Sign inGet Started

Get spam-trap hits for a sending domain

GET
/v1/email/inbox-insights/spam-traps
// Requires Insights preview access for the organization.
let sendingDomain: string | undefined;
for await (const domain of bird.email.inboxInsights.domains.list({ search: "mail.example.com" })) {
  if (domain.domain === "mail.example.com") { sendingDomain = domain.domain; break; }
}
if (!sendingDomain) throw new Error("Verify mail.example.com in this workspace first");
const report = await bird.email.inboxInsights.spamTraps({ sending_domain: sendingDomain });
console.log(report);
Réponse200
{
  "resource": "placement",
  "domain": "mail.acme.com",
  "measurement": {
    "sources": [
      "panel",
      "intelliseed_public"
    ],
    "weighting": {
      "weight_set_id": "12",
      "source": "account",
      "basis": "weighted-mean-of-per-isp-rates"
    }
  },
  "generated_at": "2026-08-18T09:34:00Z",
  "freshness": {
    "as_of": "2026-08-17",
    "lag_hint": "daily"
  },
  "cached_at": "2026-08-18T09:40:02Z",
  "window": {
    "start": "2026-08-12",
    "end": "2026-08-18",
    "group_by": "day"
  },
  "compared_to": {
    "start": "2026-06-19",
    "end": "2026-07-18"
  },
  "total": 3,
  "delta": -2,
  "by_type": [
    {
      "type": "recycled",
      "hits": 3
    }
  ],
  "by_source": [
    {
      "source": "cloudmark",
      "hits": 2
    }
  ],
  "hit_rows": {
    "items": [
      {
        "first_seen": "2026-08-14T06:21:00Z",
        "last_seen": "2026-08-16T11:04:00Z",
        "ip_address": "147.253.40.16",
        "source": "cloudmark",
        "type": "recycled",
        "hit_count": 2,
        "trap_age_days": 430
      }
    ],
    "truncated_types": [
      "recycled"
    ],
    "status": "ok"
  }
}

Returns the spam-trap hits recorded against a sending domain over the period: the total, a split by the kind of trap, a split by the trap network that observed them, and the individual hits with the sending IP and trap age behind each.

Spam traps are addresses that exist only to catch senders mailing lists they should not be mailing, so the kind of trap says more than the count. Hits on pristine traps, which never belonged to a real person, point at harvested or guessed addresses; hits on recycled traps point at stale list data. Zero hits is a measured zero and a good result, so the totals are real figures rather than an empty state.

API-key calls require Insights preview access for your organization.

Paramètres de requête

sending_domainstring

The sending domain to report on: one of the workspace's verified sending domains, exactly as it appears there. A domain that is not verified in this workspace answers not-found.

fromstring

First UTC day of the period, inclusive, in YYYY-MM-DD: the same window convention as the email statistics endpoints. Defaults to 30 days before to.

It may be at most 30 days before to, which is also the default, so a request naming neither date is already at the limit. Asking for more answers 422: the page pairs these figures with Bird's own per-provider sending statistics, and those are kept for 30 days, so a longer period could only describe two different spans side by side.

tostring

Last UTC day of the period, inclusive, in YYYY-MM-DD. Defaults to today.

comparestring

Include the prior equal-length period, populating compared_to and delta.

Possible values: previous_period

Contenu de la réponse

resource
string
obligatoire

Which resource this response is, echoed for self-description.

domain
string
obligatoire

The sending domain the figures describe.

measurement
object

How the figures were measured. Present only where a figure was weighted or drawn from a named set of sources, which today means placement and the industry benchmark. Absent on the reputation resources and on a live lookup, neither of which weights anything.

Afficher les attributs enfants
generated_at
string
obligatoire

When these figures were computed. The measurement service's own stamp where it publishes one; on the resources Bird derives from daily rates it has none to publish, and this is when Bird computed them.

freshness
object
obligatoire

How current the figures are. Freshness differs per resource (authentication data can lag a day or more while blocklist lookups are near real time), so any "as of" label binds from this field, never from a fixed string.

