HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Docs
Developer API

Developer API

Authenticate requests, manage rate limits, and automate your email alias infrastructure using the AliasFleet REST API.

Updated September 4, 2026

Developer API Overview

Programmatically provision email aliases, manage custom domain routing tables, and dispatch outbound messages through the AliasFleet REST API.


Quickstart

Make your first authenticated request to verify your API key and inspect your workspace capabilities:

curl -X GET "https://api.aliasfleet.com/v1/me" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"
{
  "user": {
    "id": "usr_9f83a2c1b4d5e6f7",
    "email": "developer@company.com",
    "plan": "pro"
  },
  "auth": {
    "key_id": "key_1a2b3c4d5e6f7g8h",
    "name": "Production Worker",
    "scopes": ["*"]
  },
  "quotas": {
    "aliases_used": 14,
    "aliases_limit": 500,
    "domains_used": 2,
    "domains_limit": 10
  }
}

Core Conventions

PropertySpecification
Base URLhttps://api.aliasfleet.com
TransportTLS 1.3 required. Plain HTTP requests are rejected.
FormatJSON (Content-Type: application/json) for all request and response bodies.
AuthenticationHTTP Bearer token via Authorization: Bearer afp_... or header x-api-key.
Date FormatISO 8601 UTC strings (YYYY-MM-DDTHH:mm:ss.sssZ).

Authentication

Generate API keys in your dashboard under Settings → Developer API. All developer keys carry an afp_ prefix followed by 48 hexadecimal characters (52 characters total):

Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e

Alternatively, pass the key via the x-api-key header:

x-api-key: afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e
Important

API keys are secret credentials that grant access to your account's routing tables. Store keys in environment variables or secret management services. Never check keys into client-side bundles or public repositories.


Entity Identifiers

AliasFleet uses type-prefixed identifiers across all resources. Prefixes allow you to identify any entity at a glance:

PrefixResourceExample IdentifierLength
afp_API Key (Secret)afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e52 chars
al_Email Aliasal_6c5J5LMXd5E3Yq1Wx1zN23 chars
dest_Destination Inboxdest_adn6UTmkzn6OWpGq21 chars
dom_Custom / Shared Domaindom_bXm9kLpQr2nVwYz320 chars
rcpt_Alias Recipient Linkrcpt_x9Kl2mNopQrStUv121 chars
acat_Alias Categoryacat_cYn0mMqRs3oWxZa421 chars
bl_Denylist Rulebl_1nNrSt4pXyAb5c6d19 chars
log_Activity Audit Eventlog_7a8b9c0d1e2f3a4b20 chars

Permission Scopes

Keys can be restricted to specific functional scopes or granted full access (*):

ScopeRead OperationsWrite Operations
aliasesList aliases, inspect stats, check availabilityCreate, update, soft-delete, restore, attach recipients
domainsQuery shared domains, inspect custom domain DNSRegister domains, verify DNS, delete domains
destinationsList inboxes, inspect routing usageAdd inboxes, submit OTP verification, update sender identity
rulesList allowlists, denylists, routing rulesCreate rules, modify blocklists, delete rules
analyticsQuery delivery metrics, stream activity logsExport log archives
userInspect workspace profile and quota headroomModify account-wide from-name and fallback routing

Rate Limits & Headers

Rate limits are evaluated per API key:

Limit WindowThresholdScope
Standard Requests60 requests / minuteGeneral reading, inspection, and update operations
Alias Creation10 creations / minuteDedicated limiter on POST /v1/aliases to prevent hoarding
OTP Resend1 request / 60 secondsCooldown per destination inbox to prevent mailbox spam

Every response includes rate limit telemetry headers:

X-RateLimit-Limit: 60
X-RateLimit-Remaining: 54
X-RateLimit-Reset: 1725450000

When a rate limit is exceeded, the server returns 429 Too Many Requests with a Retry-After header:

HTTP/1.1 429 Too Many Requests
Retry-After: 12
Content-Type: application/json

{
  "error": "Rate limit exceeded. Please back off and retry.",
  "code": "RATE_LIMIT_EXCEEDED"
}

Idempotency

All mutation endpoints (POST, PATCH, DELETE) accept an optional Idempotency-Key header:

Idempotency-Key: 9b1deb4d-3b7d-4bad-9bdd-2b0d7b3dcb6d
  • Retention Window: Keys are retained for 24 hours.
  • Retry Behavior: If network disruption interrupts a request, repeating the request with the identical key returns the cached response without re-executing the operation or double-allocating quota.
  • Payload Mismatch: Submitting the same key with a different request payload returns 422 Unprocessable Entity.

Pagination

Endpoints returning collections support cursor and offset pagination:

ParameterTypeDefaultDescription
pageinteger1Page number to retrieve (1-indexed).
limitinteger20Items per page (min 1, max 100).

