Get spam-trap hits for a sending domain
/v1/email/inbox-insights/spam-traps// Requires Insights preview access for the organization.
let sendingDomain: string | undefined;
for await (const domain of bird.email.inboxInsights.domains.list({ search: "mail.example.com" })) {
if (domain.domain === "mail.example.com") { sendingDomain = domain.domain; break; }
}
if (!sendingDomain) throw new Error("Verify mail.example.com in this workspace first");
const report = await bird.email.inboxInsights.spamTraps({ sending_domain: sendingDomain });
console.log(report);# Requires Insights preview access for the organization.
sending_domain = None
for domain in client.email.inbox_insights.domains.list(search="mail.example.com"):
if domain.domain == "mail.example.com":
sending_domain = domain.domain
break
if sending_domain is None:
raise ValueError("Verify mail.example.com in this workspace first")
report = client.email.inbox_insights.spam_traps(sending_domain=sending_domain)
print(report.model_dump_json())// Requires Insights preview access for the organization.
client, err := bird.NewClient(option.WithAPIKey(os.Getenv("BIRD_API_KEY")))
if err != nil {
log.Fatal(err)
}
ctx := context.Background()
sendingDomain := ""
for domain, err := range client.Email.InboxInsights.Domains.List(ctx, bird.EmailInboxInsightsDomainsListParams{Search: "mail.example.com"}) {
if err != nil {
log.Fatal(err)
}
if domain.Domain != nil && *domain.Domain == "mail.example.com" {
sendingDomain = *domain.Domain
break
}
}
if sendingDomain == "" {
log.Fatal("Verify mail.example.com in this workspace first")
}
report, err := client.Email.InboxInsights.SpamTraps(ctx, bird.EmailInboxInsightsSpamTrapsParams{SendingDomain: sendingDomain})
if err != nil {
log.Fatal(err)
}
encoded, err := json.MarshalIndent(report, "", " ")
if err != nil {
log.Fatal(err)
}
fmt.Println(string(encoded))// Requires Insights preview access for the organization.
$sendingDomain = null;
foreach ($bird->email->inboxInsights->domains->list(['search' => 'mail.example.com']) as $domain) {
if ($domain->getDomain() === 'mail.example.com') {
$sendingDomain = $domain->getDomain();
break;
}
}
if ($sendingDomain === null) {
throw new \RuntimeException('Verify mail.example.com in this workspace first');
}
$report = $bird->email->inboxInsights->spamTraps(['sending_domain' => $sendingDomain]);
var_dump($report);bird email inbox-insights spam-traps <sending-domain>curl -X GET "https://us1.platform.bird.com/v1/email/inbox-insights/spam-traps" \
-H "Authorization: Bearer $TOKEN" \
--url-query "sending_domain=mail.acme.com"{
"resource": "placement",
"domain": "mail.acme.com",
"measurement": {
"sources": [
"panel",
"intelliseed_public"
],
"weighting": {
"weight_set_id": "12",
"source": "account",
"basis": "weighted-mean-of-per-isp-rates"
}
},
"generated_at": "2026-08-18T09:34:00Z",
"freshness": {
"as_of": "2026-08-17",
"lag_hint": "daily"
},
"cached_at": "2026-08-18T09:40:02Z",
"window": {
"start": "2026-08-12",
"end": "2026-08-18",
"group_by": "day"
},
"compared_to": {
"start": "2026-06-19",
"end": "2026-07-18"
},
"total": 3,
"delta": -2,
"by_type": [
{
"type": "recycled",
"hits": 3
}
],
"by_source": [
{
"source": "cloudmark",
"hits": 2
}
],
"hit_rows": {
"items": [
{
"first_seen": "2026-08-14T06:21:00Z",
"last_seen": "2026-08-16T11:04:00Z",
"ip_address": "147.253.40.16",
"source": "cloudmark",
"type": "recycled",
"hit_count": 2,
"trap_age_days": 430
}
],
"truncated_types": [
"recycled"
],
"status": "ok"
}
}
Returns the spam-trap hits recorded against a sending domain over the period: the total, a split by the kind of trap, a split by the trap network that observed them, and the individual hits with the sending IP and trap age behind each.
