# Limits

Every limit an account meets, and its number.

Every limit an account meets, with its number. When a send meets one, [Errors](https://sendora.se/docs/errors) says what the refusal looks like. To raise a per-minute limit, the test servers' limits, the number of servers or a limit marked "unless Sendora sets another", write to support.

## Sending rates and the monthly cap

Emails are counted one per recipient, across `to`, `cc` and `bcc`, and a month is a calendar month in UTC.

| Limit                   | Value                                                                                                                                  |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| Per minute, per account | 300 by default                                                                                                                         |
| Monthly cap             | Set at approval from the monthly volume the application named: 10,000, 50,000, 250,000 or 1,000,000; above that, a figure Sendora sets |
| Highest monthly cap     | 10 times the cap approval set, unless Sendora sets another                                                                             |
| Warning                 | A `cap_warning` webhook at 80 percent of the cap, once a month                                                                         |

- An administrator moves the monthly cap under [Account › Usage](https://app.sendora.se/account/usage), anywhere up to the highest. Write to support to go past that.
- An account approved without an application starts at the monthly cap of the smallest volume.
- Sendora can give a server a per-minute limit and a monthly cap of its own, only ever tighter than the account's.
- A broadcast counts in full against the monthly cap as soon as Sendora accepts it. The per-minute limit does not apply to broadcasts.

## Test servers

| Limit                                      | Value             |
| ------------------------------------------ | ----------------- |
| Per minute, all the account's test servers | 300 by default    |
| Per month, all the account's test servers  | 10,000 by default |

Test mail never counts toward the account's monthly cap. A refusal under these limits has the scope `test`.

## Account

| Object                          | Limit                                      |
| ------------------------------- | ------------------------------------------ |
| Servers                         | 10 by default, more on request             |
| Keys                            | 2 live per server, and 2 live account keys |
| Webhook secrets                 | 2 live per webhook                         |
| Inbound streams                 | One live per server                        |
| Names of servers, streams, keys | Up to 100 characters                       |

Sending domains, webhooks and transactional and broadcast streams have no limit of their own.

## Requests

| Limit             | Value                                                   |
| ----------------- | ------------------------------------------------------- |
| Request body      | 10 MB, and 64 MB for `POST /v1/broadcasts`              |
| `Idempotency-Key` | Up to 255 printable characters, remembered for 24 hours |
| Batch             | Up to 100 messages                                      |

## Messages

| Limit          | Value                                                          |
| -------------- | -------------------------------------------------------------- |
| Recipients     | 50, across `to`, `cc` and `bcc`                                |
| Size           | 10 MB as built, with attachments counted after base64 encoding |
| Subject        | 998 characters                                                 |
| Attachments    | 20                                                             |
| Custom headers | 20                                                             |
| Metadata       | 20 entries, keys of up to 40 characters, values of up to 500   |
| Tag            | Up to 100 characters                                           |

## Broadcasts

| Limit         | Value                                                                                                                    |
| ------------- | ------------------------------------------------------------------------------------------------------------------------ |
| Messages      | 50,000 per broadcast                                                                                                     |
| Size          | 50 MB for the whole broadcast as built, and 10 MB for each message in it                                                 |
| Substitutions | 20 per message, each up to 500 characters                                                                                |
| Pace          | 600 messages a minute per broadcast stream, unless Sendora sets another                                                  |
| The brake     | The stream pauses when complaints pass 0.1 percent of its deliveries in the last 24 hours, once those are at least 1,000 |

## SMTP submission

| Limit       | Value                                    |
| ----------- | ---------------------------------------- |
| Connections | 200 at once on each listener             |
| Idle        | A connection is closed after 60 seconds  |
| Message     | 10 MB and 50 recipients, as over the API |

## Inbound mail

| Limit        | Value                                                                                       |
| ------------ | ------------------------------------------------------------------------------------------- |
| Size         | 35 MB per message                                                                           |
| Rate         | 300 recipients a minute per account, unless Sendora sets another                            |
| Recipients   | 50 per delivery from a sending server                                                       |
| Connections  | 300 a minute from one sending server                                                        |
| Content kept | The stream's `contentRetentionDays`, 1 to 30 days, 30 by default                            |
| Addresses    | `to` and `cc` hold up to 100 entries each, with the whole number in `toCount` and `ccCount` |
| Domain grace | Mail to a verified domain whose records went missing is deferred for 72 hours, then refused |

If a received message passes one of these limits, Sendora still keeps it whole. `parseIssue` says which limit, and you can download the raw message while the stream keeps its content:

| Parser limit    | Value                                       |
| --------------- | ------------------------------------------- |
| Header block    | 256 KB and 1,000 lines                      |
| Parts           | 500 MIME parts, nested up to 50 deep        |
| Text and HTML   | 1 MB of text and 2 MB of HTML once decoded  |
| Decoded content | 4 times the size of the message as received |
| Time            | 20 seconds to parse                         |
| Attachments     | The first 100 are kept                      |
| Header values   | The first 2,000 characters are kept         |
| Address lists   | The first 1,000 addresses are kept          |

If a message passes the header, part, size or time limit, its parsed text, HTML and attachments are empty. If it passes one of the last three, Sendora parses it and leaves out the rest.

## Retention

| What                                                                       | Kept for                                                      |
| -------------------------------------------------------------------------- | ------------------------------------------------------------- |
| A message's text and HTML                                                  | 30 days                                                       |
| Its attachments' content                                                   | Until Sendora's mail server has the message, or it has failed |
| The message, its recipients and events, and a received message's reference | 13 months                                                     |
| On a test server                                                           | 7 days for the text and HTML, 30 days for the rest            |

## Webhooks

| Limit   | Value                                                                                                                                     |
| ------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| Timeout | 10 seconds for an answer; a redirect is not followed and counts as a failure                                                              |
| Retries | After 30 seconds, 2 minutes, 10 minutes, 30 minutes, 1 hour, 3 hours, 6 hours and 12 hours; then the delivery is dead until you replay it |

## Page sizes

| Lists                                   | Page size                   |
| --------------------------------------- | --------------------------- |
| Messages, received messages, broadcasts | Up to 100, 50 by default    |
| Suppressions, webhook deliveries        | Up to 1,000, 100 by default |

## Sign-in

| Limit         | Per 15 minutes                |
| ------------- | ----------------------------- |
| Sign-in tries | 10 per address, 30 per client |
| Mailed links  | 3 per address, 10 per client  |
| Invitations   | 3 per address, 20 per client  |

## Requests per second

Before any request reaches the API, the proxy holds each client to 20 requests a second, with bursts of up to 50, and each body to the sizes under Requests. Its refusals are plain text, not JSON: `429 Too Many Requests` and `413 Request Entity Too Large`.
