{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "zoho-zeptomail",
    "name": "Zoho CPaaS (formerly ZeptoMail)",
    "vendor": "Zoho Corporation",
    "vendorUrl": "https://www.zoho.com/cpaas/",
    "kind": "http-api",
    "category": "email",
    "summary": "Transactional email service from Zoho, renamed from ZeptoMail to Zoho CPaaS in September 2026. It sends application email through a REST API or SMTP relay, with templates, domain management, suppression lists, logs and webhooks.",
    "url": "https://www.anchorterminal.com/tools/zoho-zeptomail",
    "markdownUrl": "https://www.anchorterminal.com/tools/zoho-zeptomail.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoho-zeptomail.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoho-zeptomail.json",
    "license": "Proprietary service under the Zoho CPaaS terms of use. The Node SDK on npm is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://cpaas.zoho.com/v1.1",
    "packages": [
      {
        "registry": "npm",
        "name": "zeptomail"
      }
    ],
    "auth": "mixed",
    "authNotes": "Sending takes a send key in the `Authorization` header with the prefix Zoho-enczapikey. Each Agent has its own keys, one set per channel, copied from the console's SMTP/API tab or created and deleted by API. Logs, domains, templates, agents and suppression lists take a Zoho OAuth 2.0 access token (authorisation code grant, one-hour tokens, refresh tokens) with per-resource scopes. Access is self-serve, but every new account passes a manual review that the docs say takes two business days.",
    "pricing": "usage",
    "pricingNotes": "$2.50 per email credit of 10,000 emails ($0.25 per 1,000), valid six months, counted per recipient. The first credit is free, and a sandbox Agent accepts 10,000 test emails a day without sending them. No monthly plan. Credits can be bought only after the account review. Dedicated IP $30 a month, billed annually. Prices are filled in by script from a public JSON file (https://www.zoho.com/cpaas/pricing.html).",
    "priceSummary": "$30 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 40110,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.zoho.com/cpaas/help/api/api-home.html",
    "llmsTxt": "https://www.zoho.com/cpaas/llms.txt",
    "openapi": "https://www.zohowebstatic.com/sites/zweb/json/api/cpaas/oas.json",
    "capabilities": [
      "email.send",
      "email.templates",
      "email.domains",
      "email.analytics"
    ],
    "tags": [
      "hosted",
      "usage",
      "openapi",
      "llms-txt",
      "oauth",
      "smtp",
      "webhooks",
      "sandbox",
      "typescript",
      "status-page",
      "bug-bounty",
      "soc2"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 61.8,
      "grade": "C",
      "agentReady": false,
      "rank": 356,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 10,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 55,
        "maintenance": 74,
        "payments": 40,
        "reliability": 41,
        "schema": 78,
        "security": 76,
        "transparency": 82
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 41,
          "points": 8.2,
          "reason": "Graded on the hosted email API with the hosted lines. Zoho's status site at us.zohostatus.com lists three Zepto Mail components with status and incident history sections (20). The history loads by script and we couldn't read it. The site's RSS feed shows Zepto Mail and Zepto Mail-SMTP last changed status on 29 July 2026, in the same minute as several other Zoho services, with no duration, so this line is scored as no readable history (5). No request rate limit was found. The docs give payload caps (500 addresses a field, 60 attachments, 15 MB each) and the sandbox allowance of 10,000 emails a day (6). No 429 handling, Retry-After or idempotency key found in the docs or the OpenAPI file, whose email operations document only 200, 400 and 404 (0). No SLA found (0). The email channel is generally available, while SMS, WhatsApp and voice are marked beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "One public OpenAPI 3.0.3 file with 42 operations, linked from the docs without a login (25). llms.txt at zoho.com/cpaas/llms.txt and a second for the help centre, with a Markdown copy of each page (10). Every operation has a description, most of them one sentence, with nothing on when not to use it (10). Request bodies name required fields and length caps, with 9 enums across the file, but log filters take dates as free strings and responses are typed as a bare JSON object (10). Sample requests and responses on every page and an error-code table of 24 rows with remedies. The 401 body we got from the live endpoint has a different shape from the documented sample (11). Version 1.1 in the path and a What's New page dated by month only (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 55,
