Inspect sending rules
GET /v1/inboxes/{inbox_id}/sending-policy
Read as Markdown ↗GET /v1/inboxes/{inbox_id}/sending-policy
Requires a Claim-issued API key: Authorization: Bearer YOUR_CREDENTIAL.
GET /v1/inboxes/{inbox_id}/sending-policy returns 200.
enabled: false means unrestricted by this control, even when saved addresses or domains remain. When enabled, every To/Cc/Bcc recipient must match an exact address or an exact domain; both lists empty blocks all sending. Local-part case is significant, domain case is not, and plus tags/dots remain distinct. Names do not participate in matching. Each list contains at most 100 normalized, unique entries. Domains are lowercase ASCII, including punycode; matching does not include subdomains unless listed separately.
revision is the saved policy version, starting at 0 for an unconfigured inbox. Inspection is not authorization for a later send: the policy at send reservation is authoritative. Missing, deleted and other-account inboxes return 404.
This endpoint is read-only. Only the human’s browser session can edit rules in Account → Sending rules, not an API key or OAuth mail grant. New inboxes start unrestricted. See recipient restrictions for setup and scope.
Parameters
| Parameter | Location | Required | Type | Meaning |
|---|---|---|---|---|
inbox_id | path | Yes | string | Owned Cherami resource ID returned by the API. |
curl example
Replace resource-ID placeholders with returned IDs. Supply CHERAMI_API_KEY through your private shell environment.
curl --silent --show-error --include --request GET \
"https://cherami.to/v1/inboxes/INBOX_ID/sending-policy" \
--header "Authorization: Bearer $CHERAMI_API_KEY"Responses
HTTP 200
Successful operation; inspect resource state and outcome fields.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
{
"inbox_id": "11111111-1111-4111-8111-111111111111",
"enabled": true,
"addresses": [],
"domains": [],
"revision": 0
}HTTP 401
unauthorized: Provide a valid bearer credential. Use human-approved recovery if access is lost.
X-Request-ID: Support correlation ID, not an idempotency key.WWW-Authenticate:"Bearer"
Content type: application/json.
HTTP 404
not_found: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
HTTP 500
internal_error: Operation failed; a write may already have happened. Follow the operation-specific recovery below.
X-Request-ID: Support correlation ID, not an idempotency key.
Content type: application/json.
Schema: Policy
| Field | Required | Type | Meaning and constraints |
|---|---|---|---|
inbox_id | Yes | string | Cherami resource ID, distinct from the RFC Message-ID. Use the returned value. |
enabled | Yes | boolean | |
addresses | Yes | array of string | maxItems: 100 |
domains | Yes | array of string | maxItems: 100 |
revision | Yes | integer | Zero when unconfigured. Inspection does not reserve a policy for later mail. minimum: 0 |
Schema: Error
| Field | Required | Type | Meaning and constraints |
|---|---|---|---|
error | Yes | object |
error fields
| Field | Required | Type | Meaning and constraints |
|---|---|---|---|
code | Yes | string | Programmatic error code. Handle unrecognized codes by status and operation-specific recovery. |
message | Yes | string | Human-readable context, not a stable string to match. |
HTTP conventions, errors and pagination · Download OpenAPI 3.1