Domains#
Three calls: create the domain, publish the records it returns at your registrar, verify. Nothing is checked at creation, and DNS takes time to propagate, so verification is a call you make when you are ready and can make again at any time. It re-reads DNS and stores what it found, and a record found gone withdraws what that record granted.
Ownership is proved by one TXT record at , holding a token issued for this domain row and nothing else. Barua's sending relay is shared by every customer, so a domain another customer once verified reads as sendable to the relay for good; the token is what stops a second account claiming a name it does not control. Until it is published, sending stays off however the other records look.
Four records are issued: (that TXT), (a TXT at the domain naming ), (an MX pointing at Barua's mail server) and (a TXT at carrying the DKIM public key). Publish every row returns; if the relay accepted the domain, its own record appears too. Each row carries or from the last check.
Verification answers with the domain as stored plus : is , or ; , and are , or . Unknown means a resolver did not answer, not that anything is wrong; check again. becomes when ownership is proven. turns on when ownership is proven and there is a path for the mail: signing and SPF both published (), or the relay still holding the domain. turns on when the MX is published.
A name belongs to one account at a time. Adding one you already hold is ; a name claimed elsewhere is , which deliberately does not say whose it is. A claim that was never verified and is more than 7 days old is cleared when you claim the name, since only whoever controls the DNS can then verify it. Removing a domain is refused while it still has mailboxes, and removal keeps the relay registration so the name can come back without new records.
GET /api/v1/domains
List domains. Scope .
curl https://barua.tz/api/v1/domains \
-H "Authorization: Bearer barua_YOUR_KEY"
POST /api/v1/domains
Connect a domain. Scope .
Registers the name and returns the DNS records to publish. Nothing is checked yet, and the domain cannot send until POST /domains/{id}/verify finds the ownership record published. A name belongs to one account at a time, with one exception: a claim that was never verified and is more than 7 days old is cleared when someone else claims the name, since only whoever controls the DNS can then verify it. Up to 20 domains per account.
curl https://barua.tz/api/v1/domains \
-H "Authorization: Bearer barua_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "dukalangu.co.tz"
}'
201
{
"id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
"name": "dukalangu.co.tz",
"status": "pending",
"ownershipVerified": false,
"sending": false,
"receiving": false,
"direct": false,
"records": [
{
"record": "Ownership",
"type": "TXT",
"name": "_barua-verify.dukalangu.co.tz",
"value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
"status": "pending"
},
{
"record": "SPF",
"type": "TXT",
"name": "dukalangu.co.tz",
"value": "v=spf1 include:_spf.barua.tz ~all",
"status": "pending"
},
{
"record": "Receiving",
"type": "MX",
"name": "dukalangu.co.tz",
"value": "10 mx.tznova.com",
"status": "pending"
},
{
"record": "Signing",
"type": "TXT",
"name": "barua._domainkey.dukalangu.co.tz",
"value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
"status": "pending"
}
],
"createdAt": "2026-09-24T07:58:12.000Z",
"lastCheckedAt": "2026-09-24T07:58:12.000Z"
}
GET /api/v1/domains/{id}
Get a domain. Scope .
The domain as stored, with each record's status from the last verification.
curl https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708 \
-H "Authorization: Bearer barua_YOUR_KEY"
200
{
"id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
"name": "dukalangu.co.tz",
"status": "verified",
"ownershipVerified": true,
"sending": true,
"receiving": true,
"direct": true,
"records": [
{
"record": "Ownership",
"type": "TXT",
"name": "_barua-verify.dukalangu.co.tz",
"value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
"status": "published"
},
{
"record": "SPF",
"type": "TXT",
"name": "dukalangu.co.tz",
"value": "v=spf1 include:_spf.barua.tz ~all",
"status": "published"
},
{
"record": "Receiving",
"type": "MX",
"name": "dukalangu.co.tz",
"value": "10 mx.tznova.com",
"status": "published"
},
{
"record": "Signing",
"type": "TXT",
"name": "barua._domainkey.dukalangu.co.tz",
"value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
"status": "published"
}
],
"createdAt": "2026-09-24T07:58:12.000Z",
"lastCheckedAt": "2026-09-24T09:31:40.000Z"
}
POST /api/v1/domains/{id}/verify
Check the domain's DNS now. Scope .
Reads DNS now, stores what it found, and answers synchronously. Run it after publishing records and again whenever you like: a record found gone withdraws what it granted. Ownership is proved by the _barua-verify TXT record; status becomes verified only when it is. sending turns on when ownership is proven and either both the signing and SPF records are published (direct) or the relay still holds the domain. receiving turns on when the MX record is published. unknown in checks means a resolver did not answer, not that anything is wrong.
curl -X POST https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708/verify \
-H "Authorization: Bearer barua_YOUR_KEY"
200
{
"id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
"name": "dukalangu.co.tz",
"status": "verified",
"ownershipVerified": true,
"sending": true,
"receiving": true,
"direct": true,
"records": [
{
"record": "Ownership",
"type": "TXT",
"name": "_barua-verify.dukalangu.co.tz",
"value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
"status": "published"
},
{
"record": "SPF",
"type": "TXT",
"name": "dukalangu.co.tz",
"value": "v=spf1 include:_spf.barua.tz ~all",
"status": "published"
},
{
"record": "Receiving",
"type": "MX",
"name": "dukalangu.co.tz",
"value": "10 mx.tznova.com",
"status": "published"
},
{
"record": "Signing",
"type": "TXT",
"name": "barua._domainkey.dukalangu.co.tz",
"value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
"status": "published"
}
],
"createdAt": "2026-09-24T07:58:12.000Z",
"lastCheckedAt": "2026-09-24T09:31:40.000Z",
"checks": {
"ownership": "proven",
"receiving": "published",
"signing": "published",
"spf": "published"
}
}
DELETE /api/v1/domains/{id}
Remove a domain. Scope .
Refused while the domain still has active mailboxes. Its relay registration is kept, so the name can be connected again later without new DNS records.
curl -X DELETE https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708 \
-H "Authorization: Bearer barua_YOUR_KEY"