← barua.tz

Domains#

Three calls: create the domain, publish the records it returns at your registrar, verify. Nothing is checked at creation, and DNS takes time to propagate, so verification is a call you make when you are ready and can make again at any time. It re-reads DNS and stores what it found, and a record found gone withdraws what that record granted.

Ownership is proved by one TXT record at _barua-verify.<your domain>, holding a token issued for this domain row and nothing else. Barua's sending relay is shared by every customer, so a domain another customer once verified reads as sendable to the relay for good; the token is what stops a second account claiming a name it does not control. Until it is published, sending stays off however the other records look.

Four records are issued: Ownership (that TXT), SPF (a TXT at the domain naming include:_spf.barua.tz), Receiving(an MX pointing at Barua's mail server) and Signing (a TXT at barua._domainkey.<your domain> carrying the DKIM public key). Publish every row records returns; if the relay accepted the domain, its own record appears too. Each row carries published or pending from the last check.

Verification answers with the domain as stored plus checks: ownership is proven, absent or unknown; receiving, signing and spf are published, missing or unknown. Unknown means a resolver did not answer, not that anything is wrong; check again. status becomes verified when ownership is proven. sending turns on when ownership is proven and there is a path for the mail: signing and SPF both published (direct), or the relay still holding the domain. receiving turns on when the MX is published.

A name belongs to one account at a time. Adding one you already hold is 409 domain_exists; a name claimed elsewhere is 409 domain_unavailable, which deliberately does not say whose it is. A claim that was never verified and is more than 7 days old is cleared when you claim the name, since only whoever controls the DNS can then verify it. Removing a domain is refused while it still has mailboxes, and removal keeps the relay registration so the name can come back without new records.

GET /api/v1/domains

List domains. Scope domains:read.

curl
curl https://barua.tz/api/v1/domains \
  -H "Authorization: Bearer barua_YOUR_KEY"
response 200
200, no body
422 invalid_requestThe body or query failed validation. The message names the first field that failed.

POST /api/v1/domains

Connect a domain. Scope domains:write.

Registers the name and returns the DNS records to publish. Nothing is checked yet, and the domain cannot send until POST /domains/{id}/verify finds the ownership record published. A name belongs to one account at a time, with one exception: a claim that was never verified and is more than 7 days old is cleared when someone else claims the name, since only whoever controls the DNS can then verify it. Up to 20 domains per account.

curl
curl https://barua.tz/api/v1/domains \
  -H "Authorization: Bearer barua_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "dukalangu.co.tz"
  }'
response 201
201
{
  "id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
  "name": "dukalangu.co.tz",
  "status": "pending",
  "ownershipVerified": false,
  "sending": false,
  "receiving": false,
  "direct": false,
  "records": [
    {
      "record": "Ownership",
      "type": "TXT",
      "name": "_barua-verify.dukalangu.co.tz",
      "value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
      "status": "pending"
    },
    {
      "record": "SPF",
      "type": "TXT",
      "name": "dukalangu.co.tz",
      "value": "v=spf1 include:_spf.barua.tz ~all",
      "status": "pending"
    },
    {
      "record": "Receiving",
      "type": "MX",
      "name": "dukalangu.co.tz",
      "value": "10 mx.tznova.com",
      "status": "pending"
    },
    {
      "record": "Signing",
      "type": "TXT",
      "name": "barua._domainkey.dukalangu.co.tz",
      "value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "status": "pending"
    }
  ],
  "createdAt": "2026-09-24T07:58:12.000Z",
  "lastCheckedAt": "2026-09-24T07:58:12.000Z"
}
400 invalid_jsonThe request body could not be parsed as JSON.
409 domain_existsThe domain is already on this account.
409 domain_unavailableThe name is claimed elsewhere and cannot be added here. Whether it belongs to another Barua account is deliberately not confirmed. A claim that was never verified and is more than a week old is cleared instead, and the name can be claimed.
409 domain_limitThe account already has 20 domains.
422 invalid_requestThe body or query failed validation. The message names the first field that failed.

