# Block unwanted senders

Reject future mail from selected addresses and domains, with rules only you can change.

Source: https://cherami.to/docs/guides/receiving-rules



Open [Account → Receiving rules](https://cherami.to/account/receiving-rules), select an inbox, and enter unwanted senders in the **Email addresses** and **Domains** tabs, one entry per line. Turn on **Block senders**, then **Save rules**. Both lists and the switch are saved together; switching tabs keeps unsaved entries.

A match in either list rejects future incoming mail for that inbox. Messages already received stay unchanged. Turn blocking off to pause it without clearing the lists. Empty lists block nothing, even with blocking on. Existing and new inboxes start with blocking off.

## Choose addresses and domains [#choose-addresses-and-domains]

Enter bare ASCII email addresses, without display names or wildcards. You can save up to 100 addresses and 100 domains independently. Whitespace around entries and duplicates are removed. Domain names are lowercased; use punycode for internationalized domains, not raw Unicode or URLs.

The part before `@` is case-sensitive: `Alex@example.com` and `alex@example.com` are distinct. Domain case does not matter. Plus tags and dots stay distinct, even when a provider delivers those variations to the same mailbox.

A domain rule matches only that exact domain. Blocking `example.com` does not block `sub.example.com` or `notexample.com`. Add a subdomain separately to block it.

## Understand what gets rejected [#understand-what-gets-rejected]

Rules use the address in the message’s visible **From** header, not its display name, Reply-To or SMTP envelope sender. When more than one supported address can be parsed from From, a match on any one rejects the message. These are nuisance filters, not sender authentication: From is sender-controlled and can be forged.

Missing, unusable or unsupported From addresses do not match a rule. Supported addresses use the same bare ASCII syntax as rule entries; quoted local parts and raw internationalized addresses are not supported. From fields longer than 65,536 characters are left unmatched. Unmatched mail follows ordinary receipt and provider protections, without a fallback to the envelope sender.

Matching mail is rejected during SMTP receipt before it is stored. It does not appear in mail listings, and there is no quarantine or copy to recover. Rejection does not guarantee a particular bounce notification to the sender. A rule change does not recall a receipt already in progress.

If saving could not be confirmed or another browser session changed the rules, reload the saved rules before editing again.

These rules do not screen message content. For spam, phishing or agent-manipulation screening needs, see [advanced mail protection](https://cherami.to/docs/guides/safety#advanced-mail-protection).

## Let the agent inspect the rules [#let-the-agent-inspect-the-rules]

Agents can use `get_receiving_policy` over MCP or [inspect the policy over HTTP](https://cherami.to/docs/api/inboxes/get-receiving-policy). Only the human’s browser session can change it, not an API key or OAuth mail grant. Inspection shows the saved settings; it is not a record of rejected mail or proof of why a particular message did not arrive.
