The Inbox app
Inbox lets your members talk to each other on your marketplace — a buyer asking a seller about a listing, a seller answering. This guide covers what it does, every setting you can change, and how to keep it from being abused.
Audience: marketplace owners and administrators
Reading time: about 12 minutes
1. What the Inbox does
A private, one-to-one conversation between two members of your marketplace.
A visitor browsing a listing sees a contact button on the listing page and on the seller's store page. Clicking it opens a conversation. Both members then get a full inbox on your storefront: a list of their conversations on the left, the open thread on the right, a box to reply, and — if you leave the option on — the listing the conversation started from, pinned at the top of the thread.
Messages are plain text. Members can attach images and documents. Either party can delete a conversation from their own inbox, and either can report it to you as spam.

A seller reading a buyer's first message. The listing the conversation started from is shown on the right, because Link listing to conversation is on.

2. Turning it on
Inbox is an app. It has to be enabled before any of it appears.
- In your admin, go to Plugins and open Inbox.
- Switch Activate Inbox plugin on.
- Press Save Changes.
Every setting below lives on that same screen, grouped into cards. You can save each card on its own — you do not have to fill the whole page before saving. Every card's current values are visible on screen, so this guide describes what each setting does rather than repeating the numbers shown there.
Good to know
Turning the app off hides the inbox and the contact buttons, but does not delete anything. Conversations stay in your database and come back if you switch it on again.
3. General settings
What the inbox is called and how it behaves on your storefront.

Plugins → Inbox → General settings.
Title
The name shown to your members in their account menu and page titles. Rename it to "Messages", "Discussions", whatever fits your marketplace.
Count to show in the menus
Whether the badge next to the inbox link counts unread messages or unread conversations. Conversations gives a smaller, calmer number when one person sends several messages in a row.
Send message when user press Enter key
On, Enter sends and Shift+Enter makes a new line — the chat convention. Off, Enter makes a new line and members must click the send button.
Link listing to conversation
When a conversation is started from a listing page, remember which listing it was about and show it at the top of the thread. Worth turning on for most marketplaces: it saves both people from asking "which item are we talking about?"
4. What a message may contain
Rules applied to the text itself — links, email addresses, phone numbers.

Plugins → Inbox → What a message may contain.
Links: what happens by default
You do not have to configure anything for links to be handled sensibly. Out of the box:
- A link to your own marketplace is allowed and displayed normally.
- A link to any other website is allowed, but shown to the recipient with a visible warning to check the destination before clicking.
- A link using a known URL shortener is refused when the message is sent. A shortener hides where it actually goes, which is why there is no setting to allow them.
Why refuse rather than hide
A blocked link is refused at the moment the message is sent, not merely hidden when it is displayed. Hiding it would still deliver the message, and if the display setting were ever turned off, every past link would become clickable again at once.
Blocked domains
One domain per line. A message containing a link to any of them — or to one of their subdomains — is refused when sent. Use this for a site that is actively being used to scam your members.
You do not need to list URL shorteners here. They are already refused.
Remove links to other websites
For marketplaces that want no outbound links at all. The message still reaches its recipient — only the link is replaced by the text of your choice, so a member who pasted a reference in good faith is not turned away. Links to your own store are never removed.
Remove Emails / Remove phone numbers
Replaces email addresses and phone numbers in message bodies with a placeholder you choose. Marketplaces use this to keep transactions on the platform rather than moving to a private channel.
Treat it as a speed bump, not a wall: someone determined to share a number can space out the digits. It stops the casual case, which is most of them.
What is always refused, with no setting
Two rules apply on every marketplace and cannot be switched off, because there is no legitimate use for either:
- HTML is refused when a message is sent. Members write plain text; HTML in a message body is, in practice, an attack.
- Very long messages are refused. A generous limit, well beyond anything a real conversation needs.
5. Sending limits
How much one member can send, and how fast — the part that stops a spam run.

