Sign inGet Started

Get email authentication standing for a sending domain

GET
/v1/email/inbox-insights/authentication
// Requires Insights preview access for the organization.
let sendingDomain: string | undefined;
for await (const domain of bird.email.inboxInsights.domains.list({ search: "mail.example.com" })) {
  if (domain.domain === "mail.example.com") { sendingDomain = domain.domain; break; }
}
if (!sendingDomain) throw new Error("Verify mail.example.com in this workspace first");
const report = await bird.email.inboxInsights.authentication({ sending_domain: sendingDomain });
console.log(report);
Response200
{
  "resource": "placement",
  "domain": "mail.acme.com",
  "measurement": {
    "sources": [
      "panel",
      "intelliseed_public"
    ],
    "weighting": {
      "weight_set_id": "12",
      "source": "account",
      "basis": "weighted-mean-of-per-isp-rates"
    }
  },
  "generated_at": "2026-08-18T09:34:00Z",
  "freshness": {
    "as_of": "2026-08-17",
    "lag_hint": "daily"
  },
  "cached_at": "2026-08-18T09:40:02Z",
  "window": {
    "start": "2026-08-12",
    "end": "2026-08-18",
    "group_by": "day"
  },
  "compared_to": {
    "start": "2026-06-19",
    "end": "2026-07-18"
  },
  "spf": {
    "pass_rate_percent": 99.8,
    "delta_pts": 0.1,
    "source": "dmarc_rua",
    "status": "ok"
  },
  "dkim": {
    "pass_rate_percent": 99.8,
    "delta_pts": 0.1,
    "source": "dmarc_rua",
    "status": "ok"
  },
  "dmarc": {
    "aligned_rate_percent": 98.6,
    "policy": "quarantine",
    "ready_for_reject": false,
    "readiness_reasons": [
      "source_below_threshold"
    ],
    "delta_pts": -0.2,
    "source": "dmarc_rua",
    "status": "ok"
  },
  "sources": {
    "items": [
      {
        "name": "Bird (mail.acme.com)",
        "category": "esp",
        "volume": 4820000,
        "spf_aligned_rate_percent": 99.8,
        "dkim_aligned_rate_percent": 99.9,
        "dmarc_pass_rate_percent": 99.9,
        "verdict": "aligned",
        "qualifies_for_readiness": true
      }
    ],
    "latest_data_date": "2026-08-15",
    "status": "ok"
  }
}

Returns whether the domain's mail authenticates and who sends as the domain: SPF and DKIM pass rates, the DMARC standing with its published policy and a conservative ready-for-reject judgement, and a per-source table showing every system observed sending under the domain's name, forwarders and unidentified senders included.

The DMARC figures name their source: authoritative aggregate reporting that covers every sender, or Google Postmaster as a fallback covering only mail Google received. Aggregate reports arrive on reporters' own schedules, routinely a day or more behind, so the source table names its latest included day; label from it rather than reading the newest days' sparseness as a regression. For a domain with neither reporting source configured, sections report not_configured with a setup path, not an error.

API-key calls require Insights preview access for your organization.

Query Parameters

sending_domainstring

The sending domain to report on: one of the workspace's verified sending domains, exactly as it appears there. A domain that is not verified in this workspace answers not-found.

fromstring

First UTC day of the period, inclusive, in YYYY-MM-DD: the same window convention as the email statistics endpoints. Defaults to 30 days before to.

It may be at most 30 days before to, which is also the default, so a request naming neither date is already at the limit. Asking for more answers 422: the page pairs these figures with Bird's own per-provider sending statistics, and those are kept for 30 days, so a longer period could only describe two different spans side by side.

tostring

Last UTC day of the period, inclusive, in YYYY-MM-DD. Defaults to today.

comparestring

Include the prior equal-length period, populating compared_to.

Possible values: previous_period

Response Payload

resource
string
required

Which resource this response is, echoed for self-description.

domain
string
required

The sending domain the figures describe.

measurement
object

How the figures were measured. Present only where a figure was weighted or drawn from a named set of sources, which today means placement and the industry benchmark. Absent on the reputation resources and on a live lookup, neither of which weights anything.

Show child attributes
generated_at
string
required

When these figures were computed. The measurement service's own stamp where it publishes one; on the resources Bird derives from daily rates it has none to publish, and this is when Bird computed them.

freshness
object
required

How current the figures are. Freshness differs per resource (authentication data can lag a day or more while blocklist lookups are near real time), so any "as of" label binds from this field, never from a fixed string.

Show child attributes
freshness.as_of
nullable string
required

The most recent UTC day the figures include, or null for a live lookup that has no measurement window.

freshness.lag_hint
nullable string
required

How far behind real time this resource usually runs. A lowercase identifier rather than a display label, so pick your own wording for it, and treat the set as open: the measurement names a hint per resource and can add one without notice.

Null when the measurement reports no hint, which several resources do: show the figures without an age rather than inventing one.

Possible values (may grow over time): daily, nightly, near_real_time

cached_at
string

Present when the response was served from a short-lived copy rather than fetched for this request: when that copy was fetched.

window
object
required

The period every figure in the response covers: whole UTC calendar days, inclusive on both ends. The same window convention the email statistics endpoints use, so figures from the two sources describe the same days and can be combined without adjustment.

Show child attributes
compared_to
object

The prior equal-length period the delta figures compare against. Present only when the request asked for a comparison.

Show child attributes
spf
object
required

The domain's SPF pass rate.

Show child attributes
dkim
object
required

The domain's DKIM pass rate.

Show child attributes
dmarc
object
required

The domain's DMARC standing over the period.

Show child attributes
sources
object
required

Every system observed sending as this domain, with how each authenticates. This is the table that shows who else sends under the domain's name.

Show child attributes

Continue with the documentation, guides and examples for this topic.