HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Developer API
Docs
Developer API
Activity & Audit Logs API

Activity & Audit Logs API

Inspect real-time email forwarding streams, query unified delivery logs, perform deep forensic X-Ray envelope analysis, and export audit trails.

6 min read
Updated September 4, 2026

Stream real-time forwarding events, query paginated delivery logs, perform deep forensic X-Ray envelope analysis, and export compliance audit trails.


Quick Reference

EndpointMethodScopePurpose
/v1/activityGETactivity:readRetrieve unified dashboard activity feed
/v1/activity/logsGETactivity:readQuery paginated email delivery events with search filters
/v1/activity/logs/:id/xrayGETactivity:readInspect deep envelope telemetry and forensic diagnostics
/v1/activity/logs/exportGETactivity:readStream audit logs in CSV or JSON format
/v1/activity/retentionGETactivity:readInspect log retention boundaries and expiring event counts
/v1/activity/anonymizationGETactivity:readInspect automated privacy anonymization settings

Log Architecture & Privacy Protection

AliasFleet records operational metadata required for delivery troubleshooting while adhering to zero-knowledge privacy guarantees:

  1. Envelope vs. Payload Separation: The log engine captures envelope routing metadata (sender, recipient alias, destination, spam scores, authentication verdicts, tracker count) but never stores the raw message bodies of forwarded emails.
  2. Tracker Stripping Telemetry: When tracker blocking is active, the engine increments tracker counts and records detected tracker domains without logging user interaction behavior.
  3. Forensic X-Ray: Detailed email headers, originating MTA IP addresses, and cryptographic signature validations (SPF, DKIM, DMARC) are available on demand for diagnostics through the X-Ray endpoint.

GET /v1/activity — Retrieve Activity Feed

Scope: activity:read · Rate Limit: 60/min · Idempotent: Yes

Returns recent workspace activity events in reverse chronological order, including forwarding actions, bounce detections, and security events.

Query Parameters

ParameterTypeRequiredDefaultDescription
limitintegerOptional10Maximum number of activity records to return (max 100).

Example Request

curl -X GET "https://api.aliasfleet.com/v1/activity?limit=2" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "activities": [
    {
      "id": "email-evt_7f8a9b0c1d2e",
      "type": "email_forwarded",
      "title": "Email Forwarded",
      "description": "Forwarded message from billing@saas-provider.com to inbox",
      "timestamp": "2026-09-04T12:45:00.000Z",
      "metadata": {
        "aliasName": "subscriptions@acme-corp.com",
        "email": "billing@saas-provider.com"
      }
    },
    {
      "id": "act_8a9b0c1d2e3f4a5b",
      "type": "sender_blocked",
      "title": "Sender Blocked",
      "description": "Added scamnetwork.xyz to denylist",
      "timestamp": "2026-09-04T12:20:00.000Z",
      "metadata": {
        "sender": "scamnetwork.xyz"
      }
    }
  ]
}

GET /v1/activity/logs — Query Delivery Logs

Scope: activity:read · Rate Limit: 60/min · Idempotent: Yes

Queries unified inbound and outbound email delivery events with support for full-text search, event type filtering, date windowing, and pagination.

Query Parameters

ParameterTypeRequiredDefaultDescription
pageintegerOptional1Page number for pagination.
limitintegerOptional50Results per page (max 100).
typestringOptional—Event type filter: forwarded, bounced, blocked, sent, or quick_send.
aliasIdstringOptional—Filter events to a specific alias ID (al_...).
searchstringOptional—Substring search across sender, recipient, subject, or alias.
startDatestringOptional—ISO 8601 start date timestamp (e.g. 2026-09-01T00:00:00Z).
endDatestringOptional—ISO 8601 end date timestamp.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/activity/logs?page=1&limit=1&type=forwarded" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "logs": [
    {
      "id": "evt_9a8b7c6d5e4f3a2b",
      "type": "forwarded",
      "sender_email": "notifications@vendor.com",
      "sender_name": "Vendor Operations",
      "recipient_email": "inbox@primary-domain.com",
      "subject": "System Status Alert: Maintenance Window",
      "message_id": "<9f8e7d6c-5b4a-3a2b@vendor.com>",
      "created_at": "2026-09-04T12:40:00.000Z",
      "expires_at": "2026-10-04T12:40:00.000Z",
      "bounced": false,
      "spam_score": 0.2,
      "trackers_blocked_count": 3,
      "tracker_domains": ["tracking.pixel.com", "analytics.mail.net"],
      "security_status": {
        "spf": "pass",
        "dkim": "pass",
        "dmarc": "pass"
      },
      "ip_address": "198.51.100.42",
      "country_code": "US",
      "is_catchall_virtual": false,
      "alias_id": "al_6c5J5LMXd5E3Yq1Wx1zN",
      "alias_local_part": "vendor-alerts",
      "alias_domain": "acme-corp.com",
      "category_prediction": "transactional"
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 1,
    "total": 1420,
    "totalPages": 1420
  },
  "retention": {
    "retentionDays": 30,
    "planRetention": 30,
    "logsCount": 1420
  }
}

GET /v1/activity/logs/:id/xray — Inspect Forensic X-Ray

Scope: activity:read · Rate Limit: 60/min · Idempotent: Yes

Retrieves deep diagnostic telemetry for a specific delivery event, including cryptographic authentication checks (SPF, DKIM, DMARC), blocked spy pixels and tracking domains, and transit hops.

Path Parameters

ParameterTypeRequiredDescription
idstringYesEvent identifier (evt_...).

