Skip to content

[Email Service] Document account-wide suppressions - #32948

Closed
rpots wants to merge 102 commits into
productionfrom
ruisilva/EMAIL-2041
Closed

[Email Service] Document account-wide suppressions#32948
rpots wants to merge 102 commits into
productionfrom
ruisilva/EMAIL-2041

Conversation

@rpots

@rpots rpots commented Aug 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

Documents account-wide Email Sending suppressions and adds a dashboard and REST API management guide. Clarifies suppression reasons, expiration behavior, read-only policy metadata, limits, troubleshooting, and REST API, Workers binding, and SMTP behavior.

Documentation checklist

  • Is there a changelog entry (guidelines)? If you don't add one for something awesome and new (however small) — how will our customers find out? Changelogs are automatically posted to RSS feeds, the Discord, and X.
  • The change adheres to the documentation style guide.
  • If a larger change - such as adding a new page- an issue has been opened in relation to any incorrect or out of date information that this PR fixes.
  • Files which have changed name or location have been allocated redirects.

@rpots
rpots requested a review from thomasgauvin August 24, 2026 11:01
@rpots
rpots requested a review from a team as a code owner August 24, 2026 11:01
@cloudflare-docs-bot

cloudflare-docs-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Review

⚠️ 2 warnings found in commit 2136176.

👉 Fix in your agent 👈
Fix the following review findings in PR #32948 (https://github.com/cloudflare/cloudflare-docs/pull/32948).

Before making changes, review each finding and present a brief summary table:
- For each finding, state whether you agree, disagree, or need clarification
- If you disagree (e.g. the fix requires disproportionate effort for minimal benefit,
  or the finding is factually incorrect), explain why
- If you need clarification before deciding, ask those questions
- Then share your plan for which issues to tackle and in what order

After triaging, follow this order:
1. Post a comment on this PR for any findings you are skipping, with the finding ID and your reasoning.
2. Then commit the fixes for the legitimate findings.

The comment must come before the commit — the bot reads PR comments when a new
push triggers a review, so skip comments posted after the push will be missed.

---

## Code Review

### Warnings (1)

#### CR-f5dc835d3bd1 · PR scope mismatch
- **File:** `src/content/docs/dns/nameservers/nameserver-options.mdx` line 25
- **Issue:** The PR title is '[Email Service] Document account-wide suppressions', but the changed file is src/content/docs/dns/nameservers/nameserver-options.mdx and the additions describe Cloudflare DNS nameserver assignment behavior, not email suppressions.
- **Fix:** Verify this is the intended file/branch for the PR. If these DNS nameserver changes are unrelated to the PR's stated purpose, move them to the correct PR or update the PR title and description.

---

## Conventions

### Warnings (1)

#### CV-b617070ce148 · Scope accuracy
- **File:** PR-level finding
- **Issue:** The description only covers Email Service suppression documentation, but the diff touches ~770 files across many unrelated product areas (Cloudflare WAN, Cloudflare One, Workers, AI Search, Radar, WAF, model catalogs, changelogs) and removes src/content/docs/cloudflare-one/traffic-policies/network-policies/ssh-logging.mdx plus dozens of partials — none of which are mentioned.
- **Fix:** Describe the full scope of the diff in the PR description, or rebase the branch so the diff contains only the Email Service changes.

Code Review

This code review is in beta and may not always be helpful — use your judgment.

Warnings (1)
File Issue
dns/nameservers/nameserver-options.mdx line 25 PR scope mismatch — The PR title is '[Email Service] Document account-wide suppressions', but the changed file is src/content/docs/dns/nameservers/nameserver-options.mdx and the additions describe Cloudflare DNS nameserver assignment behavior, not email suppressions. Fix: Verify this is the intended file/branch for the PR. If these DNS nameserver changes are unrelated to the PR's stated purpose, move them to the correct PR or update the PR title and description.

Conventions

Warnings (1)
File Issue
PR Scope accuracy — The description only covers Email Service suppression documentation, but the diff touches ~770 files across many unrelated product areas (Cloudflare WAN, Cloudflare One, Workers, AI Search, Radar, WAF, model catalogs, changelogs) and removes src/content/docs/cloudflare-one/traffic-policies/network-policies/ssh-logging.mdx plus dozens of partials — none of which are mentioned. Fix: Describe the full scope of the diff in the PR description, or rebase the branch so the diff contains only the Email Service changes.

Style Guide Review

No style-guide issues found.

Commands

Only codeowners can run commands. Post a comment with the command to trigger it.

Command Description
/review Runs a review now. Incremental if a prior review exists, full if not.
/full-review Re-reviews the entire PR diff from scratch, ignoring incremental history. Useful after a rebase, when you want a fresh review, or if the bot gets out of sync and reports issues that no longer exist.
/ignore-review-limit Permanently lifts the 2-review automatic limit for this PR. Future pushes will trigger reviews as normal.
/disable-auto-review Stops automatic reviews from triggering on future pushes to this PR. Codeowners can still run /review or /full-review manually.
/rebase Rebases the PR branch against production. On conflict, attempts to resolve automatically using AI. Stops with an explanation if confidence is not high enough.