          "points": 8.94,
          "reason": "Send responses are small, and the logs endpoint takes offset and limit, with no field selection (15). Thirteen filters on email logs, among them recipient, subject, date range, `client_reference` and bounce or delivery state (16). Errors carry a code, a sub-code and a message, and the docs pair each with a fix (16). No idempotency key and no guidance on retrying a send (0). A send needs only from, to and subject. The one official SDK found is for Node, and managing the account needs a second credential type (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 76,
          "points": 13.3,
          "reason": "Send keys are per Agent and per channel, can be created, listed and deleted by API, and can only send and upload attachments. Management calls use Zoho OAuth 2.0 with READ, CREATE, UPDATE and DELETE scopes per resource and one-hour access tokens. That earns 30, less 10 because the OAuth guide documents the client secret and refresh token in the token URL's query string (20). Read-only scopes, send-only keys, sandbox Agents and IP allow lists for sending, the REST API and the web console. No approval step for deletes (15). No inbound mail, so responses hold only the account's own logs and settings (10). Activity logs per user kept one year with export, and email logs for 60 days that show the triggering IP (13). security.txt valid until 30 June 2028, a bug bounty, and SOC 2 Type II and ISO/IEC 27001 on Zoho's compliance page. No public advisory feed found (18)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). $2.50 per credit of 10,000 emails and $30 a month for a dedicated IP, public without a login (20). The first credit is free, and the documented signup asks for a phone verification and no payment details (20). Signup is a browser form with phone verification, and Zoho staff review each new account, so there is no autonomous route (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 74,
          "points": 6.48,
          "reason": "The What's New page dates entries by month. The newest is the September 2026 rename with new SMS, WhatsApp and voice endpoints, and help pages carry dates up to 6 October 2026, so we counted it as within 30 days (30). Entries for September, August and July 2026 fall in the last 90 days, though the July one may predate 10 July (20). A public changelog, a support address and a contact page that says support runs around the clock. We saw no public forum replies (10). The Node SDK zeptomail 8.0.1 is from 29 May 2026 with about 40,000 weekly downloads, and it is the only official SDK found (10). The npm package names no source repository, so CI and dependency health couldn't be read (4)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 82,
          "points": 7.18,
          "note": "editorial 69, provenance 94",
          "reason": "Closed service with its own published terms of use, and an MIT Node SDK (20). Zoho's privacy policy of 22 December 2025 covers service data, and the CPaaS pages say content is stored only on opt-in for 60 days and logs for 60 days. The pages disagree on deletion. The GDPR page says account data is deleted within 24 hours of a 48-hour grace period, the privacy policy says a clean-up every six months with backups three months later, and the April 2026 changelog entry says content can be kept up to 50 days (18). The terms commit to a six-month deprecation period after a service announcement, with no dated notices to check it against (16). Six data centre regions are named with their hosts, and Zoho publishes a sub-processor directory by service that loads by script and that we couldn't read (15)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Send responses are small, and the logs endpoint takes offset and limit, with no field selection (15). Thirteen filters on email logs, among them recipient, subject, date range, `client_reference` and bounce or delivery state (16). Errors carry a code, a sub-code and a message, and the docs pair each with a fix (16). No idempotency key and no guidance on retrying a send (0). A send needs only from, to and subject. The one official SDK found is for Node, and managing the account needs a second credential type (8).",
