Request flows
How the pieces cooperate for the five things people do most. Every mail write is one database transaction in the mail service; notifications go out only after it commits.
Sign-up by text (portal, web or app)
The phone proves itself by sending a text, so no outgoing OTP is needed. It is the fallback when a Verify code can't be delivered.
Password sign-in (the brief's fallback)
Sending a new email (spec §6.1)
Each person in To/Cc/Bcc gets the email in their own direct chat with the sender; a group recipient delivers into the group chat. If two routes reach the same chat, it is delivered once.
Email with people outside PhoneMail
The outside person never sees a chat: every copy they get is a normal email, and their replies arrive in the same PhoneMail chat.
Replying (spec §6.2)
Starting a group from Compose
The brief says two or more people in To start a group. The clients do this on top of the spec's API, which keeps exactly one To per message:
This client-side behaviour is still an open decision for the team (see Decisions).