- authentication
- Secret API key as a bearer token
- billing
- Free.
Names only the rules that change; the rest stay as they were, and the change applies to the account's next lookup. max_risk_score: null ignores the score, block_signals: [] blocks on no signal. A body naming none of the three rules is refused with a 422 keyed policy, because that is the shape a misspelled key takes.
Request body
| field | type | description |
|---|---|---|
| max_risk_score | integer | null | Block when risk_score is above this; null ignores the score. |
| block_signals | string[] | null | Signals that block whenever they fire, whatever the score. |
| min_mailbox_confidence | integer | null | Block an unconfirmed mailbox whose mailbox_confidence is below this; null ignores it. |
Example request
curl -X PUT https://spaw.co/api/v1/email/policy \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{
"max_risk_score": 40,
"block_signals": [
"disposable",
"likely_typo",
"parked_domain",
"mx_blocklisted",
"no_reply",
"catch_all"
]
}'This endpoint has no console on its page. It writes to your account. A documentation page can show you the request; making the change is for the dashboard or for a call you make yourself.
Responses
200The policy now in force.
Error codes
Failures answer { success: false, error: { code, message, request_id } }. Each code has its own page.