HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Developer API
Docs
Developer API
Sender Rules API

Sender Rules API

Configure inbound firewall rules to allowlist trusted contacts or block abusive senders, entire domains, and wildcard patterns.

11 min read
Updated September 4, 2026

Configure inbound email firewall rules to allowlist trusted senders or reject unwanted addresses, full domains, and wildcard patterns at the network edge.


Quick Reference

EndpointMethodScopePurpose
/v1/sender-rules/whitelistGETsender_rules:readList configured allowed sender rules
/v1/sender-rules/whitelistPOSTsender_rules:writeCreate an allowlist rule for an address, domain, or pattern
/v1/sender-rules/whitelistPATCHsender_rules:writeToggle or update an allowlist rule
/v1/sender-rules/whitelistDELETEsender_rules:writeDelete an allowlist rule
/v1/sender-rules/whitelist/statsGETsender_rules:readRetrieve allowlist volume and monthly trend metrics
/v1/sender-rules/blacklistGETsender_rules:readList configured blocked sender rules
/v1/sender-rules/blacklistPOSTsender_rules:writeCreate a denylist rule to reject senders or domains
/v1/sender-rules/blacklistPATCHsender_rules:writeToggle or update a denylist rule
/v1/sender-rules/blacklistDELETEsender_rules:writeDelete a denylist rule
/v1/sender-rules/blacklist/statsGETsender_rules:readRetrieve blocked volume and monthly trend metrics

Inbound Firewall Architecture

The AliasFleet Inbound Firewall evaluates incoming messages at the earliest possible stage of the email delivery pipeline:

  1. Edge Rejection: When an inbound SMTP transaction arrives from a blocked sender or domain, the firewall terminates the session during the MAIL FROM envelope handshake with an RFC 5321 550 5.7.1 permanent failure code. The message body is never accepted or stored.
  2. Mutual Exclusivity Invariant: A sender pattern cannot exist on both your allowlist and your denylist. If you attempt to allow an address that is currently blocked, the API rejects the request with CROSS_TABLE_CONFLICT.
  3. Pattern Matching Hierarchy:
    • Exact: Matches specific email addresses (spammer@example.com).
    • Domain: Matches all senders under a domain (badcompany.com), with optional recursive subdomain coverage (includeSubdomains: true).
    • Pattern: Advanced wildcard matching (*@promo.*.com, alert*@monitoring.internal).

GET /v1/sender-rules/whitelist — List Allowed Sender Rules

Scope: sender_rules:read · Rate Limit: 60/min · Idempotent: Yes

Returns a paginated list of allowed sender rules configured for your workspace.

Query Parameters

ParameterTypeRequiredDefaultDescription
pageintegerOptional1Page number for pagination.
limitintegerOptional50Number of records per page (max 100).
searchstringOptional—Case-insensitive filter on email_pattern.
includeGlobalbooleanOptionalfalseWhen true, includes platform-wide system rules alongside workspace rules.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/sender-rules/whitelist?page=1&limit=2" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "entries": [
    {
      "id": "7c8d9e0f-1a2b-3c4d-5e6f-7a8b9c0d1e2f",
      "user_id": "usr_9f8e7d6c5b4a3a2b",
      "email_pattern": "vip-notifications@partner.com",
      "pattern_type": "exact",
      "include_subdomains": false,
      "reason": "Critical billing and invoice updates",
      "source": "manual",
      "is_active": true,
      "allowed_count": 48,
      "created_at": "2026-08-20T10:00:00.000Z",
      "updated_at": "2026-08-20T10:00:00.000Z"
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 2,
    "total": 1,
    "totalPages": 1
  }
}

POST /v1/sender-rules/whitelist — Create Allowed Sender Rule

Scope: sender_rules:write · Rate Limit: 30/min · Idempotent: Yes

Adds a sender address, domain, or wildcard pattern to your inbound allowlist.

Request Body Parameters

ParameterTypeRequiredConstraintsDescription
emailPatternstringYes1–255 charsEmail (user@domain.com), domain (partner.com), or wildcard pattern (*@*.corp.com).
patternTypestringOptionalexact, domain, patternPattern evaluation strategy. Defaults to exact.
includeSubdomainsbooleanOptionalBooleanWhen true with patternType: "domain", matches subdomains (e.g. *.partner.com).
reasonstringOptionalMax 255 charsContextual note explaining why the sender is allowlisted.
sourcestringOptionalMax 50 charsOrigin tag: manual, quick_action, or api. Defaults to manual.