Spam traps are addresses that exist only to catch senders mailing lists they should not be mailing, so the kind of trap says more than the count. Hits on pristine traps, which never belonged to a real person, point at harvested or guessed addresses; hits on recycled traps point at stale list data. Zero hits is a measured zero and a good result, so the totals are real figures rather than an empty state.
API-key calls require Insights preview access for your organization.
Query Parameters
sending_domainstringThe sending domain to report on: one of the workspace's verified sending domains, exactly as it appears there. A domain that is not verified in this workspace answers not-found.
fromstringFirst UTC day of the period, inclusive, in YYYY-MM-DD: the same window
convention as the email statistics endpoints. Defaults to 30 days
before to.
It may be at most 30 days before to, which is also the default, so a
request naming neither date is already at the limit. Asking for more
answers 422: the page pairs these figures with Bird's own per-provider
sending statistics, and those are kept for 30 days, so a longer period
could only describe two different spans side by side.
tostringLast UTC day of the period, inclusive, in YYYY-MM-DD. Defaults to today.
comparestringInclude the prior equal-length period, populating compared_to and delta.
Possible values: previous_period
Response Payload
resourceWhich resource this response is, echoed for self-description.
domainThe sending domain the figures describe.
measurementHow the figures were measured. Present only where a figure was weighted or drawn from a named set of sources, which today means placement and the industry benchmark. Absent on the reputation resources and on a live lookup, neither of which weights anything.
Show child attributes
measurement.sourcesIdentifiers of the measurement systems that contributed to these figures. The set grows as measurement coverage does, so treat the values as labels rather than a closed list.
measurement.weightingHow the figures were weighted. Present on figures weighted against an audience mix, which is placement's method; measurements that weight nothing carry no weighting block.
Show child attributes
measurement.weighting.weight_set_idThe measurement's own identifier for the audience mix, carried through so a client can tell two weightings apart without comparing basis strings. No operation accepts it.
measurement.weighting.sourceWhich audience mix the weighting used. Null when the measurement weighted these figures by a method this API does not model: the enum is closed so that a client can branch on it exhaustively, which means an unfamiliar method has to answer "not one of these" rather than be passed through. basis usually still describes the method in words when that happens.
measurement.weighting.basisThe weighting method behind the rates, as the measurement names it. A slug rather than a sentence, so render it as a label and do not expect it to read as English. Null when the measurement did not state one, which pairs with source: both describe the method, so neither can claim to know it when the measurement was silent.
generated_atWhen these figures were computed. The measurement service's own stamp where it publishes one; on the resources Bird derives from daily rates it has none to publish, and this is when Bird computed them.
freshnessHow current the figures are. Freshness differs per resource (authentication data can lag a day or more while blocklist lookups are near real time), so any "as of" label binds from this field, never from a fixed string.
cached_atPresent when the response was served from a short-lived copy rather than fetched for this request: when that copy was fetched.
windowThe period every figure in the response covers: whole UTC calendar days, inclusive on both ends. The same window convention the email statistics endpoints use, so figures from the two sources describe the same days and can be combined without adjustment.
compared_toThe prior equal-length period the delta figures compare against. Present only when the request asked for a comparison.
totalTrap hits observed over the period, across every trap network. The authoritative count: hit_rows holds a sample of the rows behind it.
deltaHow the hit count moved against the prior period, as a change in the number of hits rather than in percentage points. Negative is an improvement. Present only when the request asked for a comparison and the prior period had data; absence is not zero change.
by_typeHits split by kind, one entry per kind the trap network reported. Read counts from here rather than assuming a fixed set of kinds: the set can grow, and an entry that is absent was not reported rather than being a measured zero. These sum to total.
by_sourceHits split by the trap network that observed them.
hit_rowsThe individual trap hits behind the totals. A sample rather than a guaranteed complete list, and its rows do not count hits: one row is one trap address, carrying a hit_count for how many times that address was reached. Neither the number of rows nor the sum of hit_count reconstructs total, because that field is absent wherever the trap network does not break the figure out. Read truncated_types for what the measurement capped rather than inferring completeness by comparing counts.
Related resources
Continue with the documentation, guides and examples for this topic.