Skip to main content
Manage mailbox and SMTP credentials from the dashboard or the authenticated REST API. A credential controls one login address, its incoming-mail scopes, its SMTP sender policy, and its enabled state.

Use the dashboard

1

Open Mailboxes & SMTP

Go to Mailboxes & SMTP. You need at least one verified domain before creating a credential.
2

Create a credential

Select Create credential, then choose Mailbox + SMTP or SMTP only. Enter a name and login email, select the IMAP access level when applicable, configure the sender policy, and add at least one domain or address scope.
3

Store the generated password

After creation, the dashboard displays the login address, generated password, and applicable connection settings. The password is shown only once.
4

Manage an existing credential

Open the credential’s actions menu to Edit, Rotate password, Disable or Enable, or Delete the credential.
A generated mailbox or SMTP password cannot be retrieved after the creation or rotation dialog closes. Store it securely. If you lose it, rotate the password and update every client using that credential.

Authenticate REST requests

The dashboard uses your authenticated account session. For programmatic REST requests, use an ordinary account API key from API Keys, supplied as a Bearer token:
Credential-management endpoints require your ordinary account API token. A generated mailbox or SMTP password is for managed mail authentication and cannot be used to list, create, update, rotate, or delete credentials.
All examples use the production API base URL:

Find a verified domain ID

A scope references a verified domain’s ID, not just its domain name. Obtain YOUR_DOMAIN_ID from the dashboard or list your verified domains:
Use the id of the matching domain in the data array. When creating or editing a credential definition, its login address must also use an exact owned, verified domain, which does not have to be the same domain as a scope.

List credentials

A successful response contains the credentials and offset-based pagination metadata:
limit defaults to 50 and cannot exceed 100. Increase offset while pagination.hasMore is true.

Create a credential

POST /mailboxes requires every top-level field shown below, including sendingName and sendingAddress; nullable values must still be included. Provide between 1 and 100 unique scopes. Accounts can create up to 100 managed credentials by default.
Replace YOUR_DOMAIN_ID with the verified domain ID returned by GET /domains. A successful creation returns HTTP 201:
The real data object includes the complete credential fields shown in the list response. password appears only in this creation response. For a domain-wide scope, use {"type":"domain","domainId":"YOUR_DOMAIN_ID"}. For sendingMode: "scoped_domains", provide "sendingName": null and "sendingAddress": null. SMTP-only credentials use "type": "smtp"; accessMode is still required in the request and is normalized to read_write in responses.
An address scope plus scoped_domains allows sending from any address on that exact domain. See scopes and permissions before choosing a sender policy.

Update a credential

PUT /mailboxes/:id accepts a partial JSON object. Omitted fields retain their existing values.
To change scopes, provide the complete replacement scope list:
The resulting configuration must remain valid. For example, an exact sending identity must still be covered by the replacement scopes. Successful updates return {"data": {...}}.

Disable or re-enable access

Disabling prevents new IMAP and SMTP authentication while preserving the credential, its folders, drafts, sent copies, flags, and other mailbox state. Re-enabling preserves the existing password unless you also rotate it.

Rotate a password

A successful response contains only the newly generated password:
The previous password stops working immediately. The replacement is shown only in this response, so update every IMAP and SMTP client that uses the credential.

Delete a credential

A successful response is:
Deletion permanently removes the credential and its credential-specific IMAP folders, drafts, saved sent copies, flags, and locally appended mailbox data. This mailbox state cannot be restored by creating another credential. Disable the credential instead when access should be suspended without losing its state.

Active sessions and errors

Changes to authentication or permissions, including login addresses, access modes, sender settings, scopes, enabled state, and password rotation, cause active IMAP sessions for that credential to be logged out. Clients must reconnect using the current credential settings. Deletion also invalidates active IMAP sessions. A domain verification-status change is different: it affects which scope domains are accepted during subsequent authentication, but does not automatically terminate an established IMAP session. Disable or edit the credential, or rotate its password, when existing sessions must be ended. Credential-management requests share the account API limit, which defaults to 10 requests per second. See API rate limits.

Scopes and Permissions

Choose the right incoming scopes, IMAP access mode, and sender policy.

Connect with IMAP

Read mail over IMAP using your generated login and password.

Send with SMTP

Send mail over SMTP using the same credential.