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

This pull request requires reviews from CODEOWNERS as it changes files that match the following patterns:

Pattern Owners
* @cloudflare/product-owners
*.ts @cloudflare/content-engineering, @kodster28
/.github/CODEOWNERS @cloudflare/product-owners, @cloudflare/content-engineering, @kodster28
/.github/ @cloudflare/content-engineering, @kodster28, @mvvmm, @colbywhite, @ahaywood, @MohamedH1998
package.json @cloudflare/content-engineering
/public/__redirects @cloudflare/content-engineering, @cloudflare/product-owners
/src/assets/images/ @cloudflare/pm-changelogs, @cloudflare/product-owners
/src/assets/images/radar/ @cloudflare/pm-changelogs, @cloudflare/product-owners, @laiyi-ohlsen
*.astro @cloudflare/content-engineering, @kodster28
/src/components/models/ @mchenco, @superhighfives, @shridhar-cf, @ethulia, @kflansburg, @cloudflare/content-engineering, @cloudflare/product-owners, @kodster28
/src/content/catalog-models/ @abhishekkankani, @palashgo, @thebongy, @roerohan, @kathayl, @mchenco, @zeke, @superhighfives, @shridhar-cf, @mattrothenberg, @ethulia, @kflansburg, @cloudflare/content-engineering, @cloudflare/product-owners
/src/content/changelog/ @cloudflare/pm-changelogs, @cloudflare/product-owners
/src/content/changelog/ai-search/ @cloudflare/pm-changelogs, @rita3ko, @irvinebroque, @aninibread, @mchenco, @cloudflare/product-owners
/src/content/changelog/cloudflare-one/ @kennyj42, @asamborski, @cloudflare/pm-changelogs, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/changelog/cloudflare-wan/ @steve-cloudflare, @jeffh-cloudflare, @alpdot, @cloudflare/pm-changelogs, @cloudflare/product-owners
/src/content/changelog/log-explorer/ @angelampcosta, @sahidya, @cjolowicz, @cloudflare/pm-changelogs, @cloudflare/product-owners
/src/content/changelog/logs/ @soheiokamoto, @angelampcosta, @rianvdm, @sahidya, @cloudflare/pm-changelogs, @cloudflare/product-owners
/src/content/changelog/radar/ @cloudflare/pm-changelogs, @cloudflare/product-owners, @laiyi-ohlsen
/src/content/changelog/waf/ @worenga, @cloudflare/firewall, @vs-mg, @fb1337, @cloudflare/pm-changelogs, @cloudflare/appsec-reviewers, @cloudflare/product-owners, @danielegm, @ay-cf, @xmflsct
/src/content/docs/agent-memory/ @lambrospetrou, @rts-rob, @pmesgari, @cloudflare/product-owners
/src/content/docs/ai-gateway/ @abhishekkankani, @palashgo, @thebongy, @roerohan, @kathayl, @mchenco, @zeke, @superhighfives, @shridhar-cf, @adriandlam, @mattrothenberg, @ethulia, @aninibread, @kflansburg, @cloudflare/product-owners
/src/content/docs/ai-search/ @rita3ko, @irvinebroque, @aninibread, @G4brym, @mchenco, @cloudflare/product-owners
/src/content/docs/analytics/ @soheiokamoto, @angelampcosta, @rianvdm, @cloudflare/product-owners
/src/content/docs/api-shield/ @cloudflare/appsec-reviewers, @xmflsct, @danielegm, @cloudflare/product-owners, @janrueth, @djhworld, @alexpovel, @mattrighetti, @abdelrahman-t
/src/content/docs/argo-smart-routing/ @cloudflare/product-owners, @ncrouch-cflare
/src/content/docs/artifacts/ @dmmulroy, @mattzcarey, @dinasaur404, @zebp, @cloudflare/product-owners
/src/content/docs/bots/ @cloudflare/appsec-reviewers, @cloudflare/product-owners, @marinaelmore, @njustus1, @migueldemoura, @olipayne, @cf-jian, @worenga
/src/content/docs/browser-run/ @mchenco, @cloudflare/product-owners, @celso, @kathayl, @meddulla, @simonabadoiu, @jonnyparris, @ruifigueira, @Refaerds, @omarmosid
/src/content/docs/cache/ @cloudflare/product-owners, @ack-cf, @zaidoon1, @mbullock1986
/src/content/docs/client-side-security/ @cloudflare/appsec-reviewers, @xmflsct, @danielegm, @cloudflare/product-owners
/src/content/docs/cloudflare-challenges/ @cloudflare/appsec-reviewers, @cloudflare/product-owners, @marinaelmore, @migueldemoura, @njustus1, @olipayne, @cf-jian, @worenga
/src/content/docs/cloudflare-for-platforms/cloudflare-for-saas/ @baubuchon-cf, @irvinebroque, @dinasaur404, @cloudflare/appsec-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/access-controls/ @kennyj42, @asamborski, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/data-loss-prevention/ @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/ @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/insights/dex/ @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/integrations/ @cloudflare/cf1-reviewers, @cloudflare/product-owners, @mmiranda-cf, @zesilva63, @mkdewidar, @marcinflare, @jlu-cloudflare, @pjennings1020, @TylerStanish, @claudiocn
/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/ @nikitacano, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/team-and-resources/devices/ @cf-rhett, @csujedihy, @lpraneis, @jiulingz, @tojens-ietf, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-one/traffic-policies/ @alexmoraru7, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/cloudflare-wan/ @steve-cloudflare, @jeffh-cloudflare, @alpdot, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/d1/ @rita3ko, @irvinebroque, @vy-ton, @ivoryibu, @rts-rob, @joshthoward, @lambrospetrou, @cloudflare/product-owners
/src/content/docs/data-localization/ @mathew-cf, @aberglund-cf, @cferike, @cagrawal, @Arkanayan, @connect-avinash31, @umeshgtank, @angelampcosta, @cloudflare/appsec-reviewers, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/dns/ @hannes-cf, @cloudflare/product-owners, @esomoza-cf, @fattouche, @xofyarg, @dklbreitling, @chreo, @svenr-cf, @kerolasa, @matildeopbravo, @vavrusa, @mworsley-cloudflare, @sebastiaanyn, @vendemiat, @Woutifier
/src/content/docs/dns/internal-dns/ @hannes-cf, @cloudflare/cf1-reviewers, @cloudflare/product-owners, @esomoza-cf, @fattouche, @xofyarg, @dklbreitling, @chreo, @svenr-cf, @kerolasa, @matildeopbravo, @vavrusa, @mworsley-cloudflare, @sebastiaanyn, @vendemiat, @Woutifier
/src/content/docs/durable-objects/ @rita3ko, @irvinebroque, @vy-ton, @iglesiasbrandon, @joshthoward, @danlapid, @lambrospetrou, @mikenomitch, @cloudflare/product-owners
/src/content/docs/dynamic-workers/ @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @korinne, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @cloudflare/dev-plat-leads, @cloudflare/workers-runtime-1
/src/content/docs/flagship/ @roerohan, @palashgo, @akshitsinha, @abhishekkankani, @thebongy, @cloudflare/flagship, @irvinebroque, @ishita1805, @vaibhavshn, @karishnu, @cloudflare/product-owners
/src/content/docs/fundamentals/ @cloudflare/product-owners, @KaydeeDee, @adambouhmad
/src/content/docs/hyperdrive/ @rita3ko, @irvinebroque, @vy-ton, @ivoryibu, @thomasgauvin, @sejoker, @knickish, @cloudflare/product-owners
/src/content/docs/kv/ @thomasgauvin, @irvinebroque, @rts-rob, @vy-ton, @cloudflare/product-owners
/src/content/docs/learning-paths/ @cloudflare/product-owners
/src/content/docs/log-explorer/ @angelampcosta, @sahidya, @cjolowicz, @cloudflare/product-owners
/src/content/docs/logs/ @soheiokamoto, @angelampcosta, @rianvdm, @sahidya, @cloudflare/product-owners
/src/content/docs/magic-transit/ @steve-cloudflare, @jeffh-cloudflare, @alpdot, @cloudflare/product-owners
/src/content/docs/multi-cloud-networking/ @steve-cloudflare, @jeffh-cloudflare, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/docs/network/ip-geolocation.mdx @cloudflare/product-owners, @mbullock1986
/src/content/docs/pages/ @cloudflare/workers-docs, @GregBrimble, @WalshyDev, @aninibread, @irvinebroque, @cloudflare/product-owners, @MattieTK, @scottbuscemi
/src/content/docs/pages/framework-guides/ @cloudflare/wrangler, @aninibread, @GregBrimble, @cloudflare/product-owners, @MattieTK, @scottbuscemi
/src/content/docs/pipelines/ @Marcinthecloud, @cmackenzie1, @oliy, @garvit-gupta, @sejoker, @jonesphillip, @cloudflare/product-owners
/src/content/docs/queues/ @jonesphillip, @harshil1712, @mia303, @cloudflare/product-owners
/src/content/docs/r2/ @jonesphillip, @harshil1712, @helloimalastair, @rdimaio, @cloudflare/workers-docs, @cloudflare/product-owners
/src/content/docs/radar/ @cdeath, @rubenalex, @cloudflare/radar, @cloudflare/product-owners, @laiyi-ohlsen
/src/content/docs/realtime/ @cloudflare/product-owners, @cloudflare/realtime, @cloudflare/RealtimeKit, @roerohan, @ravindra-cloudflare
/src/content/docs/reference-architecture/ @securitypedant, @cloudflare/product-owners, @ncrouch-cflare
/src/content/docs/rules/ @cloudflare/appsec-reviewers, @smarsh-cf, @maurizioabba, @cloudflare/product-owners, @mbullock1986
/src/content/docs/security/ @cloudflare/appsec-reviewers, @xmflsct, @danielegm, @cloudflare/product-owners, @davejbax, @zrkn, @hemanthk1099
/src/content/docs/smart-shield/configuration/cache-reserve/ @cloudflare/appsec-reviewers, @cloudflare/product-owners, @ncrouch-cflare, @ack-cf, @zaidoon1, @mbullock1986
/src/content/docs/ssl/post-quantum-cryptography @lukevalenta, @cjpatton, @bwesterb, @Lekensteyn, @goldbe-cf, @cloudflare/appsec-reviewers, @cloudflare/product-owners
/src/content/docs/style-guide/ @cloudflare/product-owners
/src/content/docs/tunnel/ @nikitacano, @cloudflare/appsec-reviewers, @cloudflare/product-owners
/src/content/docs/vectorize/ @vy-ton, @sejoker, @mchenco, @cloudflare/product-owners
/src/content/docs/waf/ @worenga, @cloudflare/firewall, @cloudflare/appsec-reviewers, @cloudflare/product-owners, @danielegm, @xmflsct
/src/content/docs/waf/change-log/ @worenga, @cloudflare/firewall, @vs-mg, @cloudflare/appsec-reviewers, @cloudflare/product-owners, @danielegm, @ay-cf, @xmflsct
/src/content/docs/web-analytics/ @cloudflare/product-owners, @ryantownsend, @tkadlec, @ack-cf, @cnachiappan-dev, @mbullock1986
/src/content/docs/workers-ai/ @rita3ko, @craigsdennis, @mchenco, @zeke, @superhighfives, @shridhar-cf, @mattrothenberg, @ethulia, @aninibread, @kflansburg, @cloudflare/product-owners
/src/content/docs/workers-vpc/ @nikitacano, @thomasgauvin, @cloudflare/product-owners
/src/content/docs/workers/ @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @korinne, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @cloudflare/dev-plat-leads, @vy-ton, @cloudflare/workers-runtime-1
/src/content/docs/workers/framework-guides/automatic-configuration.mdx @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @korinne, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @cloudflare/dev-plat-leads, @vy-ton, @cloudflare/workers-runtime-1, @scottbuscemi
/src/content/docs/workers/framework-guides/web-apps/nextjs.mdx @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @korinne, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @cloudflare/dev-plat-leads, @vy-ton, @cloudflare/workers-runtime-1, @scottbuscemi
/src/content/docs/workers/framework-guides/web-apps/opennext.mdx @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @korinne, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @cloudflare/dev-plat-leads, @vy-ton, @cloudflare/workers-runtime-1, @scottbuscemi
/src/content/docs/workers/static-assets @irvinebroque, @GregBrimble, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @MattieTK, @vy-ton
/src/content/docs/workflows/ @rita3ko, @irvinebroque, @vy-ton, @celso, @deloreyj, @mia303, @jonesphillip, @cloudflare/product-owners
/src/content/fields/ @cloudflare/appsec-reviewers, @maurizioabba, @mbullock1986, @danielegm, @xmflsct
/src/content/pages-framework-presets/ @cloudflare/product-owners, @scottbuscemi
/src/content/partials/browser-run/ @mchenco, @cloudflare/product-owners, @celso, @kathayl, @meddulla, @simonabadoiu, @jonnyparris, @ruifigueira, @Refaerds, @omarmosid
/src/content/partials/cache/ @cloudflare/product-owners, @ack-cf, @zaidoon1, @mbullock1986
/src/content/partials/cloudflare-for-platforms/ @baubuchon-cf, @irvinebroque, @dinasaur404, @cloudflare/appsec-reviewers, @cloudflare/product-owners
/src/content/partials/cloudflare-one/access/ @kennyj42, @asamborski, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/partials/cloudflare-one/ @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/partials/cloudflare-one/tunnel/ @nikitacano, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/partials/cloudflare-one/warp/ @cf-rhett, @csujedihy, @lpraneis, @jiulingz, @tojens-ietf, @cloudflare/cf1-reviewers, @cloudflare/product-owners
/src/content/partials/durable-objects/ @rita3ko, @irvinebroque, @vy-ton, @iglesiasbrandon, @joshthoward, @danlapid, @lambrospetrou, @mikenomitch, @cloudflare/product-owners
/src/content/partials/networking-services/ @steve-cloudflare, @jeffh-cloudflare, @alpdot, @cloudflare/product-owners
/src/content/partials/realtime/ @cloudflare/realtime, @cloudflare/RealtimeKit, @roerohan, @ravindra-cloudflare, @cloudflare/product-owners
/src/content/partials/turnstile/ @worenga, @cloudflare/appsec-reviewers, @cloudflare/product-owners, @marinaelmore, @njustus1, @migueldemoura, @olipayne, @cf-jian, @worenga
/src/content/partials/waf/ @worenga, @cloudflare/firewall, @cloudflare/appsec-reviewers, @cloudflare/product-owners, @danielegm, @xmflsct
/src/content/partials/workers/ @cloudflare/workers-docs, @GregBrimble, @irvinebroque, @mikenomitch, @WalshyDev, @cloudflare/deploy-config, @cloudflare/product-owners, @cloudflare/wrangler, @MattieTK, @vy-ton, @cloudflare/workers-runtime-1
/src/content/release-notes/ai-search.yaml @rita3ko, @irvinebroque, @aninibread, @G4brym, @mchenco, @cloudflare/product-owners
/src/content/release-notes/realtimekit-recording-sdk.yaml @cloudflare/realtime, @cloudflare/RealtimeKit, @roerohan, @ravindra-cloudflare, @cloudflare/product-owners
/src/content/release-notes/realtimekit-web-core.yaml @cloudflare/realtime, @cloudflare/RealtimeKit, @roerohan, @ravindra-cloudflare, @cloudflare/product-owners
/src/content/release-notes/realtimekit-web-ui-kit.yaml @cloudflare/realtime, @cloudflare/RealtimeKit, @roerohan, @ravindra-cloudflare, @cloudflare/product-owners
/src/content/release-notes/workers.yaml @cloudflare/workers-docs, @GregBrimble, @WalshyDev, @aninibread, @cloudflare/deploy-config, @cloudflare/product-owners, @irvinebroque, @mikenomitch, @MattieTK
/src/content/workers-ai-models/ @craigsdennis, @mchenco, @superhighfives, @shridhar-cf, @ethulia, @kflansburg, @cloudflare/product-owners, @kodster28
/src/pages/ai/models/ @mchenco, @superhighfives, @shridhar-cf, @ethulia, @kflansburg, @cloudflare/content-engineering, @cloudflare/product-owners, @kodster28
/src/pages/workers-ai/models/ @mchenco, @superhighfives, @shridhar-cf, @ethulia, @kflansburg, @cloudflare/content-engineering, @cloudflare/product-owners, @kodster28
/src/util/api.ts @cloudflare/content-engineering, @kodster28
/src/util/models/ @mchenco, @superhighfives, @shridhar-cf, @ethulia, @kflansburg, @cloudflare/content-engineering, @cloudflare/product-owners, @kodster28

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 24, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://ruisilva-email-2041.previews.developers.cloudflare.com (commit 844e126)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Cancelled 🚫

View logs ↗
2136176 2026-08-28T14:50:38.211Z View logs ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://b13d3322.previews.developers.cloudflare.com 844e126 2026-08-28T09:57:43.990Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://6dd92ed3.previews.developers.cloudflare.com 9e35426 2026-08-26T21:26:43.323Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ac95385f-cloudflare-docs.cloudflare-docs.workers.dev 1aa8b47 2026-08-24T11:15:04.582Z Visit the dashboard ↗

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Preview URL: https://2136176b.preview.developers.cloudflare.com
Preview Branch URL: https://ruisilva-email-2041.preview.developers.cloudflare.com

Files with changes (up to 15)

Original Link Updated Link
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/juniper/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/juniper/
https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/juniper/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/third-party/juniper/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/cisco-meraki-static/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/cisco-meraki-static/
https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/cisco-meraki-static/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/third-party/cisco-meraki-static/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/palo-alto/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/palo-alto/
https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/palo-alto/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/third-party/palo-alto/
https://developers.cloudflare.com/cloudflare-wan/reference/traffic-steering/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/reference/traffic-steering/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering/
https://developers.cloudflare.com/fundamentals/api/reference/permissions/ https://ruisilva-email-2041.preview.developers.cloudflare.com/fundamentals/api/reference/permissions/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/fortinet/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/third-party/fortinet/
https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/fortinet/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/third-party/fortinet/
https://developers.cloudflare.com/cloudflare-wan/configuration/appliance/configure-virtual-appliance/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/appliance/configure-virtual-appliance/
https://developers.cloudflare.com/cloudflare-wan/configuration/appliance/configure-hardware-appliance/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-wan/configuration/appliance/configure-hardware-appliance/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/appliance/configure-virtual-appliance/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/configuration/appliance/configure-virtual-appliance/
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/troubleshooting/tunnel-health/ https://ruisilva-email-2041.preview.developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-wan/troubleshooting/tunnel-health/

Comment thread src/content/docs/email-service/api/send-emails/smtp.mdx Outdated

When some recipients are suppressed, Email Service removes them and continues processing the remaining recipients. When every recipient is suppressed, the server returns `250 2.0.0 Ok` but does not deliver the message.

Use [Email sending logs](/email-service/observability/logs/) to confirm delivery. Suppressed recipients appear with a **Rejected** result.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as above


Search with a complete address or a username. A username search checks that username across every domain. For example, `alex` matches `alex@example.com` and `alex@example.org`.

## 2. Add a suppression in the dashboard

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we mention the import button and supported formats here?

---

Suppression lists prevent emails from being sent to addresses that should not receive them, protecting your sender reputation and ensuring compliance with anti-spam regulations.
An Email Sending suppression list contains recipients that Email Service does not contact. Suppressions protect your sender reputation and help prevent unwanted mail.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
An Email Sending suppression list contains recipients that Email Service does not contact. Suppressions protect your sender reputation and help prevent unwanted mail.
An Email Sending suppression list contains recipients that Email Service does not contact. Suppressions protect your sender reputation and help prevent sending unwanted mail.

Cloudflare creates suppressions after eligible delivery failures and spam complaints. You can create manual suppressions for recipients who should not receive your mail. The management API can also return Cloudflare-managed policy entries.

Cloudflare automatically manages suppressions for your account to preserve your reputation as an email sender.
To add or remove entries, refer to [Manage suppressions](/email-service/configuration/suppressions/).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
To add or remove entries, refer to [Manage suppressions](/email-service/configuration/suppressions/).
To add or remove entries, refer to [Manage suppressions](/email-service/configuration/suppressions/). Suppressions only apply to Email Sending.

- **Hard bounces**: Invalid or non-existent email addresses are immediately suppressed.
- **Repeated soft bounces**: Addresses that repeatedly fail delivery are temporarily or permanently suppressed based on the frequency and pattern of failures.
- **Spam complaints**: Recipients who marked emails as spam. Cloudflare integrates with Postmasters to receive spam complaints and automatically updates your account suppression list to prevent you from sending emails to this email address and preserve your email sending reputation.
The Email Sending dashboard and suppression management API are account-scoped. New entries created through these interfaces apply to every sending domain and subdomain in the account.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The Email Sending dashboard and suppression management API are account-scoped. New entries created through these interfaces apply to every sending domain and subdomain in the account.
Suppressions are account-scoped. Once an email address is on the suppression list, sending to that email address from any of the domains within your account will be suppressed.
If you need to have different suppression lists for different use cases, consider using separate Cloudflare accounts.

The Email Sending dashboard and suppression management API are account-scoped. New entries created through these interfaces apply to every sending domain and subdomain in the account.

You may also manually add or remove email addresses from your suppression list as needed. The removal of email addresses that have been automatically added to your suppression list as a result of a spam complaint is limited to avoid abuse.
These interfaces do not let you create zone-scoped or domain-scoped entries. Each recipient can have only one active Email Sending suppression per account.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
These interfaces do not let you create zone-scoped or domain-scoped entries. Each recipient can have only one active Email Sending suppression per account.

| Reason | Created when | Expiration | Customer action |
| ------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- | --------------------------------------------------------------------- |
| Manual (`manual`) | You add the recipient through the dashboard or API | The time you choose, or no expiration | Change the expiration or delete the entry |
| Spam complaint (`complaint`) | Cloudflare receives and validates a complaint from the recipient's email provider | Created without an expiration | Delete only after the recipient provides new consent |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Delete only after the recipient provides new consent

What does this mean?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applies to all other rows

| ------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- | --------------------------------------------------------------------- |
| Manual (`manual`) | You add the recipient through the dashboard or API | The time you choose, or no expiration | Change the expiration or delete the entry |
| Spam complaint (`complaint`) | Cloudflare receives and validates a complaint from the recipient's email provider | Created without an expiration | Delete only after the recipient provides new consent |
| Hard bounce (`hard_bounce`) | The receiving system permanently rejects an eligible recipient | 7 days by default | Wait for expiration, or delete only after verifying the address |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| Hard bounce (`hard_bounce`) | The receiving system permanently rejects an eligible recipient | 7 days by default | Wait for expiration, or delete only after verifying the address |
| Hard bounce (`hard_bounce`) | The receiving system permanently rejects an eligible recipient | 7 days | Wait for expiration, or delete only after verifying the address |

| Manual (`manual`) | You add the recipient through the dashboard or API | The time you choose, or no expiration | Change the expiration or delete the entry |
| Spam complaint (`complaint`) | Cloudflare receives and validates a complaint from the recipient's email provider | Created without an expiration | Delete only after the recipient provides new consent |
| Hard bounce (`hard_bounce`) | The receiving system permanently rejects an eligible recipient | 7 days by default | Wait for expiration, or delete only after verifying the address |
| Confirmed invalid recipient (`hard_bounce`) | All observed failures confirm an invalid recipient, or qualifying availability failures persist without a successful delivery | No expiration | Delete only after independently verifying the address |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed invalid recipient

What does this mean in english? Inbox does not exist?

| Hard bounce (`hard_bounce`) | The receiving system permanently rejects an eligible recipient | 7 days by default | Wait for expiration, or delete only after verifying the address |
| Confirmed invalid recipient (`hard_bounce`) | All observed failures confirm an invalid recipient, or qualifying availability failures persist without a successful delivery | No expiration | Delete only after independently verifying the address |
| Soft bounce (`soft_bounce`) | An eligible recipient-side temporary failure occurs, such as a full mailbox or rate limit | 24 hours by default | Wait for expiration, or delete after confirming the issue is resolved |
| Cloudflare-managed metadata (`policy`) | The API returns a policy entry with `read_only: true` | The displayed expiration, or no expiration | Contact [Cloudflare Support](/support/contacting-cloudflare-support/) |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The API returns a policy entry with read_only: true

What API? Is it when trying to send email? Is it the binding?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider omitting this row entirely


### Manual suppressions

Manual suppressions support application-level decisions that Email Service cannot observe. For example, add a manual suppression when a recipient unsubscribes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Manual suppressions support application-level decisions that Email Service cannot observe. For example, add a manual suppression when a recipient unsubscribes.
Manual suppressions allow you to add application-level decisions that Email Service cannot observe. For example, if a user manually unsubcribes from emails in your app, you can add their email to your Email Service suppression list.

Comment on lines +48 to +50
Email providers send feedback reports when recipients mark messages as spam. Cloudflare validates these reports before creating complaint suppressions.

Complaint suppressions are created without an expiration. Delete or shorten one only after the recipient provides new consent, such as a fresh opt-in.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Delete or shorten one only after the recipient provides new consent, such as a fresh opt-in.

This is fully at the user discretion right? "Fresh opt-in within your app" could be more clear

Comment on lines +88 to +94
## Suppression timing

Bounce suppressions rely on background delivery processing and are not immediate. Messages already being delivered can fail before the suppression takes effect.

Complaint suppressions appear after Cloudflare receives and validates the provider report. The provider determines when that report arrives.

Expired entries stop appearing in the public list when their `expires_at` timestamp passes. Delivery enforcement can take additional time to expire. Updates and deletions also propagate asynchronously, so the management list and delivery enforcement can briefly differ.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
## Suppression timing
Bounce suppressions rely on background delivery processing and are not immediate. Messages already being delivered can fail before the suppression takes effect.
Complaint suppressions appear after Cloudflare receives and validates the provider report. The provider determines when that report arrives.
Expired entries stop appearing in the public list when their `expires_at` timestamp passes. Delivery enforcement can take additional time to expire. Updates and deletions also propagate asynchronously, so the management list and delivery enforcement can briefly differ.

I think we can omit this entirely. Too many docs means less reading

Comment on lines +96 to +222
### List suppressions

List active suppressions for the account:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions"
method="GET"
parameters={{ per_page: 50 }}
/>

Each entry contains the following fields:

| Field | Description |
| ------------ | --------------------------------------------------------------------------- |
| `id` | Unique suppression identifier |
| `email` | Suppressed recipient |
| `reason` | `manual`, `complaint`, `hard_bounce`, `soft_bounce`, or `policy` |
| `created_at` | Creation timestamp |
| `expires_at` | Expiration timestamp, or `null` when the entry has no expiration |
| `read_only` | Whether the server prevents customers from updating or deleting the entry |

The account list includes active Email Sending suppressions owned by the account. The API does not return zone or domain scope. New entries created through this API apply account-wide.

### Get one suppression

Retrieve one suppression by ID:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions/{suppression_id}"
method="GET"
/>

The item response also includes its optional `note` field.

### Find an exact address

Use the `email` parameter to check one complete address:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions"
method="GET"
parameters={{ email: "recipient@example.com" }}
/>

An empty `result` array means the account has no active entry for that address.

### Search by username

The `search` parameter accepts a complete address or a username ending in `@`. A username search matches that username across every domain:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions"
method="GET"
parameters={{ search: "alex@" }}
/>

Search is case-insensitive. Values such as `alex` or `@example.com` are invalid API searches. The dashboard automatically adds the trailing `@` for username searches.

### Filter by reason

Use the `reason` parameter to filter API results:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions"
method="GET"
parameters={{ reason: "complaint" }}
/>

Valid values are `manual`, `complaint`, `hard_bounce`, `soft_bounce`, and `policy`.

### Paginate results

The list uses cursor pagination. Read `result_info.next_cursor` and pass it as `cursor`:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions"
method="GET"
parameters={{ per_page: 50, cursor: "$NEXT_CURSOR" }}
/>

Continue until `next_cursor` is `null`. Large, filtered lists can return a short or empty intermediate page with another cursor. Do not treat an empty page as the end while a cursor remains.

The cursor contains the search and reason filters. Keep those filters unchanged while paginating. To change a filter, start again without a cursor.

The response does not include a total count.

### Update a suppression

Use `PATCH` to update the expiration or note:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions/{suppression_id}"
method="PATCH"
json={{
expires_at: null,
note: "Recipient requested a permanent opt-out",
}}
/>

Set `expires_at` to a future ISO 8601 timestamp for a temporary entry. Set it to `null` for no expiration. Omitting a field leaves its current value unchanged, and an empty string clears the note.

The API returns `403` when `read_only` is `true`. Extending an automatic suppression can provide additional protection. Shorten or remove one only after verifying the recipient.

### Remove a suppression

Delete a mutable suppression by ID:

<APIRequest
path="/accounts/{account_id}/email/sending/suppressions/{suppression_id}"
method="DELETE"
/>

The API returns `403` for read-only suppressions. Updates and deletions propagate asynchronously, so the management list and delivery enforcement can briefly differ.

:::caution
Deleting a hard-bounce or complaint suppression permits delivery attempts to an address that already failed or reported your mail as spam. Verify the recipient before deleting the entry.
:::

## 5. Verify suppression changes

Refresh the suppression list after creating or updating an entry. Confirm that the recipient, reason, and expiration match the intended values.

After deleting an entry, confirm that it no longer appears. Delivery enforcement can briefly lag behind the management list.

## 6. Limits

For page size, bulk import, and rate limits, refer to [Suppression list limits](/email-service/platform/limits/#suppression-list-limits).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Too much docs. This doc does not need to explain how to use each endpoint. Can add link to Wrangler and API, or use tabs to show how to add remove for each. But this doc is too long


When the setting is off, the REST API returns `400`, the Workers binding throws `E_RECIPIENT_SUPPRESSED`, and SMTP rejects the message. Any suppressed recipient causes the send to fail.

When the setting is on, Email Service removes suppressed recipients and processes the remaining recipients. If none remain, SMTP may return `250 2.0.0 Ok` without a Message-ID and deliver nothing.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Might be worth clarifying that if all recipients are suppressed, RPC & HTTP will still throw that error

djhworld and others added 5 commits August 28, 2026 10:47
- Removes references to the "Applied Learned Schema" functionality
	removed from the dashboard
- Removes references to the  `cf-risk-missing-schema` label as this is no
	longer applied.
…ltimekit (#32946)

* docs(realtimekit): added release notes for 24 aug 2026 release of realtimekit

* docs(realtimekit): added the new localization key in language-pack

* docs(realtimekit): removed internal fix line
* Add Logpush Transformers documentation (closed beta)

* Resolve VERIFY markers in Logpush Transformers doc

* Rename to Transformers, add Beta badge, clarify Studio

* Remove API reference link (hidden during closed beta)
… downloads (#32915)

* Document self-serve Cloudflare One Virtual Appliance downloads

Update the connector configuration partial so the Cloudflare One Virtual
Appliance is documented as self-serve across VMware ESXi (OVA image),
Proxmox (VM helper script), and a new libvirt/KVM (beta) tab. License keys
are now generated self-serve from the Connectors page.

Co-authored-by: OpenCode <noreply@opencode.ai>
Co-authored-by: Build <noreply@cloudflare.com>
Co-authored-by: Anthropic <noreply@anthropic.com>
Co-authored-by: claude-opus-4-8 <noreply@anthropic.com>

* VMWare > VMware

* Add changelog for self-serve virtual appliance download

Announce selecting a hypervisor (VMware ESXi, Proxmox, libvirt/KVM) and
downloading the Cloudflare One Virtual Appliance image or install script
directly from the Connectors page.

Co-authored-by: OpenCode <noreply@opencode.ai>
Co-authored-by: Build <noreply@cloudflare.com>
Co-authored-by: Anthropic <noreply@anthropic.com>
Co-authored-by: claude-opus-4-8 <noreply@anthropic.com>

---------

Co-authored-by: OpenCode <noreply@opencode.ai>
Co-authored-by: Build <noreply@cloudflare.com>
Co-authored-by: Anthropic <noreply@anthropic.com>
ngayerie and others added 7 commits August 28, 2026 15:49
* Clarify that assigned nameservers cannot be changed

DEE-3776

Common customer question: 'why did my new zone get different
nameservers than my other zones, can we reassign it?' The answer is
already documented but easy to miss. Small changes to make it more
discoverable:

- DNS FAQ: new entry 'Why does my new zone have different nameservers
  than my other zones?' explaining the reasons a new zone can be
  assigned a different pair (cross-account conflict, prior deletion,
  parent/child rules, Foundation DNS color rotation) and how to get
  consistent nameservers via Account custom nameservers or DNS zone
  defaults.
- Nameserver options: replace a plain sentence with a callout that
  points to the new FAQ entry and to the Nameserver consistency section.
- Foundation DNS advanced nameservers: new subsection under Nameservers
  hosting and assignment that explains why a new zone might get a
  different color set (blue / gold / orange) and cross-links Account
  custom nameservers.

* Style guide: remove directional word from Nameserver consistency link

* Address review feedback from @hannes-cf

- faq.mdx: reword 'a different pair' -> 'different nameservers'; drop
  'pair' in the parent/child bullet; use 'set' consistently in the
  delete-and-re-add caveat.
- foundation-dns/advanced-nameservers.mdx: 'The same name is' ->
  'The same domain is', matching the FAQ wording.
- nameservers/nameserver-options.mdx: replace titled ':::note[...]' with
  an untitled ':::caution' (per docs convention and given severity); in
  the adjacent pre-existing caution, replace 'a new pair of nameservers'
  with 'a new set of nameservers' for wording consistency.

Also rebased onto origin/production.
Document post-quantum key agreement on inbound and outbound TLS 1.3 SMTP
connections between Cloudflare Email Security MX deployments and
third-party mail servers.

Split out of #32966 per review feedback.
* fix: serve original images in local dev

The @astrojs/cloudflare/image-service emits /cdn-cgi/image/ URLs that only
exist on Cloudflare's edge, so every image 404s under astro dev. Use the
passthrough service locally (original files are already local, no resizing
needed) and keep the Cloudflare service for production builds.

* fix: trim image service dev-mode comment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.