          "maintenance": "The What's New page dates entries by month. The newest is the September 2026 rename with new SMS, WhatsApp and voice endpoints, and help pages carry dates up to 6 October 2026, so we counted it as within 30 days (30). Entries for September, August and July 2026 fall in the last 90 days, though the July one may predate 10 July (20). A public changelog, a support address and a contact page that says support runs around the clock. We saw no public forum replies (10). The Node SDK zeptomail 8.0.1 is from 29 May 2026 with about 40,000 weekly downloads, and it is the only official SDK found (10). The npm package names no source repository, so CI and dependency health couldn't be read (4).",
          "payments": "No x402, MPP or L402 (0). $2.50 per credit of 10,000 emails and $30 a month for a dedicated IP, public without a login (20). The first credit is free, and the documented signup asks for a phone verification and no payment details (20). Signup is a browser form with phone verification, and Zoho staff review each new account, so there is no autonomous route (0).",
          "reliability": "Graded on the hosted email API with the hosted lines. Zoho's status site at us.zohostatus.com lists three Zepto Mail components with status and incident history sections (20). The history loads by script and we couldn't read it. The site's RSS feed shows Zepto Mail and Zepto Mail-SMTP last changed status on 29 July 2026, in the same minute as several other Zoho services, with no duration, so this line is scored as no readable history (5). No request rate limit was found. The docs give payload caps (500 addresses a field, 60 attachments, 15 MB each) and the sandbox allowance of 10,000 emails a day (6). No 429 handling, Retry-After or idempotency key found in the docs or the OpenAPI file, whose email operations document only 200, 400 and 404 (0). No SLA found (0). The email channel is generally available, while SMS, WhatsApp and voice are marked beta (10).",
          "schema": "One public OpenAPI 3.0.3 file with 42 operations, linked from the docs without a login (25). llms.txt at zoho.com/cpaas/llms.txt and a second for the help centre, with a Markdown copy of each page (10). Every operation has a description, most of them one sentence, with nothing on when not to use it (10). Request bodies name required fields and length caps, with 9 enums across the file, but log filters take dates as free strings and responses are typed as a bare JSON object (10). Sample requests and responses on every page and an error-code table of 24 rows with remedies. The 401 body we got from the live endpoint has a different shape from the documented sample (11). Version 1.1 in the path and a What's New page dated by month only (12).",
          "security": "Send keys are per Agent and per channel, can be created, listed and deleted by API, and can only send and upload attachments. Management calls use Zoho OAuth 2.0 with READ, CREATE, UPDATE and DELETE scopes per resource and one-hour access tokens. That earns 30, less 10 because the OAuth guide documents the client secret and refresh token in the token URL's query string (20). Read-only scopes, send-only keys, sandbox Agents and IP allow lists for sending, the REST API and the web console. No approval step for deletes (15). No inbound mail, so responses hold only the account's own logs and settings (10). Activity logs per user kept one year with export, and email logs for 60 days that show the triggering IP (13). security.txt valid until 30 June 2028, a bug bounty, and SOC 2 Type II and ISO/IEC 27001 on Zoho's compliance page. No public advisory feed found (18).",
          "transparency": "Closed service with its own published terms of use, and an MIT Node SDK (20). Zoho's privacy policy of 22 December 2025 covers service data, and the CPaaS pages say content is stored only on opt-in for 60 days and logs for 60 days. The pages disagree on deletion. The GDPR page says account data is deleted within 24 hours of a 48-hour grace period, the privacy policy says a clean-up every six months with backups three months later, and the April 2026 changelog entry says content can be kept up to 50 days (18). The terms commit to a six-month deprecation period after a service announcement, with no dated notices to check it against (16). Six data centre regions are named with their hosts, and Zoho publishes a sub-processor directory by service that loads by script and that we couldn't read (15)."
