Integration · Cloudflare R2

Back up email to Cloudflare R2 — automatically.

Forward any email to your private InboxBucket address and the original .eml is written to your own R2 bucket over the S3 API. And because R2 charges zero egress, getting your whole archive back out is always free.

Free plan available · No credit card required

Received13 Jul 2026 · 11:03 UTC
From:
Acme Billing <[email protected]>
To:
[email protected]
Subject:
Invoice #4471 — June services
Files:
invoice-4471.pdf
written to your R2 bucket as

s3://your-bucket/inboxbucket/2026/07/0713__invoice-4471__acme-billing.eml

✓ stored · 84 KB · original MIME

Archived · Cloudflare R2

Why back up to R2

Durable storage you can read back for free.

Zero egress on restores

A backup you can't afford to restore isn't much of a backup. R2 charges nothing for egress, so re-downloading one message or your entire archive is always free.

S3-compatible, no glue

R2 implements the S3 API, so InboxBucket writes to it with the same code path it uses for AWS. Give it your endpoint, a token, and a bucket — that's the whole integration.

In the account you already have

If you're already on Cloudflare, your email archive lives right beside the rest of your infrastructure, under tokens and buckets you control.

How it works

Point it at your bucket, then forward.

  1. Add your R2 bucket

    Give InboxBucket your R2 endpoint, bucket, and an API token's key and secret (details on the right).

  2. Get your address

    You receive a private inbound address that only receives mail:

    [email protected]
  3. Forward anything

    Forward one message by hand or set an auto-forward rule; seconds later the original .eml is an object in R2.

What you'll need to connect

Endpoint
https://<account-id>.r2.cloudflarestorage.com
Region
auto
Access key + secret
from an R2 API token (Object Read & Write, one bucket)
Bucket
your backup bucket name

Everything comes from your Cloudflare R2 dashboard. Pick Cloudflare R2 when connecting storage in InboxBucket — it's the same connector as Amazon S3, preset for your R2 endpoint.

The access we ask for

A token scoped to one bucket.

You create an R2 API token with Object Read & Write on just your backup bucket and hand InboxBucket its access key and secret. That's the narrowest scope R2 offers — it can't reach any other bucket in your account.

We're the pipe, not the vault. Mail passes through us only on its way to R2; what we keep is the metadata behind your dashboard — sender, subject, date, status — never the messages. Roll or delete the token anytime in the Cloudflare dashboard, and every .eml already written stays in your bucket.

  • Scoped to one bucket — no access to the rest of your account
  • Credentials you generate and control
  • Roll or revoke the token anytime — your .eml objects remain

The details

Built like a backup should be.

Free to get back

R2 charges zero egress, so re-downloading or fully restoring your email archive never costs bandwidth. You pay for the bytes you store, not for reading your own mail back.

Drop-in S3-compatible

R2 speaks the S3 API, so InboxBucket writes to it exactly as it writes to AWS — point it at your R2 endpoint with an access key and you're done.

The original message, byte for byte

Every email is written as a .eml object — the raw RFC 822 message with headers, body, and attachments in one file, openable in any mail client or a text editor.

Big attachments via multipart

Large attachments upload with S3 multipart, so a 40 MB signed contract lands whole in your bucket, well past any single-request size limit.

Written once, however it arrives

People double-forward and mail servers retry. Deduplication on Message-ID means each message becomes exactly one object in R2.

Loud on failure, never silent

A failed write queues and retries, with status in your dashboard until it lands — plus a clear prompt if the R2 token needs rotating.

FAQ

R2 backup, answered.

What endpoint and region do I use for Cloudflare R2?

Use your R2 S3 endpoint, which looks like https://<account-id>.r2.cloudflarestorage.com, and set the region to auto (R2 also accepts us-east-1, which aliases to auto). Both come straight from your Cloudflare R2 dashboard. InboxBucket handles the path-style addressing R2 expects automatically.

What credentials does InboxBucket need for R2?

An R2 API token, which gives you an Access Key ID and a Secret Access Key that work with any S3 tool. Create the token with Object Read & Write access scoped to just your backup bucket — that's the narrowest scope R2 offers, and it still can't touch any other bucket. Pick Cloudflare R2 when connecting storage in InboxBucket and paste the key and secret along with your endpoint and bucket.

Does restoring my email archive from R2 cost anything?

No bandwidth cost. R2 has zero egress fees, so re-downloading individual messages or restoring your entire archive is free — you only ever pay R2 for the bytes you store and the operations you make. That's the main reason to choose R2 as a backup destination.

Is backing up email to R2 the same as Amazon S3?

Effectively yes — R2 is S3-compatible, so InboxBucket uses the same connector, just pointed at your R2 endpoint. If you're weighing destinations, see the Amazon S3 setup; everything there applies, minus the egress fees.

What format are the backups in?

Every email is stored as a .eml file — the standard RFC 822 message with headers, body, and attachments in one portable file that opens in any mail client or a text editor. No proprietary format, nothing to export later.

Is R2 email backup free?

InboxBucket's Free plan includes one storage connection with full-fidelity .eml backup, so you can archive to R2 on the free tier. You pay Cloudflare separately for R2 storage, which includes a free monthly allowance and low per-gigabyte pricing beyond it.

Free plan · No credit card

Put your email in your own R2 bucket.

Add your bucket, get your address, and the next email you forward is written to storage you control — free to read back, always.

Add your R2 bucket