generated: '2026-08-13' method: searched source: https://docs.sublime.security/reference/emailrep-introduction limit_count: 5 specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: EmailRep providerId: emailrep created: '2026-05-30' modified: '2026-05-30' reconciled: true tags: - Rate Limiting - Email Reputation - Threat Intelligence - Security description: >- EmailRep enforces rate limits per API key. The Free (Community) tier is capped at 250 queries per month with a 10-queries-per-day daily ceiling. The Commercial tier raises the monthly quota to 1,000 and removes the daily cap. Enterprise plans negotiate high-volume quotas with SLAs. Anonymous (no API key) queries are heavily rate-limited per IP and are intended for ad-hoc lookups via the emailrep.io web UI. Rate-limit enforcement returns 429 Too Many Requests; submit reports and reputation queries should back off and retry with exponential delay when throttled. sources: - https://emailrep.io - https://emailrep.io/key - https://docs.sublimesecurity.com/reference/emailrep-introduction window: type: rolling period: 24 hours note: >- "Rate-limits are enforced using a rolling 24-hour window, not by calendar day." Waiting for midnight does not reset the allowance — callers must back off. source: https://docs.sublime.security/reference/emailrep-introduction responseCodes: throttled: 429 quotaExceeded: 429 headers: responseHeaders: - name: X-Rate-Limit-Daily-Remaining direction: response description: >- Requests remaining in the rolling 24-hour window. Returned for keys carrying a daily quota (the free Community tier). Verbatim from the provider's docs. - name: X-Rate-Limit-Monthly-Remaining direction: response description: >- Requests remaining in the monthly quota. Returned for keys carrying a monthly quota. Verbatim from the provider's docs. retryAfter: null retryAfterNote: >- No Retry-After header is documented, and none was observed on the live 429 (the response carried only nginx defaults). Callers must implement their own backoff. ietfDraftHeaders: false observed: fetched: '2026-08-13' url: https://emailrep.io/bill@microsoft.com http_status: 429 response_headers_seen: [Server, Date, Content-Type, Content-Length, Connection] note: >- No X-Rate-Limit-* headers were present on the anonymous 429, because that 429 is not a rate limit — see the overloaded-429 warning below. The documented headers require an API key to observe. overloaded429: warning: >- 429 carries TWO unrelated meanings on this API and the status code alone cannot separate them. Read the JSON `reason` field. conditions: - condition: quota exhausted retryable: true action: exponential backoff against the rolling window - condition: anonymous access disabled reason: 'the unauthenticated API is currently disabled. please use an API key' retryable: false action: >- Supply an API key. Retrying will never succeed. Observed live on 2026-08-13 — the docs still advertise the keyless tier as available. limits: - name: Anonymous (no API key) scope: IP metric: requests_per_day limit: low (intended for ad-hoc lookups via the web UI) notes: >- Anonymous lookups are rate-limited per IP. For programmatic use, sign up for a free API key at https://emailrep.io/key. - name: Free Community Tier (with API key) scope: key metric: requests_per_month limit: 250 timeFrame: month notes: >- Free tier quota. Combined with a 10-query-per-day ceiling. - name: Free Community Tier Daily Ceiling scope: key metric: requests_per_day limit: 10 timeFrame: day notes: Daily ceiling that applies on top of the monthly quota. - name: Commercial Tier scope: key metric: requests_per_month limit: 1000 timeFrame: month notes: $20/month commercial subscription. No daily cap. - name: Enterprise Tier scope: key metric: requests_per_month limit: see contract notes: High-volume quota negotiated per Enterprise contract with SLA-backed support. policies: - name: API Key Required For Reports description: >- The POST /report endpoint requires an API key. Anonymous report submission is not supported. - name: Tier-Based Scoping description: >- Rate limits are bound to the API key. Each key carries one of the Free, Commercial, or Enterprise quotas. - name: 429 Retry With Backoff description: >- When a quota or per-day ceiling is exceeded the API returns 429. Callers should back off with exponential delay and retry on the next window (next day for Free, next month for paid). - name: Raise Via Support description: >- Commercial and Enterprise quotas can be raised by contacting Sublime Security through the contact form at sublimesecurity.com/contact. - name: Web UI Lookups description: >- The emailrep.io web UI provides ad-hoc lookups for security analysts without an API key, subject to per-IP throttling.