GET /api/v1/domains/{id}

Get a domain. Scope domains:read.

The domain as stored, with each record's status from the last verification.

curl
curl https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708 \
  -H "Authorization: Bearer barua_YOUR_KEY"
response 200
200
{
  "id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
  "name": "dukalangu.co.tz",
  "status": "verified",
  "ownershipVerified": true,
  "sending": true,
  "receiving": true,
  "direct": true,
  "records": [
    {
      "record": "Ownership",
      "type": "TXT",
      "name": "_barua-verify.dukalangu.co.tz",
      "value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
      "status": "published"
    },
    {
      "record": "SPF",
      "type": "TXT",
      "name": "dukalangu.co.tz",
      "value": "v=spf1 include:_spf.barua.tz ~all",
      "status": "published"
    },
    {
      "record": "Receiving",
      "type": "MX",
      "name": "dukalangu.co.tz",
      "value": "10 mx.tznova.com",
      "status": "published"
    },
    {
      "record": "Signing",
      "type": "TXT",
      "name": "barua._domainkey.dukalangu.co.tz",
      "value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "status": "published"
    }
  ],
  "createdAt": "2026-09-24T07:58:12.000Z",
  "lastCheckedAt": "2026-09-24T09:31:40.000Z"
}
404 not_foundNo domain, sub-account or key with that id on this account.

POST /api/v1/domains/{id}/verify

Check the domain's DNS now. Scope domains:write.

Reads DNS now, stores what it found, and answers synchronously. Run it after publishing records and again whenever you like: a record found gone withdraws what it granted. Ownership is proved by the _barua-verify TXT record; status becomes verified only when it is. sending turns on when ownership is proven and either both the signing and SPF records are published (direct) or the relay still holds the domain. receiving turns on when the MX record is published. unknown in checks means a resolver did not answer, not that anything is wrong.

curl
curl -X POST https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708/verify \
  -H "Authorization: Bearer barua_YOUR_KEY"
response 200
200
{
  "id": "5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708",
  "name": "dukalangu.co.tz",
  "status": "verified",
  "ownershipVerified": true,
  "sending": true,
  "receiving": true,
  "direct": true,
  "records": [
    {
      "record": "Ownership",
      "type": "TXT",
      "name": "_barua-verify.dukalangu.co.tz",
      "value": "barua-verify=k3Jx9vQ2mN8pL5wR7tY1uZ4aB6cD0eFg",
      "status": "published"
    },
    {
      "record": "SPF",
      "type": "TXT",
      "name": "dukalangu.co.tz",
      "value": "v=spf1 include:_spf.barua.tz ~all",
      "status": "published"
    },
    {
      "record": "Receiving",
      "type": "MX",
      "name": "dukalangu.co.tz",
      "value": "10 mx.tznova.com",
      "status": "published"
    },
    {
      "record": "Signing",
      "type": "TXT",
      "name": "barua._domainkey.dukalangu.co.tz",
      "value": "v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "status": "published"
    }
  ],
  "createdAt": "2026-09-24T07:58:12.000Z",
  "lastCheckedAt": "2026-09-24T09:31:40.000Z",
  "checks": {
    "ownership": "proven",
    "receiving": "published",
    "signing": "published",
    "spf": "published"
  }
}
404 not_foundNo domain, sub-account or key with that id on this account.

DELETE /api/v1/domains/{id}

Remove a domain. Scope domains:write.

Refused while the domain still has active mailboxes. Its relay registration is kept, so the name can be connected again later without new DNS records.

curl
curl -X DELETE https://barua.tz/api/v1/domains/5f0c1a2b-6d7e-4f80-91a2-b3c4d5e6f708 \
  -H "Authorization: Bearer barua_YOUR_KEY"
response 204
204, no body
404 not_foundNo domain, sub-account or key with that id on this account.
409 domain_in_useThe domain still has active mailboxes. Remove them first.