domains
POST /v1/domains/{domainId}/email-routing/enabled
Turn inbound email routing on for a domain.
Authentication
Send an API key as a bearer token. The key must carry the domains.dns.manage permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/domains/{domainId}/email-routing/enabled \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
**This can destroy a customer's inbound mail.** Enabling republishes the zone's apex `MX` and SPF, so any mail service the domain already uses stops receiving. The endpoint therefore refuses with `409 MAIL_WOULD_BE_REPLACED` when the zone carries mail records that are not the provider's own, and the override is **typed, not clicked**: `confirm_domain` must be the domain's own name. A boolean would be settable by a client that never showed the customer anything. The judgement runs on a confirmed call as well as a refused one, so the override is audit-logged with the same evidence as the refusal — otherwise the one case that actually replaced live mail would be the one case with no record of what was there. A zone that cannot be read is a refusal, never a pass. Requires `domains.dns.manage`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domainId (path) | Uuid | Yes | The domain's id. |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
confirm_domain | string | No | The domain's own name, typed. Required only when `impact.safe` is `false`. A string rather than a boolean deliberately: a boolean would be settable by a client that never showed… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
domain_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
fqdn | string | Yes | — |
supported | boolean | Yes | — |
enabled | boolean | Yes | — |
status | string | Yes | The provider's own word for the zone's state. Displayed, never branched on. |
dns_ready | boolean | Yes | Whether the provider reports the required DNS actually live. Distinct from `enabled` — a zone can be switched on with its `MX` not yet resolving. |
plan | DomainEmailRoutingDnsRecord[] | Yes | — |
rules | DomainEmailRoutingRule[] | Yes | — |
catch_all | DomainEmailRoutingRule | Yes | — |
addresses | DomainEmailRoutingAddress[] | Yes | — |
addresses_readable | boolean | Yes | `false` when the credential could not list destination addresses — a scope a customer's own token may legitimately lack. Separate from an empty `addresses` list, because an empt… |
rules_readable | boolean | Yes | `false` when the credential could not list the forwarding rules. `Zone → Email Routing Rules` is a **separate** Cloudflare permission from the one that reads the zone's routing… |
status_readable | boolean | Yes | `false` when the credential could not read the zone's routing **settings** — the half that supplies `enabled`, `status`, `dns_ready` and `plan`. On Cloudflare this is a differen… |
impact | DomainEmailRoutingImpact | Yes | What turning routing on would replace, measured against the zone's live records. |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 503