mail

PUT /v1/mail/reseller-brand

Set the mail hostnames this reseller's mail carries.

All mail endpoints

All developer docs

Authentication

Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X PUT https://api.zinndigital.com/v1/mail/reseller-brand \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "mx_hosts": <string[]>, "spf_include": <string>, "autodiscover_host": <string>, "imap_host": <string>, "smtp_host": <string>, "webmail_host": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Requires mail.manage. Every field is a public hostname — there is no credential here, because the relay authenticates the mailbox rather than the brand. ⭐ This is what makes hosted mail sellable by a white-label reseller. With their own mx1. / imap. / smtp. / webmail. names in front of the relay, nothing published on a client's zone and nothing handed to a client's mail app carries the platform's name — so the product can be offered without the leak that previously required withholding it. ⛔ A partially-filled brand is saved and does not enable anything. configured is all-or-nothing: a brand with an MX and no webmail host would publish the reseller's MX and then send their client to somebody else's webmail, which is the leak arriving through the mechanism built to close it.

Request body

NameTypeRequiredWhat it is
namestringNoWhat the reseller calls this brand, for their own screens.
mx_hostsstring[]YesApex MX targets in priority order, on the reseller's own domain, pointed at the relay's addresses. Their names — an A record they publish, never a CNAME to ours, which would put…
spf_includestringYesThe domain in the reseller's v=spf1 include:…. A delegation, so it must be a name whose SPF record they control and which in turn includes our sender list.
autodiscover_hoststringYes
imap_hoststringYes
smtp_hoststringYes
webmail_hoststringYesWhere the reseller's client's browser goes to read mail — the single most visible name in the whole product.

Response

NameTypeRequiredWhat it is
namestringNoWhat the reseller calls this brand, for their own screens.
mx_hostsstring[]YesApex MX targets in priority order, on the reseller's own domain, pointed at the relay's addresses. Their names — an A record they publish, never a CNAME to ours, which would put…
spf_includestringYesThe domain in the reseller's v=spf1 include:…. A delegation, so it must be a name whose SPF record they control and which in turn includes our sender list.
autodiscover_hoststringYes
imap_hoststringYes
smtp_hoststringYes
webmail_hoststringYesWhere the reseller's client's browser goes to read mail — the single most visible name in the whole product.
configuredbooleanYesWhether every hostname the preset needs has been supplied. All-or-nothing: a half-set would publish the reseller's MX beside the platform's SPF include, which is a leak and a…
verified_atstringNoWhen these names were last confirmed to resolve to the relay.

Errors this endpoint can return

401 · 403 · 422 · 429