Account ownership
Every email belongs to the authenticated account that created it. Messages, raw source, and attachments inherit that ownership. Missing, expired, and foreign private resources all return the same404 shape.
Opaque resource identifiers
Use the returnedeml_*, msg_*, and att_* identifiers in API paths. An email address, filename, or storage key is never a resource identifier.