Authentication
Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.
Where your organisation id goes
This endpoint takes org_id as a field in the JSON body.
Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/mail/services \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "fqdn": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Registers the email service and requests its provisioning. Returns `201` with the service `pending`: creating the backend account and publishing the mail DNS is a durable Temporal workflow (CLAUDE.md §2.9), so poll `status` or subscribe to `mail.provisioned` / `mail.provisioning_failed`. ⛔ **Provisioning refuses to overwrite existing mail.** If the domain's apex already carries a foreign `MX`, or its zone cannot be read at all, the service ends `failed` rather than replacing records that are delivering someone's live email. That refusal is not retried — it is a decision about the customer's own domain. Requires `mail.manage`. Fails `409` when the domain already has an email service, and `422` when the plan does not include mailboxes.
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
org_id | Uuid | No | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
fqdn | string | Yes | The domain to set email up on. |
domain_id | Uuid | null | No | — |
provider | MailProvider | No | Who runs the mailboxes for this domain. Defaults to `zinn` — our own email. `google_workspace` and `microsoft_365` publish that provider's own MX, SPF, DKIM and autodiscover rec… |
provider_config | MailProviderConfig | null | No | The `custom` provider's values. Required in effect for `custom`; ignored otherwise. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
fqdn | string | Yes | The domain the mailboxes are on. |
provider_config | MailProviderConfig | null | No | The `custom` provider's declared values, served back so the domain screen can show and edit what was declared. `null` on every other provider, whose values are documented and de… |
site | MailServiceSite | null | No | The site currently serving this domain, or `null` when no site does. **Derived from the hostname, never stored**: mail attaches to a domain and a domain outlives the site on it,… |
mailbox_provisioning | MailboxProvisioning | Yes | Whether **we** pre-create a starter mailbox on this domain. `managed` — we make one when the domain is provisioned (the Footprint-Free/PBN line and our own fleet); `self_service… |
mail_only | boolean | Yes | **This domain uses us for mail and nothing else** — an active mail service on a hostname no website of ours serves. Published as one server-side answer because more than one con… |
domain_id | Uuid | null | No | The registered domain this serves, when we hold the registration. |
status | MailServiceStatus | Yes | A mail service's lifecycle state. |
provider | MailProvider | Yes | Which provider serves a domain's mail. `custom` is **the reseller's own provider** (W40-MAIL, owner ruling 2026-09-06): a white-label reseller sells mail they buy elsewhere, dec… |
mailbox_quota_mb | integer | Yes | Size of each mailbox in MB, captured when the service was created. |
mailbox_limit | integer | Yes | Mailboxes allowed on this domain; `-1` is uncapped. Captured when the service was created; a later downgrade is enforced against the live plan as well, so the number actually ap… |
mailboxes_used | integer | Yes | How many mailboxes currently consume the allowance. |
dns_applied_at | object | No | When the mail DNS was last published. `null` means never — mailboxes that exist but receive nothing, which is the one state a customer must be told about. |
created_at | string | Yes | — |
Errors this endpoint can return
401 · 403 · 409 · 422 · 429