Limit an inbox’s recipients
Choose the addresses and domains an inbox may email, with rules only you can change.
Read as Markdown ↗Open Account → Sending rules, select an inbox, and enter its allowed recipients in the Email addresses and Domains tabs, one entry per line. Turn on Restrict recipients, then save. Every agent using that inbox must follow the same rules, whether connected through HTTP or MCP.
With restrictions on, every To, Cc and Bcc recipient must match either an exact address or an exact domain. One nonmatching recipient blocks the entire send, including replies, reply-all and forwards. No recipients are silently removed. Both lists empty with restrictions on blocks all sending from that inbox.
Turn restrictions off to allow any destination under Cherami’s ordinary sending permissions and policies. Turning them off keeps both saved lists. Changes take effect when saved, but do not cancel sends already authorized. Reload saved rules if a change could not be confirmed or another browser session edited them.
Enter exact addresses
Use bare ASCII email addresses, without display names or wildcard patterns. You can save up to 100 addresses. Surrounding whitespace and duplicates are removed, and domain names are lowercased.
The part before @ is case-sensitive. Alex@example.com and alex@example.com are different rules. Domain case does not matter: alex@EXAMPLE.COM matches alex@example.com. Plus tags and dots remain distinct even if a particular provider delivers those variations to the same mailbox.
Enter exact domains
Use bare ASCII domains, such as example.com, or punycode for internationalized domains, such as xn--bcher-kva.de. Raw Unicode, URLs, email addresses and wildcard patterns are not accepted in the Domains tab. You can save up to 100 domains independently of the 100-address limit. Surrounding whitespace and duplicates are removed, and domains are lowercased.
Domain matching is exact: example.com allows addresses at that domain, not at sub.example.com or notexample.com. Add each subdomain separately when needed. Switching tabs keeps your unsaved entries; Save rules saves both lists and the restriction setting together.
Allowing an address or domain is not recipient consent and does not approve the message’s content. Ordinary permissions, allowance, provider suppression and permitted sending still apply.
Let the agent inspect the rules
Agents can use get_sending_policy over MCP or read the policy over HTTP. They cannot change it using mail credentials. Ask the human to review a blocked destination rather than changing inboxes to bypass the restriction.
recipient_not_allowed means the new attempt was blocked before submission and consumed no recipient allowance. Its message identifies the blocked destinations. A retry of an existing keyed attempt returns that earlier attempt, even if rules have since changed; it does not send again or claim the earlier email was blocked.
Rules belong to the selected inbox, not the whole account. Existing and newly created inboxes start unrestricted. Other inboxes remain accessible to the same account’s agents, and inbox creation is still available when slots permit. This feature is not account-wide isolation or automatic abuse detection. For content checks against harmful or abusive correspondence, see advanced mail protection.