Example Request

curl -X POST "https://api.aliasfleet.com/v1/sender-rules/whitelist" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Content-Type: application/json" \
  -d '{
    "emailPattern": "partner-network.com",
    "patternType": "domain",
    "includeSubdomains": true,
    "reason": "Authorized B2B syndication partner"
  }'

Response (201 Created)

{
  "success": true,
  "entry": {
    "id": "3a4b5c6d-7e8f-9a0b-1c2d-3e4f5a6b7c8d",
    "user_id": "usr_9f8e7d6c5b4a3a2b",
    "email_pattern": "partner-network.com",
    "pattern_type": "domain",
    "include_subdomains": true,
    "reason": "Authorized B2B syndication partner",
    "source": "manual",
    "is_active": true,
    "allowed_count": 0,
    "created_at": "2026-09-04T12:00:00.000Z",
    "updated_at": "2026-09-04T12:00:00.000Z"
  },
  "message": "partner-network.com has been added to the allowlist"
}

Errors

StatusCodeCause & Resolution
400 Bad RequestINVALID_PATTERNThe emailPattern string is malformed or invalid syntax.
402 Payment RequiredENTITLEMENT_REQUIREDDomain and wildcard rules require a Pro or Business plan.
409 ConflictCROSS_TABLE_CONFLICTThe pattern already exists on your denylist (blacklist). Remove it from the denylist first.
409 ConflictALREADY_EXISTSThe pattern is already present on your allowlist.

PATCH /v1/sender-rules/whitelist — Update Allowed Sender Rule

Scope: sender_rules:write · Rate Limit: 60/min · Idempotent: Yes

Toggles the active state or updates the description metadata for an existing allowlist rule.

Request Body Parameters

ParameterTypeRequiredConstraintsDescription
idstringYesRule UUIDUnique identifier of the rule to modify.
isActivebooleanOptionalBooleanActivates or pauses rule enforcement.
reasonstringOptionalMax 255 charsUpdated note or rationale.
includeSubdomainsbooleanOptionalBooleanWhether domain matching extends to subdomains.

Example Request

curl -X PATCH "https://api.aliasfleet.com/v1/sender-rules/whitelist" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "3a4b5c6d-7e8f-9a0b-1c2d-3e4f5a6b7c8d",
    "isActive": false,
    "reason": "Temporarily disabled during vendor security audit"
  }'

Response (200 OK)

{
  "success": true,
  "entry": {
    "id": "3a4b5c6d-7e8f-9a0b-1c2d-3e4f5a6b7c8d",
    "user_id": "usr_9f8e7d6c5b4a3a2b",
    "email_pattern": "partner-network.com",
    "pattern_type": "domain",
    "include_subdomains": true,
    "reason": "Temporarily disabled during vendor security audit",
    "source": "manual",
    "is_active": false,
    "allowed_count": 12,
    "created_at": "2026-09-04T12:00:00.000Z",
    "updated_at": "2026-09-04T12:15:00.000Z"
  }
}

DELETE /v1/sender-rules/whitelist — Delete Allowed Sender Rule

Scope: sender_rules:write · Rate Limit: 60/min · Idempotent: Yes

Permanently deletes an allowlist rule from your workspace.

Query Parameters

ParameterTypeRequiredDescription
idstringYesUnique identifier of the allowlist rule to delete.

Example Request

curl -X DELETE "https://api.aliasfleet.com/v1/sender-rules/whitelist?id=3a4b5c6d-7e8f-9a0b-1c2d-3e4f5a6b7c8d" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e"

Response (200 OK)

{
  "success": true,
  "message": "Removed from whitelist"
}

GET /v1/sender-rules/whitelist/stats — Allowlist Metrics & Trends

Scope: sender_rules:read · Rate Limit: 60/min · Idempotent: Yes

Returns aggregated statistics regarding allowlist rule counts, lifetime forwarded volumes, and monthly trends.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/sender-rules/whitelist/stats" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "stats": {
    "totalRules": 14,
    "activeRules": 12,
    "rulesTrend": 20,
    "totalAllowedEmails": 384,
    "newThisMonth": 3
  }
}

GET /v1/sender-rules/blacklist — List Blocked Sender Rules

Scope: sender_rules:read · Rate Limit: 60/min · Idempotent: Yes

Returns a paginated list of blocked sender rules (denylist) configured for your workspace.

