Integration · Cloudflare R2
Back up email to Cloudflare R2 — automatically.
Forward any email to your private InboxBucket address and the original .eml is written to your own R2 bucket over the S3 API. And because R2 charges zero egress, getting your whole archive back out is always free.
Free plan available · No credit card required
- From:
- Acme Billing <[email protected]>
- To:
- [email protected]
- Subject:
- Invoice #4471 — June services
- Files:
- invoice-4471.pdf
s3://your-bucket/inboxbucket/2026/07/0713__invoice-4471__acme-billing.eml
✓ stored · 84 KB · original MIME
Why back up to R2
Durable storage you can read back for free.
Zero egress on restores
A backup you can't afford to restore isn't much of a backup. R2 charges nothing for egress, so re-downloading one message or your entire archive is always free.
S3-compatible, no glue
R2 implements the S3 API, so InboxBucket writes to it with the same code path it uses for AWS. Give it your endpoint, a token, and a bucket — that's the whole integration.
In the account you already have
If you're already on Cloudflare, your email archive lives right beside the rest of your infrastructure, under tokens and buckets you control.
How it works
Point it at your bucket, then forward.
Add your R2 bucket
Give InboxBucket your R2 endpoint, bucket, and an API token's key and secret (details on the right).
Get your address
You receive a private inbound address that only receives mail:
[email protected]Forward anything
Forward one message by hand or set an auto-forward rule; seconds later the original .eml is an object in R2.
What you'll need to connect
- Endpoint
- https://<account-id>.r2.cloudflarestorage.com
- Region
- auto
- Access key + secret
- from an R2 API token (Object Read & Write, one bucket)
- Bucket
- your backup bucket name
Everything comes from your Cloudflare R2 dashboard. Pick Cloudflare R2 when connecting storage in InboxBucket — it's the same connector as Amazon S3, preset for your R2 endpoint.
The access we ask for
A token scoped to one bucket.
You create an R2 API token with Object Read & Write on just your backup bucket and hand InboxBucket its access key and secret. That's the narrowest scope R2 offers — it can't reach any other bucket in your account.
We're the pipe, not the vault. Mail passes through us only on its way to R2; what we keep is the metadata behind your dashboard — sender, subject, date, status — never the messages. Roll or delete the token anytime in the Cloudflare dashboard, and every .eml already written stays in your bucket.
- Scoped to one bucket — no access to the rest of your account
- Credentials you generate and control
- Roll or revoke the token anytime — your .eml objects remain
The details
Built like a backup should be.
Free to get back
R2 charges zero egress, so re-downloading or fully restoring your email archive never costs bandwidth. You pay for the bytes you store, not for reading your own mail back.
Drop-in S3-compatible
R2 speaks the S3 API, so InboxBucket writes to it exactly as it writes to AWS — point it at your R2 endpoint with an access key and you're done.
The original message, byte for byte
Every email is written as a .eml object — the raw RFC 822 message with headers, body, and attachments in one file, openable in any mail client or a text editor.
Big attachments via multipart
Large attachments upload with S3 multipart, so a 40 MB signed contract lands whole in your bucket, well past any single-request size limit.
Written once, however it arrives
People double-forward and mail servers retry. Deduplication on Message-ID means each message becomes exactly one object in R2.
Loud on failure, never silent
A failed write queues and retries, with status in your dashboard until it lands — plus a clear prompt if the R2 token needs rotating.
FAQ
R2 backup, answered.
What endpoint and region do I use for Cloudflare R2?
Use your R2 S3 endpoint, which looks like https://<account-id>.r2.cloudflarestorage.com, and set the region to auto (R2 also accepts us-east-1, which aliases to auto). Both come straight from your Cloudflare R2 dashboard. InboxBucket handles the path-style addressing R2 expects automatically.
What credentials does InboxBucket need for R2?
An R2 API token, which gives you an Access Key ID and a Secret Access Key that work with any S3 tool. Create the token with Object Read & Write access scoped to just your backup bucket — that's the narrowest scope R2 offers, and it still can't touch any other bucket. Pick Cloudflare R2 when connecting storage in InboxBucket and paste the key and secret along with your endpoint and bucket.
Does restoring my email archive from R2 cost anything?
No bandwidth cost. R2 has zero egress fees, so re-downloading individual messages or restoring your entire archive is free — you only ever pay R2 for the bytes you store and the operations you make. That's the main reason to choose R2 as a backup destination.
Is backing up email to R2 the same as Amazon S3?
Effectively yes — R2 is S3-compatible, so InboxBucket uses the same connector, just pointed at your R2 endpoint. If you're weighing destinations, see the Amazon S3 setup; everything there applies, minus the egress fees.
What format are the backups in?
Every email is stored as a .eml file — the standard RFC 822 message with headers, body, and attachments in one portable file that opens in any mail client or a text editor. No proprietary format, nothing to export later.
Is R2 email backup free?
InboxBucket's Free plan includes one storage connection with full-fidelity .eml backup, so you can archive to R2 on the free tier. You pay Cloudflare separately for R2 storage, which includes a free monthly allowance and low per-gigabyte pricing beyond it.
Free plan · No credit card
Put your email in your own R2 bucket.
Add your bucket, get your address, and the next email you forward is written to storage you control — free to read back, always.
Add your R2 bucket