Skip to content
Oct 3, 2026NewsletterRSS

Cloudflare Stops One Domain's Bounces From Blocking a Whole Account

Cloudflare Email Service now ties bounce and complaint suppressions to the sending domain that caused them instead of the whole account.

2 min read

Cloudflare Email ServiceDeliverability

Hand-drawn illustration of a wall of mail slots with one slot taped shut and the rest open on a hot pink background

Cloudflare Email Service now records bounce and complaint suppressions against the sending domain that caused them, not the whole account, Cloudflare said in a Sept. 25 changelog entry. A recipient whose mail bounced from one domain can still get mail from the account’s other domains.

Bounces now get the narrow scope

Automatic bounce and complaint suppressions now use the new sending_domain scope instead of account. A complaint still becomes account-wide when Cloudflare “cannot identify the sending domain of the original message,” according to Cloudflare’s suppression lists doc, updated the same day. Manual suppressions default to account. API calls that leave out scope create account-level entries. Existing integrations behave as before.

Domain matching is exact. A suppression for myappexample.com does not block mail from mail.myappexample.com. A suppression for mail.myappexample.com does not block myappexample.com either. Cloudflare takes the sending domain from the from address for its REST API and Workers binding and from the envelope MAIL FROM for SMTP.

How long a suppression lasts

Complaint suppressions never expire, the doc says. Neither do hard bounces from a mailbox or domain that doesn’t exist, or from a problem that persists across repeated attempts. Other hard bounces last seven days. Soft bounces, such as a full mailbox, last 24 hours by default. Sender-side authentication or reputation problems don’t create suppressions.

By default, Cloudflare rejects a whole send if any recipient is suppressed. The REST API returns a 400, the Workers binding throws E_RECIPIENT_SUPPRESSED and SMTP rejects the message. A per-domain setting called “Drop suppressed recipients,” off by default, removes them and sends to the rest. Email Sending is still in beta, according to Cloudflare’s docs.

Key takeaways

  • Bounce and complaint suppressions now apply to one sending domain, not the whole account.
  • Manual suppressions and API calls without a scope stay account-wide.
  • Scope matching is exact. A parent domain doesn’t cover its subdomains.
  • Complaints and nonexistent-mailbox bounces never expire. Other bounces expire after seven days or 24 hours.

The take

We think domain scoping suits complaints better than bounces. A spam complaint is about one kind of mail. Someone who reports a newsletter as spam may still want password resets. That complaint should not block receipts sent from another subdomain.

A bounce from a mailbox that doesn’t exist is different. That fact is about the address, not the sender. Now each of an account’s domains has to learn it by bouncing on its own. Every one of those bounces counts against that domain’s reputation.

Teams that already split marketing and transactional mail onto separate subdomains gain the most here. They should still record unsubscribes as account-scoped manual suppressions when the person opted out of everything. They should also watch the sending logs for an address that bounces from more than one domain and suppress it account-wide by hand.