Pagination metadata is included in the response body:

{
  "aliases": [...],
  "pagination": {
    "page": 1,
    "limit": 20,
    "total": 42,
    "total_pages": 3,
    "has_more": true
  }
}

Error Handling

All error responses adhere to RFC 9457 Problem Details format:

{
  "error": "Cannot delete domain with active aliases. Please reassign or delete them first.",
  "code": "ALIASES_EXIST",
  "status": 400
}

Common HTTP Status Codes

StatusCodeCause & Remediation
400 Bad RequestVALIDATION_ERRORMalformed request body or invalid parameters. Check field formats.
401 UnauthorizedUNAUTHORIZEDMissing or invalid API key.
403 ForbiddenINSUFFICIENT_SCOPEToken lacks the required permission scope.
403 ForbiddenQUOTA_EXCEEDEDWorkspace plan quota reached. Upgrade tier to provision additional assets.
404 Not FoundNOT_FOUNDRequested entity does not exist or belongs to another workspace.
409 ConflictALREADY_EXISTSUnique constraint violation (e.g. alias local part or domain already taken).
429 Too Many RequestsRATE_LIMIT_EXCEEDEDRequest rate limit exceeded. Back off for the duration specified in Retry-After.

API Resource Directory

  • Identity API (/v1/me) — Token introspection, active scopes, and workspace capabilities.
  • Aliases API (/v1/aliases) — Core alias lifecycle (create, query, update, trash, and restore).
  • Alias Destinations & Batch API — Multi-destination forwarding fanout, atomic batch operations, and privacy settings.
  • Domains API (/v1/domains) — Shared platform domains, custom domain DNS verification, and safety locks.
  • Destinations API (/v1/destinations) — Inboxes, OTP verification, sender identities, and fallback routing.
  • Quick-Send API (/v1/quick-send) — Outbound anonymous email dispatch with attachment handling.
  • Sender Rules & Firewall API (/v1/sender-rules) — Inbound allowlist and denylist firewall rules, pattern matching, and edge threat protection.
  • Activity API (/v1/activity) — Audit forwarding events, delivery logs, and security blocks.
  • Fleet Analytics API (/v1/analytics) — Time-series forwarding trends, spam threat telemetry, tracker blockage, and vendor graphs.
  • Rules Engine API (/v1/rules) — Priority-ordered conditional routing rules, header evaluations, and automated actions.
  • Security & Threat Intelligence API (/v1/security) — Anomalous traffic volume spikes, threat alerts, and human-in-the-loop incident dismissal.
  • Webhooks API (/v1/webhooks) — Real-time event notifications, cryptographic HMAC-SHA256 signature verification, and delivery audit logs.

Articles in this topic

Identity & Token Introspection API

Developer API

Verify token validity, inspect active permission scopes, and retrieve account metadata using the Identity API.

2 min read
Updated Sep 4, 2026

Aliases API

Developer API

Create, list, inspect, update, and soft-delete email aliases programmatically using the AliasFleet REST API.

9 min read
Updated Sep 4, 2026

Alias Destinations & Batch Operations API

Developer API

Configure multi-destination forwarding fanout, execute atomic batch updates across up to 100 aliases, and fine-tune per-alias privacy settings.

8 min read
Updated Sep 4, 2026

Domains API

Developer API

Query shared platform domains, register custom brand domains, verify DNS records, and inspect catch-all forwarding rules.

8 min read
Updated Sep 4, 2026

Destinations API

Developer API

Register destination inboxes, execute 6-digit OTP verification challenges, configure per-channel sender identities, and manage routing fallbacks.

9 min read
Updated Sep 4, 2026

Quick-Send API

Developer API

Dispatch outbound emails through your aliases, stage attachments via presigned URLs, inspect delivery logs, and manage sender signatures.

11 min read
Updated Sep 4, 2026

Sender Rules API

Developer API

Configure inbound firewall rules to allowlist trusted contacts or block abusive senders, entire domains, and wildcard patterns.

11 min read
Updated Sep 4, 2026

Activity & Audit Logs API

Developer API

Inspect real-time email forwarding streams, query unified delivery logs, perform deep forensic X-Ray envelope analysis, and export audit trails.

6 min read
Updated Sep 4, 2026

Fleet Analytics API

Developer API

Query forwarding volumes, time-series delivery trends, spam threat telemetry, tracker blockage ratios, and vendor exposure graphs.

5 min read
Updated Sep 4, 2026

Rules Engine API

Developer API

Build priority-ordered conditional routing rules, evaluate message headers and spam metrics, and trigger automated forwarding, dropping, or webhook dispatching.

9 min read
Updated Sep 4, 2026

Security & Threat Intelligence API

Developer API

Monitor automated anomaly alerts, inspect delivery volume spikes, and review security telemetry across user email aliases.

7 min read
Updated Sep 4, 2026

Webhooks API

Developer API

Configure real-time HTTP event callbacks, verify cryptographic HMAC-SHA256 signatures, test live payloads, and inspect delivery telemetry.

12 min read
Updated Sep 4, 2026