Example Request

curl -X GET "https://api.aliasfleet.com/v1/activity/logs/evt_9a8b7c6d5e4f3a2b/xray" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "success": true,
  "telemetry": {
    "id": "evt_9a8b7c6d5e4f3a2b",
    "type": "forwarded",
    "alias": "vendor-alerts@acme-corp.com",
    "aliasId": "al_6c5J5LMXd5E3Yq1Wx1zN",
    "sender": "notifications@vendor.com",
    "senderName": "Vendor Operations",
    "recipient": "inbox@primary-domain.com",
    "subject": "System Status Alert: Maintenance Window",
    "messageId": "<9f8e7d6c-5b4a-3a2b@vendor.com>",
    "bounced": false,
    "timestamp": "2026-09-04T12:40:00.000Z",
    "expiresAt": "2026-10-04T12:40:00.000Z",
    "spamScore": 0.2,
    "trackersBlockedCount": 3,
    "trackerDomains": [
      "tracking.pixel.com",
      "analytics.mail.net"
    ],
    "headers": {
      "x-mailer": "VendorMailer v4.2",
      "content-type": "text/html; charset=UTF-8"
    },
    "securityStatus": {
      "spf": "pass",
      "dkim": "pass",
      "dmarc": "pass"
    },
    "ipAddress": "198.51.100.42",
    "countryCode": "US",
    "isCatchallVirtual": false,
    "localPart": "vendor-alerts",
    "domain": "acme-corp.com",
    "categoryPrediction": "transactional"
  }
}

Errors

StatusCodeCause & Resolution
404 Not FoundNOT_FOUNDDelivery log record does not exist or has exceeded retention cutoff.

GET /v1/activity/logs/export — Export Audit Logs

Scope: activity:read · Rate Limit: 10/min · Idempotent: Yes

Exports complete email delivery and audit logs for your workspace in structured JSON or CSV format for compliance archival and SIEM ingestion.

Query Parameters

ParameterTypeRequiredDefaultDescription
formatstringOptionaljsonDesired output format: json or csv.

Example Request: Export CSV

curl -X GET "https://api.aliasfleet.com/v1/activity/logs/export?format=csv" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -o "aliasfleet-audit-logs.csv"

Response Headers (200 OK)

HTTP/1.1 200 OK
Content-Type: text/csv
Content-Disposition: attachment; filename="aliasfleet-logs-2026-09-04.csv"

GET /v1/activity/retention — Inspect Log Retention

Scope: activity:read · Rate Limit: 60/min · Idempotent: Yes

Returns the active log retention window, oldest and newest log timestamps, and counts of log records scheduled for deletion.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/activity/retention" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "success": true,
  "retention": {
    "currentPlan": "business",
    "effectiveDays": 90,
    "planDays": 90,
    "isGracePeriod": false,
    "graceEndsAt": null,
    "logsCount": 4250,
    "oldestLog": "2026-06-06T10:15:00.000Z",
    "newestLog": "2026-09-04T12:45:00.000Z"
  },
  "expiring": {
    "expiringSoonCount": 18,
    "windowDays": 3
  }
}

GET /v1/activity/anonymization — Inspect Anonymization Settings

Scope: activity:read · Rate Limit: 60/min · Idempotent: Yes

Retrieves the automated privacy anonymization policy configured for your workspace. When enabled, historical sender and recipient addresses are masked after a specified aging period.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/activity/anonymization" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "success": true,
  "anonymization": {
    "enabled": true,
    "afterDays": 30,
    "totalAnonymized": 312
  }
}

Frequently Asked Questions

What events are recorded in the activity log stream?

The stream captures inbound email forwarding, rejected messages from blocked senders, delivery bounces, tracker strip events, and administrative security changes.

How long are activity and delivery logs retained?

Retention windows depend on your workspace plan tier (from 7 days on Starter up to 365 days or custom retention on Business and Enterprise tiers).

What forensic data does the X-Ray endpoint provide?

The X-Ray endpoint provides deep diagnostic metadata including SPF/DKIM/DMARC authentication verdicts, blocked tracker domains, MTA origin IPs, spam scores, and sanitized headers.

Can I export audit logs for external SIEM integration?

Yes. You can stream or download complete audit history in either structured JSON or RFC 4180 CSV format using GET /v1/activity/logs/export.

Was this article helpful?

Related articles

Identity & Token Introspection API

Verify token validity, inspect active permission scopes, and retrieve account metadata using the Identity API.

Aliases API

Create, list, inspect, update, and soft-delete email aliases programmatically using the AliasFleet REST API.

Alias Destinations & Batch Operations API

Configure multi-destination forwarding fanout, execute atomic batch updates across up to 100 aliases, and fine-tune per-alias privacy settings.

Domains API

Query shared platform domains, register custom brand domains, verify DNS records, and inspect catch-all forwarding rules.

Destinations API

Register destination inboxes, execute 6-digit OTP verification challenges, configure per-channel sender identities, and manage routing fallbacks.

Content

Quick ReferenceLog Architecture & Privacy ProtectionGET /v1/activity — Retrieve Activity FeedQuery ParametersExample RequestResponse (`200 OK`)GET /v1/activity/logs — Query Delivery LogsQuery ParametersExample RequestResponse (`200 OK`)GET /v1/activity/logs/:id/xray — Inspect Forensic X-RayPath ParametersExample RequestResponse (`200 OK`)ErrorsGET /v1/activity/logs/export — Export Audit LogsQuery ParametersExample Request: Export CSVResponse Headers (`200 OK`)GET /v1/activity/retention — Inspect Log RetentionExample RequestResponse (`200 OK`)GET /v1/activity/anonymization — Inspect Anonymization SettingsExample RequestResponse (`200 OK`)

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket