorted by how much each sender mails you. Every sender is already set to leave; keeping one is your call and never our assumption. Then there are three outcomes, and in-boxed picks the route, not you. Most senders have an automatic opt-out, and your browser sends that request straight to them. Some manage subscriptions on their own preferences page, so we hand you a direct link to it. And where neither exists but the sender is still a mailing list, we prepare a written opt-out email to their support address, a formal GDPR objection you send yourself. A fourth group publishes no route at all, and we tell you that instead of pretending. Payment happens once, before the requests go out, and runs separately through Stripe without touching any Gmail or Outlook data.

    The technical version

    HTTP POST with body "List-Unsubscribe=One-Click" per RFC 8058, sent client-side. Legal basis: GDPR Article 21, CAN-SPAM Section 5. An https URL without a matching List-Unsubscribe-Post header is not a machine endpoint but a page meant for people, so it is handed to you as a link instead of being POSTed. Senders without List-Unsubscribe fall back to a GDPR opt-out email to Reply-To or From.

    05

    Your session ends, everything is gone

    When you close the tab, the short-lived Gmail or Microsoft token, which only ever lived in your browser, is discarded with it, and so is the scan list. Our servers never received your inbox data. We have no database, so there is no record of your email address, your senders, or anything else. You can revoke access anytime in your Google Account permissions or your Microsoft account's app permissions.

    The technical version

    The access token is held only in the browser tab and expires quickly (Gmail: about one hour). Our servers never receive or store Gmail or Outlook data, no database, no logs.

    From chaos to quiet

    Drag the slider. This is the marketing mail arriving before and after in-boxed. We stop the stream; we never delete anything.

    Marketing mail this week34
    A
    ASOS
    SALE ends tonight, up to 70% off
    S
    Spotify
    Your Discover Weekly is ready
    L
    LinkedIn
    9 new jobs match your profile
    B
    Booking.com
    Deals for your next trip
    T
    Temu
    Flash deal: everything under 2 euro
    M
    Medium
    10 stories picked for you today
    N
    Netflix
    New this week you might like
    Marketing mail this week0
    No new marketing mail
    BeforeAfter

    Frequently asked questions about how it works

    Can in-boxed see my email subjects or message content?

    No. We request only header metadata from the Gmail API or Microsoft Graph API, which explicitly excludes message content, subject lines and attachments. The response contains only the headers we specify.

    Does in-boxed store my email address?

    No. We don't know your email address unless you voluntarily provide it through the feedback form. Your Gmail or Outlook account is accessed via a short-lived token that stays in your browser and is never sent to our servers.

    How is this different from clicking Unsubscribe in Gmail or Outlook?

    Functionally identical, both use the List-Unsubscribe header. The difference is that Gmail or Outlook does it one email at a time. in-boxed does it for your entire inbox at once.

    What if a sender has no List-Unsubscribe header?

    If the sender is still a mailing list (it carries a List-Id header), we generate a ready-made GDPR opt-out email to their support or sender address, so even senders that deliberately omit the header are handled.

    Is the opt-out legally binding?

    The List-Unsubscribe header itself is a technical standard, not a law. What obligates the sender is GDPR: Article 21 requires action without undue delay (within one month at the latest), and CAN-SPAM requires action within 10 business days. Senders who keep mailing after a valid opt-out are in violation of those laws.

    See it for yourself

    The scan is free. No payment until you decide to unsubscribe.

    Scan my inbox for free →