curl --request POST \
--url https://inbound.new/api/e2/guard \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"priority": 100,
"config": {
"to": {
"operator": "OR",
"values": [
"support@example.com"
]
},
"subject": {
"operator": "OR",
"values": [
"invoice",
"payment overdue"
]
},
"hasAttachment": true
},
"action": {
"action": "block"
}
}
'import requests
url = "https://inbound.new/api/e2/guard"
payload = {
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"priority": 100,
"config": {
"to": {
"operator": "OR",
"values": ["support@example.com"]
},
"subject": {
"operator": "OR",
"values": ["invoice", "payment overdue"]
},
"hasAttachment": True
},
"action": { "action": "block" }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Block suspicious support invoices',
description: 'Block invoice emails with attachments sent to support.',
type: 'explicit',
priority: 100,
config: {
to: {operator: 'OR', values: ['support@example.com']},
subject: {operator: 'OR', values: ['invoice', 'payment overdue']},
hasAttachment: true
},
action: {action: 'block'}
})
};
fetch('https://inbound.new/api/e2/guard', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://inbound.new/api/e2/guard",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Block suspicious support invoices',
'description' => 'Block invoice emails with attachments sent to support.',
'type' => 'explicit',
'priority' => 100,
'config' => [
'to' => [
'operator' => 'OR',
'values' => [
'support@example.com'
]
],
'subject' => [
'operator' => 'OR',
'values' => [
'invoice',
'payment overdue'
]
],
'hasAttachment' => true
],
'action' => [
'action' => 'block'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://inbound.new/api/e2/guard"
payload := strings.NewReader("{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://inbound.new/api/e2/guard")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://inbound.new/api/e2/guard")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"id": "V1StGXR8_Z5jdHi6B-myT",
"userId": "user_123",
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"config": "{\"to\":{\"operator\":\"OR\",\"values\":[\"support@example.com\"]},\"subject\":{\"operator\":\"OR\",\"values\":[\"invoice\",\"payment overdue\"]},\"hasAttachment\":true}",
"isActive": true,
"priority": 100,
"lastTriggeredAt": null,
"triggerCount": 0,
"actions": "{\"action\":\"block\"}",
"createdAt": "2026-06-12T17:00:00.000Z",
"updatedAt": "2026-06-12T17:00:00.000Z"
}
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Create guard rule
Create an active email filtering rule for the authenticated account.
For an explicit rule, configure one or more of subject, from, to, hasAttachment, and hasWords. Different configured criteria are combined with AND. Within a criterion, OR matches any value and AND requires every value.
Address criteria support exact, case-insensitive addresses and whole-domain patterns such as *@example.com. The to criterion matches the actual delivered recipient, which makes it suitable for limiting a rule to one inbox. Subject and body criteria use case-insensitive substring matching.
Rules are evaluated from highest priority to lowest, and the first matching rule wins. A matching rule can allow, block, or route the email to an active endpoint owned by the account. If action is omitted, it defaults to allow.
For an ai_prompt rule, provide a non-empty natural-language prompt describing when the rule should match.
curl --request POST \
--url https://inbound.new/api/e2/guard \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"priority": 100,
"config": {
"to": {
"operator": "OR",
"values": [
"support@example.com"
]
},
"subject": {
"operator": "OR",
"values": [
"invoice",
"payment overdue"
]
},
"hasAttachment": true
},
"action": {
"action": "block"
}
}
'import requests
url = "https://inbound.new/api/e2/guard"
payload = {
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"priority": 100,
"config": {
"to": {
"operator": "OR",
"values": ["support@example.com"]
},
"subject": {
"operator": "OR",
"values": ["invoice", "payment overdue"]
},
"hasAttachment": True
},
"action": { "action": "block" }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Block suspicious support invoices',
description: 'Block invoice emails with attachments sent to support.',
type: 'explicit',
priority: 100,
config: {
to: {operator: 'OR', values: ['support@example.com']},
subject: {operator: 'OR', values: ['invoice', 'payment overdue']},
hasAttachment: true
},
action: {action: 'block'}
})
};
fetch('https://inbound.new/api/e2/guard', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://inbound.new/api/e2/guard",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Block suspicious support invoices',
'description' => 'Block invoice emails with attachments sent to support.',
'type' => 'explicit',
'priority' => 100,
'config' => [
'to' => [
'operator' => 'OR',
'values' => [
'support@example.com'
]
],
'subject' => [
'operator' => 'OR',
'values' => [
'invoice',
'payment overdue'
]
],
'hasAttachment' => true
],
'action' => [
'action' => 'block'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://inbound.new/api/e2/guard"
payload := strings.NewReader("{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://inbound.new/api/e2/guard")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://inbound.new/api/e2/guard")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Block suspicious support invoices\",\n \"description\": \"Block invoice emails with attachments sent to support.\",\n \"type\": \"explicit\",\n \"priority\": 100,\n \"config\": {\n \"to\": {\n \"operator\": \"OR\",\n \"values\": [\n \"support@example.com\"\n ]\n },\n \"subject\": {\n \"operator\": \"OR\",\n \"values\": [\n \"invoice\",\n \"payment overdue\"\n ]\n },\n \"hasAttachment\": true\n },\n \"action\": {\n \"action\": \"block\"\n }\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"id": "V1StGXR8_Z5jdHi6B-myT",
"userId": "user_123",
"name": "Block suspicious support invoices",
"description": "Block invoice emails with attachments sent to support.",
"type": "explicit",
"config": "{\"to\":{\"operator\":\"OR\",\"values\":[\"support@example.com\"]},\"subject\":{\"operator\":\"OR\",\"values\":[\"invoice\",\"payment overdue\"]},\"hasAttachment\":true}",
"isActive": true,
"priority": 100,
"lastTriggeredAt": null,
"triggerCount": 0,
"actions": "{\"action\":\"block\"}",
"createdAt": "2026-06-12T17:00:00.000Z",
"updatedAt": "2026-06-12T17:00:00.000Z"
}
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Your Inbound API key. Include it in the Authorization header as: Bearer
Body
A descriptive name for the rule.
1explicit, ai_prompt Configuration matching the selected rule type. See the request examples for complete explicit and AI configurations.
- Explicit rule configuration
- AI prompt rule configuration
Show child attributes
Show child attributes
Optional explanation of what the rule handles.
Evaluation priority. Higher values run first; the first matching rule wins. Defaults to 0.
Action to take when the rule matches: allow, block, or route to an owned endpoint. Defaults to allow when omitted.
- Allow
- Block
- Route
Show child attributes
Show child attributes
Was this page helpful?