mail

POST /v1/mail/services

Set email up on a domain.

All mail endpoints

Authentication

Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.

Where your organisation id goes

This endpoint takes org_id as a field in the JSON body.

Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/mail/services \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "fqdn": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Registers the email service and requests its provisioning. Returns `201` with the service `pending`: creating the backend account and publishing the mail DNS is a durable Temporal workflow (CLAUDE.md §2.9), so poll `status` or subscribe to `mail.provisioned` / `mail.provisioning_failed`. ⛔ **Provisioning refuses to overwrite existing mail.** If the domain's apex already carries a foreign `MX`, or its zone cannot be read at all, the service ends `failed` rather than replacing records that are delivering someone's live email. That refusal is not retried — it is a decision about the customer's own domain. Requires `mail.manage`. Fails `409` when the domain already has an email service, and `422` when the plan does not include mailboxes.

Request body

NameTypeRequiredWhat it is
org_idUuidNoUUIDv7 identifier — sortable by creation time (docs/02 §8).
fqdnstringYesThe domain to set email up on.
domain_idUuid | nullNo
providerMailProviderNoWho runs the mailboxes for this domain. Defaults to `zinn` — our own email. `google_workspace` and `microsoft_365` publish that provider's own MX, SPF, DKIM and autodiscover rec…
provider_configMailProviderConfig | nullNoThe `custom` provider's values. Required in effect for `custom`; ignored otherwise.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
fqdnstringYesThe domain the mailboxes are on.
provider_configMailProviderConfig | nullNoThe `custom` provider's declared values, served back so the domain screen can show and edit what was declared. `null` on every other provider, whose values are documented and de…
siteMailServiceSite | nullNoThe site currently serving this domain, or `null` when no site does. **Derived from the hostname, never stored**: mail attaches to a domain and a domain outlives the site on it,…
mailbox_provisioningMailboxProvisioningYesWhether **we** pre-create a starter mailbox on this domain. `managed` — we make one when the domain is provisioned (the Footprint-Free/PBN line and our own fleet); `self_service…
mail_onlybooleanYes**This domain uses us for mail and nothing else** — an active mail service on a hostname no website of ours serves. Published as one server-side answer because more than one con…
domain_idUuid | nullNoThe registered domain this serves, when we hold the registration.
statusMailServiceStatusYesA mail service's lifecycle state.
providerMailProviderYesWhich provider serves a domain's mail. `custom` is **the reseller's own provider** (W40-MAIL, owner ruling 2026-09-06): a white-label reseller sells mail they buy elsewhere, dec…
mailbox_quota_mbintegerYesSize of each mailbox in MB, captured when the service was created.
mailbox_limitintegerYesMailboxes allowed on this domain; `-1` is uncapped. Captured when the service was created; a later downgrade is enforced against the live plan as well, so the number actually ap…
mailboxes_usedintegerYesHow many mailboxes currently consume the allowance.
dns_applied_atobjectNoWhen the mail DNS was last published. `null` means never — mailboxes that exist but receive nothing, which is the one state a customer must be told about.
created_atstringYes

Errors this endpoint can return

401 · 403 · 409 · 422 · 429