        },
        "sources": [
          {
            "what": "home page with the rename notice",
            "url": "https://www.zoho.com/cpaas/",
            "seen": "2026-10-08"
          },
          {
            "what": "API overview and groups",
            "url": "https://www.zoho.com/cpaas/help/api/api-home.html",
            "seen": "2026-10-08"
          },
          {
            "what": "API index with OAuth scopes",
            "url": "https://www.zoho.com/cpaas/help/api/api-index.html",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://www.zoho.com/cpaas/help/api/api-authentication.html",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth guide",
            "url": "https://www.zoho.com/cpaas/help/api/oauth-user-guide.html",
            "seen": "2026-10-08"
          },
          {
            "what": "send email reference",
            "url": "https://www.zoho.com/cpaas/help/api/email-sending.html",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://www.zoho.com/cpaas/help/api/error-codes.html",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI file",
            "url": "https://www.zohowebstatic.com/sites/zweb/json/api/cpaas/oas.json",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://www.zoho.com/cpaas/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "data centres and base URLs",
            "url": "https://www.zoho.com/cpaas/help/api/multiple-data-centers.html",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.zoho.com/cpaas/pricing.html",
            "seen": "2026-10-08"
          },
          {
            "what": "price values the pricing page loads",
            "url": "https://www.zoho.com/sites/zweb/json/pricing/cpaas-pricing-val.json",
            "seen": "2026-10-08"
          },
          {
            "what": "subscription and credits",
            "url": "https://www.zoho.com/cpaas/help/subscription.html",
            "seen": "2026-10-08"
          },
          {
            "what": "getting started and account review",
            "url": "https://www.zoho.com/cpaas/help/getting-started.html",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox Agent",
            "url": "https://www.zoho.com/cpaas/help/agent-sandbox.html",
            "seen": "2026-10-08"
          },
          {
            "what": "What's New",
            "url": "https://www.zoho.com/cpaas/whats-new.html",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use",
            "url": "https://www.zoho.com/cpaas/terms.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Zoho privacy policy",
            "url": "https://www.zoho.com/privacy.html",
            "seen": "2026-10-08"
          },
          {
            "what": "GDPR page",
            "url": "https://www.zoho.com/cpaas/gdpr.html",
            "seen": "2026-10-08"
          },
          {
            "what": "IP restrictions",
            "url": "https://www.zoho.com/cpaas/help/ip-restriction.html",
            "seen": "2026-10-08"
          },
          {
            "what": "activity logs",
            "url": "https://www.zoho.com/cpaas/help/activity-logs.html",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://us.zohostatus.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status RSS feed",
            "url": "https://us.zohostatus.com/rss",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.zoho.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "compliance page",
            "url": "https://www.zoho.com/compliance.html",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry record for zeptomail",
            "url": "https://registry.npmjs.org/zeptomail",
            "seen": "2026-10-08"
          },
          {
            "what": "contracting entities",
            "url": "https://www.zoho.com/legal/zoho-contracting-entities.html",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead named the product Zoho ZeptoMail. It was renamed Zoho CPaaS in September 2026, and the API host in the docs is now cpaas.zoho.com",
          "unchecked: incident history on us.zohostatus.com, which loads by script. Only the RSS feed's last status change (29 July 2026) was read",
          "unchecked: Zoho's sub-processor directory entries for Zoho CPaaS, which load by script",
          "unchecked: whether the Zoho MCP product listed on the status page exposes Zoho CPaaS. Nothing in the CPaaS docs mentions an MCP server",
          "Whether a request rate limit exists and what a throttled call returns",
          "Whether signup ever asks for a card. The documented steps don't",
          "The day in September 2026 of the rename, and whether the July 2026 changelog entry falls inside the last 90 days",
          "Whether bounced or rejected sends use credit",
          "No data processing addendum was looked for beyond the GDPR page",
