Skip to content
Esc
  • OverviewGuidesWhat exists today, and where to start.
  • QuickstartGuidesKey, domain, first send — in that order.
  • AuthenticationGuidesBearer keys, the mandatory User-Agent, and what each refusal means.
  • ErrorsGuidesThe whole vocabulary, with the status each name carries.
  • IdempotencyGuidesRetry a send without sending it twice.
  • PaginationGuidesCursors are item IDs, not page numbers.
  • Rate limitsGuidesTen a second per team, and the headers that tell you where you are.
  • EventsGuidesEvery event a webhook can carry, with one real payload each.
  • DomainsGuidesThe records, where they go at each registrar, and what the page does while you wait.
  • TrackingGuidesOpens and clicks: one record, two toggles, and what an open really means.
  • ReceivingGuidesInbound mail, and the Inbox: a webhook fires, you read it, you answer it.
  • InboxGuidesChannels, personal mailboxes and seats: who sees what, and where a reply goes.
  • Node SDKGuidesThe rasket package: typed from the API's own document, retries only what is safe.
  • Python SDKGuidesThe rasket package on PyPI: the Node client's methods, in snake_case, over httpx.
  • MCP serverGuidesConnect Claude, ChatGPT or any MCP client: your scopes, no key.
  • AI assistGuidesSubject lines, drafts and diagnosis — in the dashboard and over the API, off until you allow it.
  • AgentsGuidesLet an AI agent set Rasket up: the skill, the rules file, MCP, and the recipe they share.
  • OAuthGuidesLet another app act for a team: register, authorize with PKCE, exchange, refresh.
  • Single sign-onGuidesOIDC login for your team, a domain proved by DNS, enforcement and break-glass.
  • IntegrationsGuidesVercel, Netlify and Cloudflare, plus Zapier and n8n for workflows without code.
  • SMTPGuidesSend from anything that speaks SMTP: settings, setup guides, limits and replies.
  • ZapierGuidesSend email, add contacts and react to email events from a Zap, with no code.
  • n8nGuidesThe Rasket node and trigger for n8n workflows: install, connect, every operation.
  • EmailsAPI referenceSend, batch, retrieve, list, reschedule, cancel, attachments.
  • DomainsAPI referenceAdd a domain, publish its records, verify it.
  • API keysAPI referenceCreate, list, rename and revoke credentials.
  • WebhooksAPI referencePayloads, signature verification, retries and replay.
  • SuppressionsAPI referenceAddresses we will not send to, and why.
  • LogsAPI referenceEvery request made with this team's credentials.
  • MetricsAPI referenceDelivery, bounce, complaint and engagement counts.
  • TemplatesAPI referenceVersioned email content with typed variables, addressed by ID or alias.
  • ContactsAPI referenceYour audience: contacts, their typed properties, segments and topic choices.
  • SegmentsAPI referenceAudiences defined by a filter, by hand, or both.
  • TopicsAPI referenceWhat contacts subscribe to, and the preference page's list.
  • CampaignsAPI referenceCampaigns, at /broadcasts: one message to a segment, from draft to results.
  • ImportsAPI referenceCSV uploads: column mapping, conflicts and counts.
  • AutomationsAPI referenceWorkflows that run per contact: the graph, its versions, and every run.
  • Custom eventsAPI referenceThe names your product fires, and what starts a workflow.
  • ReceivingAPI referenceMail sent to you: the message, its attachments, its raw source.
  • OAuthAPI referenceClient registration, the token endpoint, and the grants a team has given.
  • TeamAPI referenceThe team a credential belongs to: its plan, sender identity, AI flag and members.
  • BillingAPI referencePlan, usage, invoices and add-ons, and the hosted pages where a customer pays.
  • AI helpersAPI referenceSubject lines, a first draft, and why an email did what it did.

GuidesDomains

Domains

Add the domain you send from, publish a handful of DNS records at whoever holds it, and the page watches them verify. This is what those records are, where they go, and what the page is doing while you wait.

The records

Adding a domain generates its record set at once; GET /domains/{domain_id} returns the same rows the dashboard shows. Send from a subdomain such as mail.example.com rather than the apex: it keeps this product's sending reputation separate from your other mail, and a Receiving MX published there cannot take mail away from the mailboxes your apex already has.

The record groups
GroupWhat it isNeeded
VerificationOne DKIM TXT record at rasket._domainkey, carrying a 2048-bit key. Proves the domain is yours and signs every message.Required
SendingOne CNAME to Rasket at the return-path label, a free name we pick (rasket by default) unless you choose one (on some domains, an MX and an SPF TXT). Bounces reach us and SPF aligns.Required to send
ReceivingOne MX at the domain, or at a subdomain you choose. Points inbound mail at us. Offered in two of the four sending regions.Required to receive
TrackingOne CNAME, links unless you rename it. Serves the open pixel and click links on your own hostname.Optional
BrandingOne TXT at default._bimi, and only once you upload a brand logo. Shows your logo in inboxes that support it.Optional

Four ways to publish them

Adding a domain walks the same four steps wherever you start it — the name, where mail should arrive, connecting, and watching the records go live — and the first three ways below are three routes through the third one. Leave at any point with Skip for now: the domain stays in your list and we keep checking in the background.

