How it works

A gate in front of your inbox: not another inbox

Knock puts one small, refundable toll between you and the strangers who want your attention. It works with a Knock address you publish, or in front of the Gmail or iCloud inbox you already use.

Last updated July 2026

The gate

Strangerhuman or AI agentKnock gatedeposit $2 · refundableRefunddelivered + allowlisted foreverClaimyou keep 90%7 days of silenceautomatic full refundPaying places a message in thequeue. It never buys a reply.
Diagram A, a stranger places a refundable hold; you release it, claim it, or let it expire.

An unknown sender is asked for a small refundable hold on their card, like a hotel deposit, before their message reaches you. Nothing is charged unless you claim it, and deposits are capped at $25. Once you release one, that sender is allowlisted and never pays again.

1. What senders experience

A deposit is a signal, not a purchase. Most holds are never charged at all, by three separate routes:

  • You release it. The message was worth reading, so the hold drops off the card and the sender is allowlisted for good.
  • You release it without signing in. The release button travels with the message, it's in the forwarded email's footer, one gesture from the reply you'd write anyway.
  • Time releases it. Any hold you never review is released in full after 7 days, 72 hours for unpaid agent challenges raised through the API, which simply expire.

Knock never sees a reply, replies travel directly between sender and recipient, so replying alone does not refund anything today. Automatic refund-on-reply is planned for the deep Gmail integration, where, with your consent, Knock can see that you answered.

A sender is only charged when you review the message and judge it unsolicited. That is a deliberate, message-by-message decision, and paying never buys a reply. It buys a place in the queue and nothing more. Full detail lives in how refunds work.

2. What you experience

Knock is not another inbox to check. Messages land where they always did, the gate sits upstream, and everything that clears it is delivered to the address you already read.

In practice most people open the dashboard about once a month: to glance at what was held, release anything worth releasing, and claim the rest. Ignoring it entirely is a valid strategy, because silence releases every hold after 7 days.

A held depositwaiting on youThe forwarded emailtwo buttons: refund or claimYour AI assistantover MCP, in plain languageThe dashboardbulk actions and filters
Diagram C, three ways to settle a hold.
  • From the forwarded email. Every forwarded message carries two buttons, release the hold, or claim it, that work without signing in.
  • From your AI assistant. Connect Knock over MCP and settle in plain language. See connect an AI assistant.
  • From the dashboard. Grouped by intent, with bulk release, bulk block and filters.

When you do claim a deposit the hold is captured and you keep 90% of it net of payment-processing fees; 10% covers payment processing and running the gate.

The four verdicts: and what each one teaches the system

Your actionThe sender's moneyThe sender's future
ReleaseHold released, never chargedAllowlisted, knocks free forever
ClaimCard charged, you keep 90% net of feesStill unknown, pays again next time
Ignore (7 days)Hold released automaticallyStill unknown, pays again next time
BlockHold released if placedSilence, future mail never reaches the queue

Release is an endorsement. It's the only action that grants free access, reserve it for senders you'd genuinely welcome again. Expiry releases the hold but grants nothing: an ignored sender starts from zero next time.

Claim is a verdict, not a tip jar. Claiming says “I reviewed this and it was unsolicited.” For paid noise, claiming beats ignoring: the sender is made to feel the cost, you're compensated for the review, and the economics only work if recipients actually render verdicts.

Block ends the conversation. For persistent noise, don't keep collecting $2, block the sender or their whole domain and the gate stops even challenging them.

A refund you chose creates trust; a refund the clock chose creates nothing. That's the entire difference between releasing and ignoring.

3. Protect the address you already use

Your Gmail / iCloudforwarding ruleKnock gatechecks your allowlistknown senderStraight backno challenge, no delayunknownChallengeddeposit, then deliveredEverything that clears the gate lands in the inbox you already use,and your replies still leave from your own address.
Diagram B, your provider forwards to the gate; cleared mail returns to your real inbox.

You don't have to move addresses or ask anyone to update their contacts. Your provider forwards incoming mail to your Knock alias, known senders flow straight back within seconds, and unknown senders meet the gate on the way in. Your replies still leave from your own address.

Gmail

Setup happens once, in Gmail's web settings at mail.google.com (the Gmail mobile app doesn't expose forwarding settings). If you read your Gmail in Apple Mail, Outlook, or any other app, nothing changes there, the gate runs on Google's servers, and you keep reading exactly where you always have.

  • Add your Knock alias as a forwarding address in Gmail's settings.
  • Google emails a verification code to that alias, we detect it automatically and show you the code and the confirmation link within seconds. You click it; we never do.
  • One filter forwards your mail to the gate.
  • Switch on “reply from the same address the message was sent to”, so answers come from your own address.

iCloud

Set up at icloud.com in a browser; the Mail apps on your devices are unaffected.

  • One server-side rule at icloud.com → Mail → Settings → Rules forwards mail addressed to you to your Knock alias. Nothing to install, nothing running on your Mac.
  • Apple usually sends no verification for rules, so the setup confirms itself with a test message instead.

Set up inbox protection

The lookalike filter

Protecting a real address raises a fair question: what stops someone from posing as your bank? Three things, none of them magic.

  • Authentication happens first. Inbound mail is checked against SPF and DKIM at the edge, before Knock processes it at all. Mail that fails authentication is rejected outright, it never reaches your queue, paid or not.
  • Allow rules only admit authenticated mail. An allow entry for paypal.com admits PayPal, and nothing merely pretending to be PayPal. The allowlist is a shortcut past the deposit, never past authentication.
  • Lookalikes meet the gate. A domain like paypal-secure-alerts.com matches no allow rule of yours, so it is treated as what it is: a stranger. It pays a deposit, lands in the queue with a low signal score, and gets reviewed, instead of landing in your inbox looking urgent.

None of this makes email scam-proof, it makes impersonation expensive and visible.

4. For agents and developers

Agents don't need a mailbox. Any handle exposes a machine-readable attention manifest and a contact endpoint: post a message, get back a challenge with the price and a payment link, settle it, and the message enters the queue exactly like a human's. Unpaid challenges expire after 72 hours.

curl -X POST https://knock.email/api/public/contact/thomas \
  -H "Content-Type: application/json" \
  -d '{"from":"agent@example.com","subject":"Intro","body":"..."}'

The full protocol, manifest fields, challenge lifecycle and settlement, is in the protocol documentation.

Questions people ask

Deposits, privacy, spam, phishing and mobile, the short answers live on the FAQ page.