PUT /v1/mail/mailboxes/{mailboxId}
Change a mailbox's size, or its send/receive switches.
Authentication
Send an API key as a bearer token. The key must carry the mail.manage permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X PUT https://api.zinndigital.com/v1/mail/mailboxes/{mailboxId} \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Every field is optional; a request that sets only `receive` leaves the size alone. **The size half is what makes the quota warning honest.** `mail.mailbox_quota_warning` tells a customer their mailbox is filling up, and until this existed the only truthful advice it could give was "delete things" — the mail backend could always resize a mailbox, but nothing exposed it (#932, #662). `quota_mb` is bounded by the **plan allowance captured on the service at purchase**, so a later plan change cannot retroactively shrink what a customer was sold. Above that sits the backend package's own ceiling; both refusals answer **422** with the same customer-facing sentence, because the customer's next action is identical either way. Requires `mail.manage`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
mailboxId (path) | Uuid | Yes | Mailbox ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
quota_mb | integer | No | New mailbox size in MB. Capped by the plan allowance captured on the service, and above that by the backend package ceiling. |
send | boolean | No | Whether the mailbox may send. |
receive | boolean | No | Whether the mailbox may receive. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
address | string | Yes | The full address. |
local | string | Yes | The part before the `@`. |
quota_mb | integer | Yes | This mailbox's size in MB. `0` means no cap. |
used_mb | integer | Yes | How much of it is used, as the mail backend last reported it (#932). Refreshed by the hourly reconcile, so it is a recent figure rather than a live one. |
percent_used | integer | Yes | How full, 0-100. Always `0` for an uncapped mailbox — a percentage of "no limit" is meaningless, not zero-ish. Read `usage_checked_at` before showing it: this is also `0` for a… |
usage_checked_at | string | No | When the backend was last asked. `null` until the first sweep sees it. |
send_enabled | boolean | Yes | — |
receive_enabled | boolean | Yes | — |
status | MailboxStatus | Yes | One mailbox's state. |
system_managed | boolean | Yes | **We** created this mailbox when the domain was provisioned; the customer did not ask for it. It is the address the site itself sends from, so `deleteMailbox` and `renameMailbox… |
created_at | string | Yes | — |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503