  • Cloudflare. One button. You sign in to Cloudflare, tick the account that holds the zone, and the records are written for you.
  • GoDaddy, IONOS, Squarespace and others. Many registrars support a shared standard for this. Where yours does, the connect step offers a Connect card with your registrar's name on it: you approve the change on their own screen and come straight back, and we start checking the records immediately. Nothing of yours is stored, and we never ask you for a password or an API key. If the domain uses a name of its own for the return path, or a renamed tracking hostname, the page says which rows one click cannot cover.
  • Any other registrar. The domain page recognises where the domain is hosted from its nameservers and shows that registrar's own instructions: where to click, the fields in the order that panel lists them and under the names it gives them, a copy button beside every value, and the panel's known traps.
  • Software. POST /domains returns the records; publish them with whatever manages your zone, then POST /domains/{domain_id}/verify asks for a check now. The MCP server exposes the same two operations.

Adding records by hand

Open the domain in the dashboard and follow the panel headed Add these at …. It is written for the registrar the nameservers point at; a domain hosted somewhere the page does not recognise gets the generic version, which is true for any record editor.

  1. Open your registrar's record editor for the domain.
  2. Add each row in the table. Copy every field from the page — the name is already spelled the way that registrar wants it.
  3. Leave TTL at the registrar's default.
  4. On Cloudflare, set every CNAME to DNS only (grey cloud). A proxied record answers with Cloudflare's addresses instead of ours and never verifies.
  5. Come back to the page. It checks every 30 seconds by itself; Check now looks straight away if you would rather not wait.
Registrars the domain page recognises
RegistrarRecognised byHow it wants the name
Cloudflare*.ns.cloudflare.comThe part before the domain; @ for the domain itself
Route 53*.awsdns-*.{com,net,org,co.uk}The part before the domain; empty for the domain itself
GoDaddy*.domaincontrol.comThe part before the domain; @ for the domain itself
Namecheap*.registrar-servers.comThe part before the domain; @ for the domain itself
Google Domains / Squarespace*.googledomains.com, *.squarespacedns.comThe part before the domain; @ for the domain itself
Vercel*.vercel-dns.comThe part before the domain; @ for the domain itself
Netlify*.nsone.netThe part before the domain; @ for the domain itself
DigitalOcean*.digitalocean.comThe part before the domain; @ for the domain itself
Hetzner*.hetzner.com, *.hetzner.deThe part before the domain; @ for the domain itself
OVH*.ovh.netThe part before the domain; empty for the domain itself
IONOS*.ui-dns.com, *.ui-dns.de, *.ui-dns.org, *.ui-dns.bizThe part before the domain; @ for the domain itself
Hover*.hover.comThe part before the domain; @ for the domain itself
Bluehost*.bluehost.comThe full name with a trailing dot
HostGator*.hostgator.com, *.websitewelcome.comThe full name with a trailing dot
DreamHost*.dreamhost.comThe part before the domain; empty for the domain itself
Wix*.wixdns.netThe part before the domain; @ for the domain itself
Shopify*.dnsimple.com, *.dnsimple-edge.net, *.dnsimple-edge.orgThe part before the domain; @ for the domain itself

The most common mistake is pasting the full name into a field that adds the domain for you, which publishes rasket._domainkey.example.com.example.com. The page's Name column already shows what to type; when a panel wants the whole name, it shows that instead.

The return path

The sending records live at one name under your domain, the return path: bounces are handled there. Another email service may already use a name like send for its own records, and a name can only point one way, so we pick one nobody uses when you add the domain — rasket, or the next free one of rasketmail, rk, rasket1 and rasket2. The other service keeps working as it does today.

  • Choose your own. Open Advanced options when you add the domain, or send custom_return_path to POST /domains. A name that already holds another service's records is refused, with a free one suggested.
  • Change it later. The domain's Configuration tab has a Return path row, and PATCH /domains/{domain_id} takes the same field. The sending records move to the new name; publish them there and keep the old ones until the new ones verify. The domain keeps sending in the meantime.
  • In use elsewhere. If a check finds another service's record at your return path, the row says so and links to Change return path.

While you wait

The domain page runs the same check the background schedule runs, every 30 seconds while it is open and for up to an hour, and each row says what the last check saw: Not found yet, Wrong value with what we saw instead, In use elsewhere when another email service holds the return path, or Found, confirming while the mail servers catch up. DNS changes can take up to an hour to show up; the background check carries on after the page stops watching, and a reload starts it again.

Under that, the row says whose turn it is. Action needed means the record is not published, or not published with this value, and nothing will change until you fix it at your registrar — the sentence beside the value says what we saw. Waiting on usmeans the record is where it should be and something on our side has not finished: our mail servers confirming it, or the certificate for a tracking hostname, which takes a few minutes. Pressing Check now looks again, but only publishing or waiting changes the answer.

  • A domain is verified for sending once DKIM and the Sending records verify; the Tracking record never holds that up.
  • A record that has not verified after 72 hours is marked failed. Fix the value and the page picks it up on its next check.
  • DMARC is not one of the records and never holds verification up. The domain page offers a guided DMARC record under the DNS records, with reports going to an address of yours; publish one once sending verifies.
  • A domain another team already verified cannot be verified by yours; see the claim flow on the domain page.