          "`lastRelease` is left empty because the newest changelog entry is dated September 2026 with no day. The newest release with a full date is the Node SDK 8.0.1 on 29 May 2026"
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI 3.0 file covers all 42 operations, and each Agent has its own send-only key. Email costs $2.50 per 10,000 with the first credit free. No API rate limit, 429 handling, idempotency key or SLA was found in the reviewed documentation, and new accounts wait for a manual review.",
      "bestFor": "Low-volume transactional senders who want prepaid credits without a monthly plan, and teams already on Zoho.",
      "strengths": [
        "Public OpenAPI 3.0.3 file with 42 operations, plus llms.txt and a Markdown copy of every help page",
        "Send keys are per Agent and per channel and can only send. Management calls use OAuth with READ, CREATE, UPDATE and DELETE scopes per resource",
        "Published price of $2.50 per credit of 10,000 emails, valid six months, with the first credit free",
        "IP allow lists for sending, the REST API and the web console, and activity logs kept for one year",
        "The terms commit to a six-month deprecation period for a retired API version"
      ],
      "weaknesses": [
        "No API rate limit, 429 behaviour or Retry-After was found in the reviewed documentation or the OpenAPI file",
        "No idempotency key on send. `client_reference` is a tracking label only",
        "Every new account is reviewed by Zoho staff, which the docs say takes two business days, before credits can be bought",
        "The only official SDK found is the Node package, last published on 29 May 2026 and still named zeptomail",
        "The OAuth guide puts the client secret and refresh token in the token URL's query string",
        "No inbound email, and no SLA was found"
      ],
      "agentNotes": [
        "Call the base URL for the account's region (cpaas.zoho.com, .eu, .in, .com.au, .jp or .com.cn). A key from one region fails on another",
        "Send with `Authorization: Zoho-enczapikey \u003ckey\u003e`. Logs, domains, templates, agents and suppressions need a Zoho OAuth token as `Authorization: Zoho-oauthtoken \u003ctoken\u003e`",
        "Post OAuth client secrets and refresh tokens in the request body, not the query string the guide shows, so they stay out of logs",
        "Don't retry a timed-out send blindly. There is no idempotency key, so look the message up by `client_reference` in the email logs first",
        "Count one email per recipient, including cc and bcc, and keep each address field to 500 entries and each attachment to 15 MB",
        "Use a sandbox Agent for tests. It accepts up to 10,000 emails a day and sends none of them"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 61.8
        }
      ],
      "editorialScores": {
        "ergonomics": 55,
        "maintenance": 74,
        "payments": 40,
        "reliability": 41,
        "schema": 78,
        "security": 76,
        "transparency": 69
      },
      "provenanceScore": 94
    },
    "connect": {
      "install": "npm install zeptomail",
      "http": "curl --request POST --url https://cpaas.zoho.com/v1.1/email \\\n  --header 'Authorization: Zoho-enczapikey REPLACE_WITH_YOUR_KEY' \\\n  --header 'content-type: application/json' \\\n  --data '{\"from\":{\"address\":\"hello@yourapp.com\",\"name\":\"Your App\"},\"to\":[{\"email_address\":{\"address\":\"user@example.com\",\"name\":\"User\"}}],\"subject\":\"Test Email\",\"htmlbody\":\"\u003cp\u003eTest email sent successfully.\u003c/p\u003e\"}'"
    },
    "letme": {
      "capability": "https://letme.dev/email.send",
      "tool": "https://letme.dev/zoho-zeptomail"
    },
    "sameCompany": [
      "zoho-books",
      "zoho-crm",
      "zoho-recruit",
      "zoho-people"
    ],
    "notable": [
      "ZeptoMail was renamed Zoho CPaaS in September 2026, and existing agents, domains, templates and settings carry over unchanged (https://www.zoho.com/cpaas/whats-new.html)",
      "Send, batch, template and file-cache calls take a per-Agent send key, while logs, domains, agents, templates and suppressions take Zoho OAuth with scopes per resource and operation (https://www.zoho.com/cpaas/help/api/api-index.html)",
      "The OpenAPI 3.0.3 file lists 42 operations, 33 of them for email (https://www.zoho.com/cpaas/help/api/download-oas.html)",
      "One email credit covers 10,000 emails for six months, usage is counted per recipient, and the first credit is free (https://www.zoho.com/cpaas/pricing.html)",
      "Every new account is reviewed by Zoho staff through a customer validation form, and credits can't be bought until then (https://www.zoho.com/cpaas/help/getting-started.html)",
