認証
ベアラー トークンとして API キーを送信します。キーには mail.view 権限が付与されている必要があります。権限のないキーは 404 ではなく 403 で拒否されます。
組織 ID を入力する場所
このエンドポイントはクエリパラメータとして org_id を受け取ります。省略した場合はテナントサブツリー全体が対象になり、指定した場合は特定の組織のみに絞り込まれます。
組織IDは、ダッシュボードのAPIキー画面にキーのすぐ横に表示されています。これは、実行するすべての呼び出しで同じIDになります。
試してみる
アングルブラケット内のすべてをご自身の値に置き換え、キーのプレースホルダーをご利用中のダッシュボードのキーに置き換えてください。
curl -X GET https://api.zinndigital.com/v1/mail/preflight?fqdn=<fqdn> \
-H "Authorization: Bearer zdk_live_…"ログインしていますか?ダッシュボード内のAPIコンソールでは、実際の組織IDやお客様ご自身のキーが自動入力され、ライブAPIに対してリクエストが実行されるため、実際のレスポンスを確認することができます。 API コンソールでこのエンドポイントを開く
詳細
Read-only. Answers **before the customer commits** whether this domain can take our mail records, and exactly what publishing them would remove (#662). Setting mail up rewrites the domain's apex `MX`. If the domain already receives email somewhere else, that stops inbound mail reaching the mailboxes it is addressed to — an outage the customer usually learns about from the people who could not reach them. Without this endpoint the only way to discover the refusal was to create a service and watch it fail asynchronously, which is a refusal arriving *after* the decision. `safe: false` means `POST /v1/mail/services` will refuse unless it is called with the override flag. `foreign_mx` and `would_delete` are listed **verbatim**, not counted, because a customer must be able to see what they are about to destroy before confirming it. `zone_unreadable: true` is **never** `safe`: there is no DNS resolver in the platform, so "we could not read the zone" is the normal answer for a domain whose DNS is hosted elsewhere, and treating that as safe would disable the guard exactly where it matters most. ⚠️ A safe answer is not a promise — the zone can change between this call and the apply, so provisioning repeats the check inside its workflow. Requires `mail.view`.
パラメータ
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
fqdn (query) | string | はい | The domain to check. |
provider (query) | MailProvider | いいえ | Which provider's records to test against; defaults to our own mail. The answer differs per provider, because each preset publishes a different record set. |
mx_hosts (query) | string | いいえ | `custom` only: the MX targets the reseller has typed so far, comma-separated. The preflight compares the zone with the records the preset **would** publish, and for a provider w… |
org_id (query) | Uuid | いいえ | The organization to act in; defaults to the caller's own when unambiguous. |
返信
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
domain | string | はい | The domain that was checked, normalised. |
safe | boolean | はい | Whether an apply would proceed without the override flag. `false` means `POST /v1/mail/services` returns 409 unless the customer confirms. |
existing_apex_mx | string[] | はい | Every apex `MX` currently published, in the order DNS returned them. |
foreign_mx | string[] | はい | The apex `MX` targets that are not ours to replace — the reason for a refusal, and the list the customer must see before confirming an override. |
foreign_spf_includes | string[] | はい | `include:` mechanisms in the current SPF that the new record would drop. |
would_delete | string[] | はい | Records the apply would remove or replace, as `"NAME TYPE VALUE"`. |
zone_unreadable | boolean | はい | The zone could not be read at all — never `safe`. Distinct from "read it, found nothing", because the two need different copy: one is "we cannot see your DNS", the other is "you… |
reason | string | はい | Customer-grade English describing what was found. Empty when safe. |
warnings | string[] | はい | Non-blocking observations about the zone. |
このエンドポイントが返すエラー
401 · 403 · 422 · 429 · 503