# List receiving domains

`GET /v1/inbound/domains`

- Authentication: required (Bearer token)
- Required scope: `api.inbound.view`

Every receiving domain in the org, with its verification state, the DNS
records that verify it, and its webhook configuration. Unpaginated: a
receiving domain is a subdomain whose MX a person publishes by hand, so
an org has a handful.

`status` is DNS verification and `webhook.status` is publication — has
what SendOps holds reached the config object your intake function reads.
They move independently and neither implies the other.

`webhook` never carries the HMAC secret. That is returned exactly once,
by the call that mints it.

## Example request

```bash
curl 'https://api.sendops.dev/v1/inbound/domains' \
  -H "Authorization: Bearer $SENDOPS_API_KEY"
```

## Responses

### 200 — The org's receiving domains

Content type: `application/json`

```json
{
  "data": [
    {
      "domain": "string",
      "id": "00000000-0000-0000-0000-000000000000",
      "status": "pending_dns",
      "last_error": "string",
      "region": "string",
      "cross_region": true,
      "mx_verified_at": "2026-05-17T20:00:00Z",
      "identity_verified_at": "2026-05-17T20:00:00Z",
      "records": [
        {
          "type": "MX",
          "name": "string",
          "value": "string",
          "verified": true
        }
      ],
      "webhook": {
        "url": "https://example.com",
        "allow_patterns": [
          "string"
        ],
        "spam_posture": "tag",
        "virus_posture": "tag",
        "status": "unset",
        "error": "string",
        "published_at": "2026-05-17T20:00:00Z"
      },
      "created_at": "2026-05-17T20:00:00Z"
    }
  ],
  "pagination": {
    "has_more": true,
    "next_cursor": "string"
  }
}
```

### 401 — Missing, malformed, or unknown API key

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 403 — Key lacks the required scope or plan limit violated

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 429 — Per-org rate limit exceeded

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 500 — Unexpected server-side failure. The `code` is `internal_error`. The
`request_id` field can be quoted to SendOps support to investigate.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```