      "The terms allow only transactional email and set limits of 5 per cent bounces and 0.1 per cent spam complaints, above which Zoho may close the account without notice (https://www.zoho.com/cpaas/terms.html)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Rename",
        "value": "ZeptoMail became Zoho CPaaS in September 2026, adding SMS (India only), WhatsApp and voice, all three marked beta. zoho.com/zeptomail redirects to zoho.com/cpaas. api.zeptomail.com still answered on 8 October 2026"
      },
      {
        "label": "API",
        "value": "REST, version 1.1, 42 operations in one OpenAPI 3.0.3 file. 33 cover email (send, batch, templates, file cache, logs, domains, agents, suppressions), 9 cover voice, SMS and WhatsApp"
      },
      {
        "label": "Regions",
        "value": "Six data centres with their own base URL. US cpaas.zoho.com, EU cpaas.zoho.eu, India cpaas.zoho.in, Australia cpaas.zoho.com.au, Japan cpaas.zoho.jp, China cpaas.zoho.com.cn"
      },
      {
        "label": "Credentials",
        "value": "Send key per Agent and per channel in the `Authorization` header with the prefix Zoho-enczapikey. Zoho OAuth 2.0 (authorisation code grant, one-hour access tokens, refresh tokens) for management calls, with scopes such as Zeptomail.Domains.READ"
      },
      {
        "label": "SMTP",
        "value": "smtp.zeptomail.com on port 587 (TLS) or 465 (SSL), username emailapikey, TLS 1.2"
      },
      {
        "label": "Limits",
        "value": "500 addresses per to, cc or bcc field, 60 attachments, 15 MB per attachment, 500 characters in a subject. No request rate limit found. An owner can set a daily blocking limit per Agent"
      },
      {
        "label": "Free allowance",
        "value": "First credit free, 10,000 emails. Unreviewed accounts have a daily sending limit and can't buy credits"
      },
      {
        "label": "Sandbox",
        "value": "Up to 2 sandbox Agents, 10,000 emails a day each, nothing sent to recipients, simulated bounces and webhooks"
      },
      {
        "label": "Logs",
        "value": "Email logs kept 60 days and readable by API with offset, limit and 13 filters. Content is stored only if the owner opts in. Account activity logs kept one year"
      },
      {
        "label": "Webhooks",
        "value": "Soft bounce, hard bounce, open, click and feedback loop events per Agent"
      },
      {
        "label": "Inbound",
        "value": "None"
      },
      {
        "label": "Dedicated IP",
        "value": "$30 a month, billed annually, in some data centres"
      },
      {
        "label": "SDK",
        "value": "Node package zeptomail 8.0.1 (29 May 2026, MIT, Node 20 or later, TypeScript types). Code samples for curl, C#, Python, PHP and Java, and a Postman collection"
      },
      {
        "label": "Certifications",
        "value": "Zoho lists SOC 2 Type II, SOC 1 Type II, ISO/IEC 27001, 27701, 27017 and 27018 on its compliance page, and runs a bug bounty at bugbounty.zohocorp.com"
      }
    ],
    "unitPrices": [
      {
        "item": "Email credit",
        "unit": "1k-emails",
        "usd": 0.25,
        "note": "$2.50 per credit of 10,000 emails, valid six months, counted per recipient. First credit free"
      },
      {
        "item": "Dedicated IP",
        "unit": "month",
        "usd": 30,
        "note": "Billed annually, some data centres only"
      }
    ],
    "provenance": {
      "legalEntity": "Zoho Corporation",
      "domain": "zoho.com",
      "domainRegistered": "2004-01-16",
      "endpointOnVendorDomain": true,
      "terms": "https://www.zoho.com/cpaas/terms.html",
      "privacy": "https://www.zoho.com/privacy.html",
      "statusPage": "https://us.zohostatus.com/",
      "changelog": "https://www.zoho.com/cpaas/whats-new.html",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Zoho CPaaS terms of use name the contracting party as the Zoho entity for the customer's region. That is Zoho Corporation for the United States and Zoho Corporation Private Limited for India (https://www.zoho.com/legal/zoho-contracting-entities.html).",
        "The privacy field points at Zoho's privacy policy, last updated 22 December 2025, whose Part II covers the data customers process through Zoho services. Zoho CPaaS has no privacy policy of its own.",
        "status.zoho.com redirects to us.zohostatus.com, which lists Zepto Mail, Zepto Mail-SMTP and Zepto Mail-SMTP (PORT:465) under the old name. Other regions have their own status sites.",
        "www.zoho.com/.well-known/security.txt names security@zohocorp.com and the bug bounty, and expires on 30 June 2028. cpaas.zoho.com/.well-known/security.txt returns 403.",
        "RDAP for zoho.com gives a registration date of 2004-01-16."
