Introduction
Capture email in a safe sandbox, inspect delivery diagnostics, and automate inbox checks without sending mail to real recipients.
Email Testing is Maileroo's capture-only sandbox for testing message delivery, authentication, rendering, and automation. Messages sent to a test inbox are stored for inspection and are never delivered to their intended recipients unless you deliberately use Release.
Email Testing has its own credentials, inboxes, webhooks, usage counters, and plan limits. It is separate from the Email API and SMTP Relay, even though it uses the same Maileroo account and API-key authentication.
Base URL
The Email Testing API is served under:
https://api.maileroo.com/v1/email-testingAuthentication
Every request must be authenticated with an API key, supplied as a Bearer token in the Authorization header:
GET /v1/email-testing/account/usage HTTP/1.1
Host: api.maileroo.com
Authorization: Bearer roo_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAPI keys must be valid and not revoked, include the scope required by the endpoint, and satisfy any configured IP allowlist. Endpoint pages show the required scope for each operation. Email Testing uses the same Account API key model as the rest of the Account API; see the Account API introduction for the full authentication and scope model.
Rate limits and responses
Email Testing shares the Account API limit of 180 requests per minute per account. Successful responses are wrapped in a top-level data property:
{
"data": {
"mailboxes": []
}
}Errors return a non-2xx HTTP status and this body:
{
"error": {
"message": "A descriptive error message."
}
}Endpoints with nothing to return, such as deletes, respond with 204 No Content and an empty body.
Common errors include 401 for missing or invalid authentication, 403 for a missing scope or disallowed IP, 404 for an unknown account resource, 409 for a conflicting resource or idempotency request, 422 for a valid request that cannot be performed, and 429 for a plan, action, release, or rate limit. Endpoint-specific validation errors use the same error format.
Retention and plan limits
Plan limits control captured messages, SMTP sink credentials, inboxes, custom domains, AI analysis, action execution, and storage policy. The Get Usage and Get Policy endpoints expose the account's current counters and policy. Message retention is controlled by the Email Testing service; deleting a message does not restore a monthly capture allowance.
Where to go next
- SMTP Sink Credentials explains SMTP and MX ingestion and authenticating apps to the Email Testing sink.
- Inboxes covers inbox behavior, magic tags, and raw message uploads.
- Analysis & Previews explains authentication, reputation, rendering, and coverage reports.
- Actions covers safe message actions and deliberate release to a verified domain.
- Testing in CI shows how to wait for a message and run assertions.
- Webhooks documents signed event delivery and replay.
- Browse the Email Testing API reference for every public operation.