# Send email from Python

Five steps: install `requests`, create a test key, send to the sandbox, read the log, then verify a domain so you can send to anyone.

## 1. Install

No SDK needed. The API is plain JSON over HTTPS, so `requests` is all it takes.

**shell**

```bash
pip install requests
```

## 2. Create an API key

[Sign in](/login), open **API keys** in the dashboard and create a **test** key. It starts with `av_test_`. Export it so the samples can read it:

**shell**

```bash
export AVELTO_API_KEY=av_test_...
```

> **Sandbox rules.** Test keys never deliver anything; they run the pipeline and record events. The sandbox sender `you@sandbox.avelto.dev` only delivers to your account's verified owner email and to the simulator addresses `delivered@`, `bounced@` and `complained@sandbox.avelto.dev`. Anything else is refused with `403 sandbox_recipient_not_allowed`. To send to anyone, verify a domain (step 5).

## 3. Send your first email

Every request carries the key as a bearer token. A rejected send comes back as a non-2xx status with a JSON body of `{ "error": { "code", "message" } }`.

```python
# send.py
import os
import requests

API = "https://api-staging.avelto.dev"
HEADERS = {"Authorization": f"Bearer {os.environ['AVELTO_API_KEY']}"}

r = requests.post(f"{API}/v1/emails", headers=HEADERS, json={
    "from": "you@sandbox.avelto.dev",
    "to": "delivered@sandbox.avelto.dev",
    "subject": "Hello from Avelto",
    "text": "It works.",
})

if r.status_code != 201:
    err = r.json()["error"]
    raise SystemExit(f"{r.status_code} {err['code']}: {err['message']}")

email_id = r.json()["id"]
print(email_id)  # "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10"
```

**shell**

```bash
python send.py
```

The API answers `201 Created` with the email id:

```http
HTTP/1.1 201 Created
Content-Type: application/json

{ "id": "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10" }
```

> **Retrying safely.** Send an `Idempotency-Key` header (any unique string, such as your order id) with every `POST /v1/emails`. If the request times out or comes back `429`, `502`, `503` or `504`, wait a moment and send it again unchanged with the same key: the API returns the original email id instead of sending twice. See [Idempotency](/docs/send-email).

## 4. Check the log

Fetch the email by id. `status` moves from `queued` to `sent` to `delivered`, and `events` records each step: `email.queued`, `email.sent`, `email.delivered`.

```python
r = requests.get(f"{API}/v1/emails/{email_id}", headers=HEADERS)
r.raise_for_status()
email = r.json()

print(email["status"])  # "queued", then "sent", then "delivered"
for event in email["events"]:
    print(event["type"], event["occurred_at"])
```

```json
{
  "id": "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10",
  "mode": "test",
  "from": "you@sandbox.avelto.dev",
  "to": ["delivered@sandbox.avelto.dev"],
  "subject": "Hello from Avelto",
  "status": "delivered",
  "events": [
    {
      "id": "e1f0c3a4-8b2d-4c6e-9a1f-5d7b3e2c8a90",
      "type": "email.queued",
      "payload": {},
      "occurred_at": "2026-09-17T10:12:04.000Z"
    },
    {
      "id": "a7c2e9d1-3f4b-4a8e-b6c0-2d9e1f7b5c34",
      "type": "email.sent",
      "payload": { "test": true, "ses_message_id": "test-9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10" },
      "occurred_at": "2026-09-17T10:12:06.000Z"
    },
    {
      "id": "c4b8d2f6-7e1a-4d3c-8f9b-6a2e0c5d1b78",
      "type": "email.delivered",
      "payload": { "test": true, "recipients": ["delivered@sandbox.avelto.dev"] },
      "occurred_at": "2026-09-17T10:12:06.000Z"
    }
  ]
}
```

## 5. Verify a domain

Add a domain, publish the DNS records it returns (three DKIM CNAMEs, an SPF TXT and a DMARC TXT), then poll `GET /v1/domains/:id` until `status` is `verified`. The GET re-checks DNS on every call. Use a subdomain such as `mail.acme.com`.

```python
# verify_domain.py
import os
import time
import requests

API = "https://api-staging.avelto.dev"
HEADERS = {"Authorization": f"Bearer {os.environ['AVELTO_API_KEY']}"}

r = requests.post(
    f"{API}/v1/domains", headers=HEADERS, json={"name": "mail.acme.com"}
)
r.raise_for_status()
domain = r.json()

for rec in domain["dns_records"]:
    print(rec["type"], rec["name"], rec["value"], f"({rec['purpose']})", sep="\t")

# Publish the records, then poll. GET re-checks DNS on every call.
status = domain["status"]
while status == "pending":
    time.sleep(30)
    r = requests.get(f"{API}/v1/domains/{domain['id']}", headers=HEADERS)
    status = r.json()["status"]

print(status)  # "verified" or "failed"
```

**shell**

```bash
python verify_domain.py
```

Once the domain is verified, switch `AVELTO_API_KEY` to a live key (`av_live_`) and change `from` to an address on it, such as `hello@mail.acme.com`. Nothing else changes.

## Next

- [Send email](/docs/send-email): every field, attachments, tags, scheduling and idempotency.
- [Webhooks](/docs/webhooks): get events pushed to your app, with a Python signature check.
- [Test mode](/docs/test-mode): test keys, the sandbox sender and the simulator addresses.

---

Rendered page: https://staging.avelto.dev/docs/quickstart/python