Query Parameters

ParameterTypeRequiredDefaultDescription
pageintegerOptional1Page number for pagination.
limitintegerOptional50Number of records per page (max 100).
searchstringOptional—Case-insensitive filter on email_pattern.
includeGlobalbooleanOptionalfalseWhen true, includes platform-wide threat network rules alongside workspace rules.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/sender-rules/blacklist?page=1&limit=2" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "entries": [
    {
      "id": "b1a2b3c4-e5f6-7a8b-9c0d-1e2f3a4b5c6d",
      "user_id": "usr_9f8e7d6c5b4a3a2b",
      "email_pattern": "spammer.org",
      "pattern_type": "domain",
      "include_subdomains": true,
      "reason": "Phishing domain targeting credentials",
      "source": "manual",
      "is_active": true,
      "blocked_count": 142,
      "created_at": "2026-08-15T09:30:00.000Z",
      "updated_at": "2026-08-15T09:30:00.000Z"
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 2,
    "total": 1,
    "totalPages": 1
  }
}

POST /v1/sender-rules/blacklist — Create Blocked Sender Rule

Scope: sender_rules:write · Rate Limit: 30/min · Idempotent: Yes

Creates an inbound denylist rule to reject messages from a specific address, domain, or wildcard pattern. Blocked messages are rejected at the edge without entering your forwarding stream.

Request Body Parameters

ParameterTypeRequiredConstraintsDescription
emailPatternstringYes1–255 charsEmail (bad@spam.com), domain (spammer.org), or wildcard pattern (*@*.phishing.com).
patternTypestringOptionalexact, domain, patternMatching mode. Auto-promoted to domain or pattern if pattern characters (*, @) are detected.
includeSubdomainsbooleanOptionalBooleanWhen true with patternType: "domain", blocks all subdomains (e.g. *.spammer.org).
reasonstringOptionalMax 255 charsRationale or internal audit comment.
sourcestringOptionalMax 50 charsOrigin tag: manual, quick_action, automated_filter, or api. Defaults to manual.

Example Request

curl -X POST "https://api.aliasfleet.com/v1/sender-rules/blacklist" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Content-Type: application/json" \
  -d '{
    "emailPattern": "scamnetwork.xyz",
    "patternType": "domain",
    "includeSubdomains": true,
    "reason": "Persistent scam outreach campaign"
  }'

Response (201 Created)

{
  "success": true,
  "entry": {
    "id": "e5f6a7b8-c9d0-1e2f-3a4b-5c6d7e8f9a0b",
    "user_id": "usr_9f8e7d6c5b4a3a2b",
    "email_pattern": "scamnetwork.xyz",
    "pattern_type": "domain",
    "include_subdomains": true,
    "reason": "Persistent scam outreach campaign",
    "source": "manual",
    "is_active": true,
    "blocked_count": 0,
    "created_at": "2026-09-04T12:00:00.000Z",
    "updated_at": "2026-09-04T12:00:00.000Z"
  },
  "message": "scamnetwork.xyz has been blacklisted"
}

Errors

StatusCodeCause & Resolution
400 Bad RequestINVALID_PATTERNThe pattern syntax does not conform to RFC email or hostname specifications.
402 Payment RequiredENTITLEMENT_REQUIREDDomain and wildcard pattern rules require a Pro or Business subscription.
409 ConflictCROSS_TABLE_CONFLICTPattern already exists on your allowlist (whitelist). Remove it from the allowlist first.
409 ConflictALREADY_EXISTSPattern is already present in your denylist.

PATCH /v1/sender-rules/blacklist — Update Blocked Sender Rule

Scope: sender_rules:write · Rate Limit: 60/min · Idempotent: Yes

Updates an existing blocked sender rule, allowing you to toggle rule enforcement on or off without deleting the rule history and counters.

Request Body Parameters

ParameterTypeRequiredConstraintsDescription
idstringYesRule UUIDUnique identifier of the denylist rule to modify.
isActivebooleanOptionalBooleanActivates or pauses rule enforcement.
reasonstringOptionalMax 255 charsUpdated note or rationale.
includeSubdomainsbooleanOptionalBooleanWhether domain matching extends to subdomains.

Example Request

curl -X PATCH "https://api.aliasfleet.com/v1/sender-rules/blacklist" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "e5f6a7b8-c9d0-1e2f-3a4b-5c6d7e8f9a0b",
    "isActive": false,
    "reason": "Deactivated pending review of false positive"
  }'

Response (200 OK)

{
  "success": true,
  "entry": {
    "id": "e5f6a7b8-c9d0-1e2f-3a4b-5c6d7e8f9a0b",
    "user_id": "usr_9f8e7d6c5b4a3a2b",
    "email_pattern": "scamnetwork.xyz",
    "pattern_type": "domain",
    "include_subdomains": true,
    "reason": "Deactivated pending review of false positive",
    "source": "manual",
    "is_active": false,
    "blocked_count": 27,
    "created_at": "2026-09-04T12:00:00.000Z",
    "updated_at": "2026-09-04T12:20:00.000Z"
  }
}

DELETE /v1/sender-rules/blacklist — Delete Blocked Sender Rule

Scope: sender_rules:write · Rate Limit: 60/min · Idempotent: Yes

Permanently deletes a blocked sender rule from your workspace. Messages from the sender will once again be evaluated according to standard forwarding rules.

