Mailbox API
Overview
The Microsoft Graph surface. Only the operations listed here are reachable — the proxy runs a strict allow-list, so any other Graph path returns 404 even if it exists upstream.
The {email} in each path must be a mailbox owned by the account the API key belongs to. A mailbox you do not own returns 404, not 403, so the API never reveals which addresses are sending.ac mailboxes.