Plugins → Inbox → Sending limits. Each guard sits directly above the numbers it uses.
Three modes, not on/off
Each limit has three modes, and they all start in the middle one:
Mode | What it does | When to use it |
|---|---|---|
Disabled | The rule never runs. | You have decided this limit does not suit your marketplace. |
Record only | Notes what it would have refused, in your audit log. Refuses nothing. | Starting point. Watch it for a while on your real traffic. |
Refuse | Actually turns the message away, with an explanation to the sender. | Once the recorded activity looks right for your marketplace. |
Why they start in "Record only"
A threshold that fits a quiet marketplace would refuse ordinary activity on a busy one. Rather than guess for you, the limits watch first: you look at what they recorded, adjust the numbers to your own traffic, then switch to Refuse. Nothing is blocked in the meantime.
What they record appears in your admin under Events, as
inbox.message.sendandinbox.conversation.openentries.
New conversations one member can start per day
A plain cap, applied to every member whatever their account age. Not one of the three-mode guards — it is always on.
Conversations opened in quick succession
Refuses a new conversation opened too soon after the previous one. Targets automated bursts: a person contacting several sellers takes longer than that to write each message.
Daily message cap
How many messages one member can send in a day, counted across all their conversations.
Restrictions on recently created accounts
A brand-new account gets a much lower message allowance and cannot share links at all. This is the single most effective limit against the pattern real attacks use: many accounts created and used in a short burst.
It is also the one most likely to annoy a genuine new buyer — which is what the next section is about.
6. How a member earns trust
The restrictions on new accounts lift on their own. Here is exactly when.
A brand-new account is restricted. But a new account is not the same thing as a bad account, and making every genuine buyer wait would cost you sales. So the restrictions lift as soon as the account has been vouched for.
An account counts as vouched for when either is true:
- It is older than the window you configured, or
- Someone who is themselves vouched for has replied to it.
A reply is a real human deciding this person is worth answering — a better signal than the calendar, and it arrives within minutes rather than days. In practice: a buyer signs up, messages a seller, the seller replies, and from that moment the buyer is unrestricted.
Worked example
A genuine buyer. Signs up, sends a couple of messages, hits the new-account cap. One seller replies that afternoon. The buyer is now unrestricted and can message freely, well before the recent-account window would have expired on its own.
A spam run. A batch of accounts created within minutes of each other, each blasting messages out. Nobody replies to any of them — that is what makes them spam. None of them is ever vouched for, so all of them stay capped for the full duration of the window.
The "themselves vouched for" part matters. A reply only counts if it comes from someone who is trusted already, so two freshly-created accounts messaging each other cannot vouch for one another. Trust has to trace back to an established member.
What the recipient sees
When a member receives a message from a recent account that nobody has vouched for yet, a warning appears above the conversation, naming the sender and suggesting they take a moment before sharing personal information. A report link sits inside the warning. It disappears by itself once the account is vouched for.
The wording of this warning is yours to edit, in the same card as the restrictions above — write your own if the default does not suit your marketplace's tone.

7. Moderation
What your members report to you, and what you do with it.

Plugins → Inbox → Moderation.
How a report works
- A member opens a conversation and clicks Report as spam.
- The reported member is immediately suspended from sending anything, anywhere on your marketplace, while the report waits for you.
- The report lands in your moderation queue.
- You review it and either confirm it or dismiss it. Either way, the suspension is lifted.
To keep the report button from becoming a weapon between competitors, one member can only file so many reports in a day.
This one acts immediately
Unlike the sending limits, reporting has no "record only" mode. A human has decided something is wrong, so the suspension applies at once — and your review is what lifts it. Check the queue regularly: an unreviewed report leaves a member unable to send.
The queue
Open it from the Reported spam button at the top of the Inbox settings screen. Each row shows who reported whom, the reason, and when it was filed.

Plugins → Inbox → Reported spam. Shown here with an empty queue.
Reports before a member is suspended from sending
How many pending reports it takes to suspend someone. The safest setting is the strictest one, unless false reports become a problem on your marketplace.
Authorize all administrators to display and view all messages exchanged by users?
Off, nobody on your team can read member conversations. On, administrators can open a transcript — which is what you need to judge a report fairly, but also means private conversations are readable by your staff.
Decide this one deliberately, and check what your privacy policy tells your members.
8. The contact button
The button that starts a conversation, and how it looks.