Query Parameters

ParameterTypeRequiredDescription
idstringYesUnique identifier of the denylist rule to delete.

Example Request

curl -X DELETE "https://api.aliasfleet.com/v1/sender-rules/blacklist?id=e5f6a7b8-c9d0-1e2f-3a4b-5c6d7e8f9a0b" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e"

Response (200 OK)

{
  "success": true,
  "message": "Removed from blacklist"
}

GET /v1/sender-rules/blacklist/stats — Denylist Metrics & Trends

Scope: sender_rules:read · Rate Limit: 60/min · Idempotent: Yes

Returns aggregated statistics regarding blocked sender rules, lifetime rejected messages, and month-over-month threat volume trends.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/sender-rules/blacklist/stats" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "total": 35,
  "active": 32,
  "totalBlocked": 1842,
  "newThisMonth": 6,
  "newLastMonth": 4,
  "blacklistTrend": 50,
  "blockedTrend": -12,
  "blockedThisMonth": 210,
  "blockedLastMonth": 238
}

Frequently Asked Questions

Can a sender exist on both the allowlist and the denylist?

No. The firewall enforces strict mutual exclusivity. Creating a rule for an entry that exists in the opposing table returns HTTP 409 CROSS_TABLE_CONFLICT.

How fast are newly created rules enforced on incoming emails?

Rules propagate to the inbound firewall immediately. Incoming SMTP transactions from blocked senders are rejected in real time during the initial envelope handshake.

What wildcard pattern formats are supported?

Wildcard patterns support asterisk (*) and question mark (?) wildcards on local parts and domain extensions (e.g. *@*.spamnetwork.com, user*@domain.com, or *.badsite.xyz).

Are wildcard and domain rules available on all plans?

Exact email address rules are supported on all tiers. Domain-wide and wildcard pattern rules require a Pro or Business subscription.

Was this article helpful?

Related articles

Identity & Token Introspection API

Verify token validity, inspect active permission scopes, and retrieve account metadata using the Identity API.

Aliases API

Create, list, inspect, update, and soft-delete email aliases programmatically using the AliasFleet REST API.

Alias Destinations & Batch Operations API

Configure multi-destination forwarding fanout, execute atomic batch updates across up to 100 aliases, and fine-tune per-alias privacy settings.

Domains API

Query shared platform domains, register custom brand domains, verify DNS records, and inspect catch-all forwarding rules.

Destinations API

Register destination inboxes, execute 6-digit OTP verification challenges, configure per-channel sender identities, and manage routing fallbacks.

Content

Quick ReferenceInbound Firewall ArchitectureGET /v1/sender-rules/whitelist — List Allowed Sender RulesQuery ParametersExample RequestResponse (`200 OK`)POST /v1/sender-rules/whitelist — Create Allowed Sender RuleRequest Body ParametersExample RequestResponse (`201 Created`)ErrorsPATCH /v1/sender-rules/whitelist — Update Allowed Sender RuleRequest Body ParametersExample RequestResponse (`200 OK`)DELETE /v1/sender-rules/whitelist — Delete Allowed Sender RuleQuery ParametersExample RequestResponse (`200 OK`)GET /v1/sender-rules/whitelist/stats — Allowlist Metrics & TrendsExample RequestResponse (`200 OK`)GET /v1/sender-rules/blacklist — List Blocked Sender RulesQuery ParametersExample RequestResponse (`200 OK`)POST /v1/sender-rules/blacklist — Create Blocked Sender RuleRequest Body ParametersExample RequestResponse (`201 Created`)ErrorsPATCH /v1/sender-rules/blacklist — Update Blocked Sender RuleRequest Body ParametersExample RequestResponse (`200 OK`)DELETE /v1/sender-rules/blacklist — Delete Blocked Sender RuleQuery ParametersExample RequestResponse (`200 OK`)GET /v1/sender-rules/blacklist/stats — Denylist Metrics & TrendsExample RequestResponse (`200 OK`)

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket