---
title: "openemail.dnsConnections"
description: "Every method in this namespace: its signature, its parameters, what it returns and an example."
url: "https://openemail.uk/docs/sdk/reference/dns-connections"
area: "SDK"
category: "Reference"
---

# openemail.dnsConnections

Every method in this namespace: its signature, its parameters, what it returns and an example.

## Methods

The DNS provider accounts connected to the workspace, through which OpenEmail writes the records of a domain itself: list them, read what disconnecting one would leave behind, and disconnect it. Connecting one is done in the app, because the provider asks the person to sign in.

### `dnsConnections.list()`

List the DNS provider accounts connected to the workspace

```ts
list(options?: RequestScope): Promise<DnsConnectionListResource>
```

Returns every DNS provider account connected to the workspace, through which OpenEmail writes the records of a domain itself, as the Providers tab of the domains page in the app shows them. Each one names the domains it serves, how many records OpenEmail wrote through it and still keeps, and whether it is `active`, needs connecting again (`needs-reauth`) or was disconnected (`revoked`).

`configured` is false when this server cannot connect a provider at all. A connection is made in the app, because the provider asks the person to sign in, so there is no method to create one.

Scopes: `domains:read`.

**Parameters**

- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client's API key for this call only.

**Returns**

`DnsConnectionListResource`, with every connection in `data`, disconnected ones included.

**Example**

```ts
const { configured, data } = await openemail.dnsConnections.list()

for (const connection of data) console.log(connection.subject, connection.status, connection.domains.length)
```

**Notes**

- A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client `maxRetries`.

Also available in: API [`GET /dns-connections`](https://openemail.uk/docs/api/reference/domains#get-dns-connections); CLI [`openemail dns-connections list`](https://openemail.uk/docs/cli/reference/dns-connections#dns-connections-list).

### `dnsConnections.get()`

Read a DNS connection and what disconnecting it would leave behind

```ts
get(id: string, options?: RequestScope): Promise<DnsConnectionDetailResource>
```

Returns one connection with what disconnecting it would do: the domains it serves, the records OpenEmail wrote through it, `busy` for the domains a sync is running on right now, which hold a disconnect back until it ends, and `keepsMail` for the verified domains that stop receiving mail once their records come down.

Scopes: `domains:read`.

**Parameters**

- `id` (`string`, required): A connection id from `list`.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client's API key for this call only.

**Returns**

`DnsConnectionDetailResource`.

**Example**

```ts
const connection = await openemail.dnsConnections.get('dnsl_3f9a1c2e7b4d4e6f8a0b2c3d')

if (connection.keepsMail.length) console.log('These stop receiving mail:', connection.keepsMail)
```

**Notes**

- A connection id that is not in this workspace is a 404 `resource_not_found`.
- A GET is retried automatically on network failure and on 408, 429 and 5xx responses, up to the client `maxRetries`.

Also available in: API [`GET /dns-connections/{id}`](https://openemail.uk/docs/api/reference/domains#get-dns-connections-id); CLI [`openemail dns-connections get`](https://openemail.uk/docs/cli/reference/dns-connections#dns-connections-get).

### `dnsConnections.delete()`

Disconnect a DNS provider account

```ts
delete(id: string, options?: RequestScope): Promise<DeletedDnsConnectionResource>
```

Disconnects the account as Disconnect does in the app: the records OpenEmail wrote through it come down, every domain it serves is detached, and the connection is revoked at the provider. A verified domain whose records come down stops receiving mail, so read `get` first. `detached` counts what came down and lists the records still published, to delete by hand.

A connection that is already disconnected is removed from the list instead, once no domain and no record is left on it, and `removed` says so.

Scopes: `domains:write`.

**Parameters**

- `id` (`string`, required): A connection id from `list`.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.apiKey` (`string`): Overrides the client's API key for this call only.

**Returns**

`DeletedDnsConnectionResource` with `removed`, `confirmed` and `detached`.

**Example**

```ts
const result = await openemail.dnsConnections.delete('dnsl_3f9a1c2e7b4d4e6f8a0b2c3d')

console.log(result.removed ? 'Removed from the list' : `${result.detached?.detached ?? 0} domains detached`)
```

**Notes**

- A sync running on one of its domains is refused with 409 `dns_busy`, and nothing is revoked. A disconnected connection that still has domains or records on it is refused with 409 `dns_connection_in_use`.
- A key or an access token limited to particular addresses or domains is refused with 422 `capability_unsupported`. An access token acting for a member also needs `workspace:manage` in their role, or it is refused with 403 `insufficient_authority`.
- An OAuth access token needs a verification code for this call, and is refused with 403 `step_up_required` until the app has verified one in the last 60 minutes. `isStepUpRequired` on the error says so. An API key is never asked for a code.
- Not retried by the SDK.

Also available in: API [`DELETE /dns-connections/{id}`](https://openemail.uk/docs/api/reference/domains#delete-dns-connections-id); CLI [`openemail dns-connections delete`](https://openemail.uk/docs/cli/reference/dns-connections#dns-connections-delete).
