mail

POST /v1/mail/mailboxes/{mailboxId}/rename

Change a mailbox's address, keeping the mail in it.

All mail endpoints

Authentication

Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/mail/mailboxes/{mailboxId}/rename \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "local": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Changes the local part — `sales@example.com` becomes `hello@example.com` — with every message already in the mailbox intact. ⚖️ Part of the owner's 2026-08-16 ruling that a domain owner must be able to *"create the mailboxes easily and manage them in full"*. **A POST to a sub-resource rather than a field on `updateMailbox`, deliberately.** A rename moves where mail is delivered; a quota edit does not. Sharing a body would let a mistyped field change a customer's address as a side effect of resizing their mailbox, and would make the two indistinguishable in the audit log. ⛔ **The engine reads the mailbox back from the backend and refuses if the address did not actually change**, rather than trusting the backend's success response. It never falls back to create-then-delete: that would "work" on screen and silently destroy every stored message. `409` when the target address already exists on the domain; `422` for a mailbox that has not finished provisioning, and for the `system_managed` address the site sends from. Requires `mail.manage`.

Parameters

NameTypeRequiredWhat it is
mailboxId (path)UuidYesMailbox ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
localstringYesThe new part before the `@`. Lower-cased and trimmed by the engine.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
addressstringYesThe full address.
localstringYesThe part before the `@`.
quota_mbintegerYesThis mailbox's size in MB. `0` means no cap.
used_mbintegerYesHow much of it is used, as the mail backend last reported it (#932). Refreshed by the hourly reconcile, so it is a recent figure rather than a live one.
percent_usedintegerYesHow full, 0-100. Always `0` for an uncapped mailbox — a percentage of "no limit" is meaningless, not zero-ish. Read `usage_checked_at` before showing it: this is also `0` for a…
usage_checked_atstringNoWhen the backend was last asked. `null` until the first sweep sees it.
send_enabledbooleanYes
receive_enabledbooleanYes
statusMailboxStatusYesOne mailbox's state.
system_managedbooleanYes**We** created this mailbox when the domain was provisioned; the customer did not ask for it. It is the address the site itself sends from, so `deleteMailbox` and `renameMailbox…
created_atstringYes

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503