Plugins → Inbox → Contact button.
Button title
Write :username where you want the seller's name to appear — "Contact :username", "Ask :username a question". Leave it out and the button reads the same for everyone.
Background, border and text colour
Match your theme. Check the result against your storefront's actual background — the defaults assume a white page.
9. Email notifications
Telling members they have a message when they are not on your site.

Plugins → Inbox → E-mail notification.
Send an email notification for each new message
On, every message triggers an email. Off, members only see messages when they visit your marketplace.
Worth turning on for most marketplaces — a seller who does not know a buyer wrote to them is a lost sale. Consider the volume first if your members exchange long back-and-forth threads.
Send invisible copy to (BCC)
A blind copy of every notification, for your own monitoring. Several addresses separated by commas.
Email subject and content
Both accept variables, listed beside the editor. The most useful ones:
{{ sender.public_name }}, {{ recipient.public_name }}, {{ message.content }}, {{ message.url }}, {{ shop.name }}
A word on including the message
{{ message.content }}puts the message text straight into the email. Convenient, but it means a spam message reaches your member's mailbox even if they never open your site. Linking to the conversation with{{ message.url }}instead keeps unwanted content where your moderation tools can reach it.
10. Response time
Showing buyers how quickly a seller usually answers.

Plugins → Inbox → Response time.
Turned on, each seller's profile displays their typical reply delay, computed from their own message history. It sets buyer expectations and quietly rewards sellers who answer quickly.
Period taken into account
Only exchanges inside this window count, so the figure reflects how a seller behaves now rather than a long time ago.
Minimum number of exchanges before showing it
Below this, nothing is shown at all. A seller who answered once is not fast — they are simply unknown, and saying otherwise would mislead buyers.
How the figure is calculated
It is a median, not an average, so one abandoned conversation does not distort it. Several messages in a row from the same person count as one exchange, and a reply arriving long after the question is ignored rather than counted as a very slow answer.
11. Recommended setups
Three starting points. Adjust from there.
A new marketplace, low volume
Leave every limit in Record only and get on with growing. Turn on email notifications and Link listing to conversation. Keep an eye on the Reported spam queue.
An established marketplace
After a while of watching, move Restrictions on recently created accounts to Refuse — it is the lowest-risk one to enforce, since genuine buyers are released as soon as a seller replies to them. Leave the other two recording until you have numbers that fit your traffic.
A marketplace under attack right now
- Set all three guards to Refuse.
- Lower New conversations one member can start per day to something tight.
- Add the domains being used in the scam to Blocked domains.
- Turn on Remove links to other websites while it lasts.
- Watch the Reported spam queue closely — reports suspend senders immediately.
Every one of these is a setting. None of them needs us to deploy anything for you.
12. Questions we get
A member says their message was refused. Why?
The message they saw explains which rule turned it away — a blocked link, HTML in the body, a daily cap, or the new-account restrictions. If it was a cap, the same member can send again once the window rolls over.
Can I see what the limits are catching before I turn them on?
That is exactly what Record only is for. Look under Events in your admin for inbox.message.send and inbox.conversation.open entries.
A genuine new member is blocked. What do I do?
The fastest fix is for one of your sellers — or you, from your own member account — to reply to them. That vouches for the account and lifts the restrictions immediately. Otherwise, raise the daily allowance for recent accounts, or shorten the recent-account window.
I disabled Inbox after being spammed. Is it safe to turn back on?
Yes, and you do not have to accept the previous behaviour to do it. Turn it on with the three guards set to Refuse and the new-account restrictions tight; loosen them later once you can see what your real traffic looks like. Your old conversations are still there.
Do administrators read members' messages?
Only if you switch that on, in Moderation. It is off by default.
Are attachments allowed?
Yes. Images (JPG, PNG, GIF) display inline in the conversation; other documents appear as a link to download.
Updated on: 01/09/2026
Thank you!
