# Limit an inbox’s recipients

Choose the addresses and domains an inbox may email, with rules only you can change.

Source: https://cherami.to/docs/guides/sending-rules



Open [Account → Sending rules](https://cherami.to/account/sending-rules), select an inbox, and enter its allowed recipients in the **Email addresses** and **Domains** tabs, one entry per line. Turn on **Restrict recipients**, then save. Every agent using that inbox must follow the same rules, whether connected through HTTP or MCP.

With restrictions on, every To, Cc and Bcc recipient must match either an exact address or an exact domain. One nonmatching recipient blocks the entire send, including replies, reply-all and forwards. No recipients are silently removed. Both lists empty with restrictions on blocks all sending from that inbox.

Turn restrictions off to allow any destination under Cherami’s ordinary sending permissions and policies. Turning them off keeps both saved lists. Changes take effect when saved, but do not cancel sends already authorized. Reload saved rules if a change could not be confirmed or another browser session edited them.

## Enter exact addresses [#enter-exact-addresses]

Use bare ASCII email addresses, without display names or wildcard patterns. You can save up to 100 addresses. Surrounding whitespace and duplicates are removed, and domain names are lowercased.

The part before `@` is case-sensitive. `Alex@example.com` and `alex@example.com` are different rules. Domain case does not matter: `alex@EXAMPLE.COM` matches `alex@example.com`. Plus tags and dots remain distinct even if a particular provider delivers those variations to the same mailbox.

## Enter exact domains [#enter-exact-domains]

Use bare ASCII domains, such as `example.com`, or punycode for internationalized domains, such as `xn--bcher-kva.de`. Raw Unicode, URLs, email addresses and wildcard patterns are not accepted in the Domains tab. You can save up to 100 domains independently of the 100-address limit. Surrounding whitespace and duplicates are removed, and domains are lowercased.

Domain matching is exact: `example.com` allows addresses at that domain, not at `sub.example.com` or `notexample.com`. Add each subdomain separately when needed. Switching tabs keeps your unsaved entries; **Save rules** saves both lists and the restriction setting together.

Allowing an address or domain is not recipient consent and does not approve the message’s content. Ordinary permissions, allowance, provider suppression and [permitted sending](https://cherami.to/docs/guides/safety#permitted-sending) still apply.

## Let the agent inspect the rules [#let-the-agent-inspect-the-rules]

Agents can use `get_sending_policy` over MCP or [read the policy over HTTP](https://cherami.to/docs/api/inboxes/get-sending-policy). They cannot change it using mail credentials. Ask the human to review a blocked destination rather than changing inboxes to bypass the restriction.

`recipient_not_allowed` means the new attempt was blocked before submission and consumed no recipient allowance. Its message identifies the blocked destinations. A retry of an existing keyed attempt returns that earlier attempt, even if rules have since changed; it does not send again or claim the earlier email was blocked.

Rules belong to the selected inbox, not the whole account. Existing and newly created inboxes start unrestricted. Other inboxes remain accessible to the same account’s agents, and inbox creation is still available when slots permit. This feature is not account-wide isolation or automatic abuse detection. For content checks against harmful or abusive correspondence, see [advanced mail protection](https://cherami.to/docs/guides/safety#advanced-mail-protection).
