Authentication
Send an API key as a bearer token. The key must carry the mail.view permission; a key without it is refused with 403, not 404.
Where your organisation id goes
This endpoint takes org_id as a query parameter. Leave it out and the call covers your whole tenancy subtree; send it to narrow the call to one organisation.
Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/mail/preflight?fqdn=<fqdn> \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Read-only. Answers **before the customer commits** whether this domain can take our mail records, and exactly what publishing them would remove (#662). Setting mail up rewrites the domain's apex `MX`. If the domain already receives email somewhere else, that stops inbound mail reaching the mailboxes it is addressed to — an outage the customer usually learns about from the people who could not reach them. Without this endpoint the only way to discover the refusal was to create a service and watch it fail asynchronously, which is a refusal arriving *after* the decision. `safe: false` means `POST /v1/mail/services` will refuse unless it is called with the override flag. `foreign_mx` and `would_delete` are listed **verbatim**, not counted, because a customer must be able to see what they are about to destroy before confirming it. `zone_unreadable: true` is **never** `safe`: there is no DNS resolver in the platform, so "we could not read the zone" is the normal answer for a domain whose DNS is hosted elsewhere, and treating that as safe would disable the guard exactly where it matters most. ⚠️ A safe answer is not a promise — the zone can change between this call and the apply, so provisioning repeats the check inside its workflow. Requires `mail.view`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
fqdn (query) | string | Yes | The domain to check. |
provider (query) | MailProvider | No | Which provider's records to test against; defaults to our own mail. The answer differs per provider, because each preset publishes a different record set. |
mx_hosts (query) | string | No | `custom` only: the MX targets the reseller has typed so far, comma-separated. The preflight compares the zone with the records the preset **would** publish, and for a provider w… |
org_id (query) | Uuid | No | The organization to act in; defaults to the caller's own when unambiguous. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
domain | string | Yes | The domain that was checked, normalised. |
safe | boolean | Yes | Whether an apply would proceed without the override flag. `false` means `POST /v1/mail/services` returns 409 unless the customer confirms. |
existing_apex_mx | string[] | Yes | Every apex `MX` currently published, in the order DNS returned them. |
foreign_mx | string[] | Yes | The apex `MX` targets that are not ours to replace — the reason for a refusal, and the list the customer must see before confirming an override. |
foreign_spf_includes | string[] | Yes | `include:` mechanisms in the current SPF that the new record would drop. |
would_delete | string[] | Yes | Records the apply would remove or replace, as `"NAME TYPE VALUE"`. |
zone_unreadable | boolean | Yes | The zone could not be read at all — never `safe`. Distinct from "read it, found nothing", because the two need different copy: one is "we cannot see your DNS", the other is "you… |
reason | string | Yes | Customer-grade English describing what was found. Empty when safe. |
warnings | string[] | Yes | Non-blocking observations about the zone. |
Errors this endpoint can return
401 · 403 · 422 · 429 · 503