Use the dashboard
1
Open Mailboxes & SMTP
Go to Mailboxes & SMTP. You need at least one verified domain before creating a credential.
2
Create a credential
Select Create credential, then choose Mailbox + SMTP or SMTP only. Enter a name and login email, select the IMAP access level when applicable, configure the sender policy, and add at least one domain or address scope.
3
Store the generated password
After creation, the dashboard displays the login address, generated password, and applicable connection settings. The password is shown only once.
4
Manage an existing credential
Open the credential’s actions menu to Edit, Rotate password, Disable or Enable, or Delete the credential.
Authenticate REST requests
The dashboard uses your authenticated account session. For programmatic REST requests, use an ordinary account API key from API Keys, supplied as a Bearer token:Find a verified domain ID
A scope references a verified domain’s ID, not just its domain name. ObtainYOUR_DOMAIN_ID from the dashboard or list your verified domains:
id of the matching domain in the data array. When creating or editing a credential definition, its login address must also use an exact owned, verified domain, which does not have to be the same domain as a scope.
List credentials
limit defaults to 50 and cannot exceed 100. Increase offset while pagination.hasMore is true.
Create a credential
POST /mailboxes requires every top-level field shown below, including sendingName and sendingAddress; nullable values must still be included. Provide between 1 and 100 unique scopes. Accounts can create up to 100 managed credentials by default.
YOUR_DOMAIN_ID with the verified domain ID returned by GET /domains.
A successful creation returns HTTP 201:
data object includes the complete credential fields shown in the list response. password appears only in this creation response.
For a domain-wide scope, use {"type":"domain","domainId":"YOUR_DOMAIN_ID"}. For sendingMode: "scoped_domains", provide "sendingName": null and "sendingAddress": null. SMTP-only credentials use "type": "smtp"; accessMode is still required in the request and is normalized to read_write in responses.
An address scope plus
scoped_domains allows sending from any address on that exact domain. See scopes and permissions before choosing a sender policy.Update a credential
PUT /mailboxes/:id accepts a partial JSON object. Omitted fields retain their existing values.
{"data": {...}}.
Disable or re-enable access
- Disable
- Re-enable
Rotate a password
Delete a credential
Active sessions and errors
Changes to authentication or permissions, including login addresses, access modes, sender settings, scopes, enabled state, and password rotation, cause active IMAP sessions for that credential to be logged out. Clients must reconnect using the current credential settings. Deletion also invalidates active IMAP sessions. A domain verification-status change is different: it affects which scope domains are accepted during subsequent authentication, but does not automatically terminate an established IMAP session. Disable or edit the credential, or rotate its password, when existing sessions must be ended.
Credential-management requests share the account API limit, which defaults to 10 requests per second. See API rate limits.
Scopes and Permissions
Choose the right incoming scopes, IMAP access mode, and sender policy.
Connect with IMAP
Read mail over IMAP using your generated login and password.
Send with SMTP
Send mail over SMTP using the same credential.