POST /v1/mail/mailboxes/{mailboxId}/rename
Change a mailbox's address, keeping the mail in it.
Authentication
Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/mail/mailboxes/{mailboxId}/rename \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "local": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Changes the local part — `sales@example.com` becomes `hello@example.com` — with every message already in the mailbox intact. ⚖️ Part of the owner's 2026-08-16 ruling that a domain owner must be able to *"create the mailboxes easily and manage them in full"*. **A POST to a sub-resource rather than a field on `updateMailbox`, deliberately.** A rename moves where mail is delivered; a quota edit does not. Sharing a body would let a mistyped field change a customer's address as a side effect of resizing their mailbox, and would make the two indistinguishable in the audit log. ⛔ **The engine reads the mailbox back from the backend and refuses if the address did not actually change**, rather than trusting the backend's success response. It never falls back to create-then-delete: that would "work" on screen and silently destroy every stored message. `409` when the target address already exists on the domain; `422` for a mailbox that has not finished provisioning, and for the `system_managed` address the site sends from. Requires `mail.manage`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
mailboxId (path) | Uuid | Yes | Mailbox ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
local | string | Yes | The new part before the `@`. Lower-cased and trimmed by the engine. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
address | string | Yes | The full address. |
local | string | Yes | The part before the `@`. |
quota_mb | integer | Yes | This mailbox's size in MB. `0` means no cap. |
used_mb | integer | Yes | How much of it is used, as the mail backend last reported it (#932). Refreshed by the hourly reconcile, so it is a recent figure rather than a live one. |
percent_used | integer | Yes | How full, 0-100. Always `0` for an uncapped mailbox — a percentage of "no limit" is meaningless, not zero-ish. Read `usage_checked_at` before showing it: this is also `0` for a… |
usage_checked_at | string | No | When the backend was last asked. `null` until the first sweep sees it. |
send_enabled | boolean | Yes | — |
receive_enabled | boolean | Yes | — |
status | MailboxStatus | Yes | One mailbox's state. |
system_managed | boolean | Yes | **We** created this mailbox when the domain was provisioned; the customer did not ask for it. It is the address the site itself sends from, so `deleteMailbox` and `renameMailbox… |
created_at | string | Yes | — |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 503