# Email integration

Some tools can only send email. The **Email** integration gives you a unique inbound address: every email sent to it opens an alert, and a follow-up email saying the problem recovered resolves it. No webhook is needed.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Email**, pick an **Escalation Policy** and click **Create Integration**.
### Copy the inbound address
EvoHub shows "Integration created! Send alert emails to this address:" with the address. You can copy it again later from the integration's **Inbound email address** field.
### Use it as the alert recipient
In your monitoring tool, add the address as the recipient of its alert emails.
### Send a test
Send a test email from the tool (or from your own mailbox) and check that an alert appears in **On-Call → Alerts**.
:::

Each email integration has its own address, so you can create one per tool and route each to a different escalation policy.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | The email subject (or "Email alert" if empty). |
| Description | The plain-text body. For HTML-only emails, the text with the HTML tags removed. |
| Severity | Always **high**. Email carries no reliable severity, so EvoHub does not guess one. |
| Fingerprint | The subject, with status words (such as DOWN, UP, ALERT, RESOLVED, CRITICAL) and punctuation removed. |

## Auto-resolve

An email is treated as a recovery when its subject or body contains any of these phrases (case does not matter):

`resolved`, `recovered`, `is up`, `back up`, `is back`, `cleared`, `no longer`, `has recovered`, `up again`, `ok again`

A recovery email does not open an alert. It resolves the open alert whose fingerprint matches — so `[DOWN] api.acme.example` is resolved by `[UP] api.acme.example is back up`, because both subjects reduce to the same fingerprint.

> [!WARNING]
> The recovery check looks at the body as well as the subject. If your tool's problem emails contain one of those phrases in their body (for example a footer such as "This alert will be resolved automatically"), they are read as recoveries and no alert opens. Remove the phrase from the tool's email template, or use a webhook integration for that tool.

## Deduplication

While an alert is open, more emails with the same subject (after status words are removed) are recorded as **Retriggered** on that alert instead of opening new ones. Different monitors should therefore have different subjects, for example by including the monitor or host name.

## Security

- The address contains a random token and is not guessable. EvoHub does not check the sender, so anyone who knows the address can open alerts. Share it only with the tools that need it.
- To stop accepting email, **Disable** the integration. To retire an address, **Delete** the integration and create a new one.
- Emails to an address that does not belong to an enabled integration are ignored.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Alert API and generic webhook](https://docs-dev.evohub.io/generic-webhook.md)
- [Alerts and incidents](https://docs-dev.evohub.io/alerts-and-incidents.md)
