Send your first message with Email API
One HTTP call from nothing to a message received, how to read the response code correctly, and the three mistakes new accounts hit first.
The goal of this page is one real message received, not understanding the whole API. That is what the Guide section in the console is for.
Before you start
- A sending domain that is active. See Publish the sending domain records
- A saved API key. See Create an API key
- A real mailbox of yours to receive the test
Make the call
Replace cf_... with your key and example.com with your active sending domain.
curl -X POST https://api-vmail.cloudfly.vn/api/emails \
-H "Authorization: Bearer cf_xxxxxxxx_xxxxxxxxxxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"from": "no-reply@example.com",
"to": "you@example.net",
"subject": "First test message",
"text": "If you can read this, Email API is working."
}'Those four fields are the minimum. The full parameter list — attachments, templates, variables, blind copies — is in Email API → Guide.

| Field | Constraint |
|---|---|
from | must belong to an active domain on the account |
to | recipient address |
subject | subject line |
text or html | at least one of the two is required |
Read the response
{
"success": true,
"data": {
"id": "em_a1b2c3d4e5f6",
"from": "no-reply@example.com",
"to": "you@example.net",
"status": "queued",
"created_at": "2026-07-01T10:30:00Z"
}
}The message id is at data.id, not id at the top level — save it to look messages up later.
Every Email API response is wrapped in success + data, error responses included.
Status 202 means accepted for sending, not delivered: the message still has to travel the
sending path and can be refused later.
Where you find out whether it arrived is Stats & logs, or a webhook if your code needs to know immediately.
Anything other than 202 means rejected on the spot. What each code means:
Email API error code reference.
Three first-time mistakes
Authentication rejected
Wrong key, deleted key, or a header missing the Bearer prefix. Copy the key again from where you
saved it — the console list only shows the first characters.
Permission rejected although the key is right
The from address does not belong to a domain the key may send from. Two causes:
- The domain has not finished activating — check the Sending domains page
- The key is a Sending Key bound to a different domain. A Sending Key can only send from its own
202 but no message
In order:
- Check the recipient's junk folder
- Open Stats & logs → Logs tab and look the message up — the status there is the truth
- Check the suppression list: the recipient may be suppressed from an earlier failure, and the message is dropped before it leaves the system
Check your work
Done when all three are true:
- The call returns
202 - The message is in the receiving mailbox, junk folder included
- Stats & logs → Logs tab has a matching row with a successful status
Landing in junk still counts as sent. To improve that, start with the _dmarc record on the
sending domain page.
Next steps
| Goal | Page |
|---|---|
| Know in code whether a message arrived or failed | Receive events by webhook |
| Understand why some addresses cannot be sent to | Read and manage the suppression list |
| Messages send but do not arrive | Troubleshoot Email API |
| Look up an error code you just received | Email API error code reference |
| The full parameter list and code samples | Email API → Guide in the console |
About Email API
Send transactional mail with one HTTP call. This page helps you choose between Email API and Email Relay, and points you to the full parameter reference.
Sending domain
Add a sending domain for Email API then publish the signing and feedback records, without touching the mailboxes you already use.