Afficher les attributs enfants
cached_at
string

Present when the response was served from a short-lived copy rather than fetched for this request: when that copy was fetched.

window
object
obligatoire

The period every figure in the response covers: whole UTC calendar days, inclusive on both ends. The same window convention the email statistics endpoints use, so figures from the two sources describe the same days and can be combined without adjustment.

Afficher les attributs enfants
compared_to
object

The prior equal-length period the delta figures compare against. Present only when the request asked for a comparison.

Afficher les attributs enfants
total
integer
obligatoire

Trap hits observed over the period, across every trap network. The authoritative count: hit_rows holds a sample of the rows behind it.

delta
integer

How the hit count moved against the prior period, as a change in the number of hits rather than in percentage points. Negative is an improvement. Present only when the request asked for a comparison and the prior period had data; absence is not zero change.

by_type
array of object
obligatoire

Hits split by kind, one entry per kind the trap network reported. Read counts from here rather than assuming a fixed set of kinds: the set can grow, and an entry that is absent was not reported rather than being a measured zero. These sum to total.

Afficher les attributs enfants
by_source
array of object
obligatoire

Hits split by the trap network that observed them.

Afficher les attributs enfants
hit_rows
object
obligatoire

The individual trap hits behind the totals. A sample rather than a guaranteed complete list, and its rows do not count hits: one row is one trap address, carrying a hit_count for how many times that address was reached. Neither the number of rows nor the sum of hit_count reconstructs total, because that field is absent wherever the trap network does not break the figure out. Read truncated_types for what the measurement capped rather than inferring completeness by comparing counts.

Afficher les attributs enfants
hit_rows.items
array of object
obligatoire

One entry per trap reached, newest first.

Afficher les attributs enfants
hit_rows.items.first_seen
string
obligatoire

When the trap network first observed mail from this domain at this trap.

hit_rows.items.last_seen
nullable string
obligatoire

The most recent sighting, or null when the trap was seen only once. On a row with several hits this is the far end of the period they span.

hit_rows.items.ip_address
string
obligatoire

The sending IP the message came from.

hit_rows.items.source
string
obligatoire

The trap network that observed a hit. The set grows as coverage does, so treat the values as labels rather than a closed list.

Possible values (may grow over time): cloudmark, abusix

hit_rows.items.type
string
obligatoire

What kind of spam trap was hit. pristine addresses were never used by a real person and never subscribed to anything, so a hit means the address was harvested or guessed rather than collected. recycled addresses belonged to a real person once and were retired, so hits point at stale list data. typo addresses catch misspellings of real domains, parked addresses sit on domains that are registered but not used for real mail, and mixed covers hits the trap network reports without a single kind. The trap network decides this set and can add to it, so treat an unrecognised value as a label to show rather than a case to exhaust. A hit whose kind is new is still a hit worth acting on.

Possible values (may grow over time): pristine, recycled, typo, parked, mixed

hit_rows.items.hit_count
integer

How many times this trap was hit over the period, so rows do not sum to total on their own: one repeatedly hit trap is one row. Absent when the trap network does not break the count out, which is not the same as one hit. A row exists because the trap was reached at least once either way.

hit_rows.items.trap_age_days
nullable integer
obligatoire

How long the trap address has been a trap, in days, or null when the network does not say. A high age on a recycled trap suggests the address has been dead in the list for a long time.

hit_rows.truncated_types
array of string
obligatoire

Trap kinds whose hits the measurement capped, so the rows shown for them are incomplete by design rather than by chance. Typo-trap hits, for instance, only ever cover the last seven days. An empty array means nothing was capped.

hit_rows.status
string
obligatoire

Whether a section of the response carries figures, and when it does not, why.

ok means the section is populated. no_data means the measurement ran and observed nothing to report for this domain in the period. not_configured means the section needs a setup step that has not been completed yet, such as connecting Google Postmaster Tools; treat it as an invitation to finish setup rather than a fault. unavailable means the figures could not be retrieved this time and the same request may well succeed on a retry; the rest of the response is unaffected. not_applicable means the section is meaningless for this domain in this period, so there is nothing to show or fix.

A successful response never implies every section is populated; read each section's status rather than assuming figures are present.

Possible values: ok, no_data, not_configured, unavailable, not_applicable

Poursuivez avec la documentation, les guides et les exemples sur ce sujet.