      ],
      "score": 94,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Zoho Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "zoho.com, registered 2004-01-16 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "cpaas.zoho.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 2 of the 7 things a reader expects",
          "points": 5.7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "us.zohostatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.zoho.com/cpaas/terms.html",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 1947,
          "points": 5.7,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": false
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If your use of Zoho CPaaS is found to be in violation of these Terms, Zoho may, in its sole discretion, take appropriate action against you, which may include suspension or permanent termination of your access to the relevant Channel or to your user account, without any prior notification."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "By using Zoho CPaaS, you agree that you will not use the Service to:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "If your use of Zoho CPaaS is found to be in violation of these Terms, Zoho may, in its sole discretion, take appropriate action against you, which may include suspension or permanent termination of your access to the relevant Channel or to your user account, without any prior notification."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Zoho may monitor account activity and email content, manually and with automated tools, and may throttle emails.",
              "quote": "In order to prevent spam and to detect possible violation of these Terms, Zoho reserves the right to monitor your account activities and email content both manually and through automated tools."
            },
            {
              "date": "2026-10-08",
              "text": "The customer must not try to reach any API functionality that the API documentation does not expose.",
              "quote": "You must not try to access any functionality that is not exposed in the documentation for the API."
            },
            {
              "date": "2026-10-08",
              "text": "Unused credits are not refunded when the customer closes the account, and credits used without authorisation are not refunded.",
              "quote": "Zoho shall not provide any refund for (i) any unauthorized use of your service credits, either knowingly or unknowingly; and (ii) unused credits in your Zoho CPaaS account in the event of your closure of your Zoho CPaaS account"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.zoho.com/privacy.html",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-12-22",
          "words": 6377,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on: 22nd Dec 2025.",
              "says": "Last updated 2025-12-22"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This policy tells you what information we collect from you, what we do with it, who can access it, and what you can do about it."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "After you terminate your account, your data will be automatically deleted from our active database within 6 months and from our backups within 3 months after that.",
              "says": "Names a period of 6 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "If you ask about our products through one of our referral programs or reselling partners, or sign in to one of our products through an authentication service provider like LinkedIn or Google, they'll pass on your contact information to us."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We share your information only in the ways that are described in this Privacy Policy, and only with parties who adopt appropriate confidentiality and security measures."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "The European Economic Area (EEA) provides certain rights to data subjects (including access, rectification, erasure, restriction of processing, data portability, and the right to object and to complain)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you wish to update or delete your testimonial, you can contact us at privacy@zohocorp.com",
              "says": "privacy@zohocorp.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…or otherwise providing personal information or service data to us, you understand that the processing, transfer, and storage of your personal information or Service Data within the United States of America, the European Economic Area (EEA) and other countries where Zoho operates.",
              "says": "Data goes to the United States"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images.",
              "quote": "so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition."
            },
            {
              "date": "2026-10-08",
              "text": "Zoho says it uses an organisation's data to develop models specific to that organisation.",
              "quote": "(ii) using your organization's data for developing models specific for your organization."
            },
            {
              "date": "2026-10-08",
              "text": "After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later.",
              "quote": "Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/zoho-zeptomail.json",
    "live": {
      "slug": "zoho-zeptomail",
      "probe": {
        "target": "https://cpaas.zoho.com/v1.1",
        "method": "get",
        "lastAt": "2026-10-08T19:53:07.788146603Z",
        "lastOk": true,
        "lastStatus": 403,
        "lastMs": 459,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 433,
        "p95ms24h": 590,
        "samples24h": 27,
        "samples30d": 27,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 27,
            "ok": 27
          }
        ]
      },
      "vendorStatus": {
        "page": "https://us.zohostatus.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:22.469628831Z"
      },
      "pages": [
        {
          "url": "https://www.zoho.com/cpaas/whats-new.html",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:56.469057518Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7bf282bb5347"
        },
        {
          "url": "https://www.zoho.com/cpaas/pricing.html",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:52.435007702Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b4b0b9f913a0"
        },
        {
          "url": "https://www.zoho.com/cpaas/terms.html",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:54.470399117Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a4fd5ba82732"
        }
      ],
      "updatedAt": "2026-10-08T19:53:07.788146603Z"
    }
  }
}
