# Limits and trust levels

> Couryo trust levels, daily and monthly limits, each plan's limits (emails and domains), the spending limit, rate limit headers, pauses and how to request a review.

Source: https://couryo.com/en/docs/limits

Couryo protects every customer's reputation without catching anyone by surprise. Limits are public, show in the dashboard and in the API (in error messages), and every pause comes with a reason and numbers.

## Trust levels

| Level | How you get there | Limit |
|---|---|---|
| 0, sandbox | account created | 25 per day, only to the account's own addresses |
| 1, new | a verified domain (DKIM, return path and DMARC) | 100 per day and 3,000 per month |
| 2, verified | 7 clean days and a checked company ID (CNPJ) or a payment method on file | 1,000 per day, doubling every clean week up to 10,000 |
| 3, trusted | 30 clean days on level 2 and a paid plan | your plan's volume, with the spending limit |

- **You move up on your own.** No manual approval, no form.
- **The dashboard shows what is missing**, for example: "4 more clean days to reach level 2".
- **"Clean days"** are days without a bounce or complaint pause.
- Limits count **recipients** (`to` + `cc` + `bcc`), not calls. The day rolls over at midnight in the account's time zone; the month is the billing period or, on Free, the calendar month.
- `ck_test_` keys never count toward sending limits.

The limit at any moment is the **lower** of the level's and the plan's: on the Free plan, the cap is 100 per day even on level 2.

## Plan limits

| Plan | Emails per month | Per day | Domains | Logs |
|---|---|---|---|---|
| Free | 3,000 | up to 100 | 1 | 7 days |
| Pro | 50,000 included, overage per 1,000 | the level's | up to 10 | 30 days |
| Scale | 200,000 included, overage per 1,000 | the level's | up to 50 | 90 days |
| Enterprise | custom | custom | unlimited | extended |

- **Domains** count across all projects of the account. Above the limit, the API answers `403 domain_limit_reached`; deleting a domain frees the slot.
- **On Free**, sending stops at the monthly quota (`monthly_limit_reached`) and resumes next month, with no charge.
- **On paid plans**, overage is billed per started block of 1,000 emails. See [pricing](https://couryo.com/en/pricing).

## Spending limit

Under **Billing**, you set how much overage you accept per month. When overage reaches that amount, **all** sending stops (transactional and marketing) with `spend_limit_reached`, until you raise the limit or the period renews. Nothing is charged above the cap.

## Limits that pause

| Metric | Pauses when |
|---|---|
| Bounce rate | above 3% over the last 24 hours, with at least 50 sent |
| Complaint rate (marked as spam) | above 0.05% over the last 7 days, with at least 200 sent and 2 complaints |

Rates are per account, measured in real time, and sit well below what major providers tolerate, so problems get fixed early. Policy blocks from the receiving side (`5.7.x`) do not count toward the bounce rate.

## Pauses

When a rate goes over the limit, the pause is **gradual**:

1. marketing email stops;
2. critical transactional email (password, login, billing) keeps going, with up to 30 per day;
3. you get an email with the reason, the numbers and what to fix.

Above a 10% bounce rate or a 0.5% complaint rate, the pause is **full**, including at the sending engine, and only a person on the team can lift it. A full stop also happens on clear fraud, such as phishing or a purchased list.

While paused, the API answers `sending_paused` with the reason, the numbers and how to fix it, and the dashboard shows the same, with a **Request review** button.

## Request a review

Disagree with a pause, or already fixed it? Use the **Request review** button in the dashboard and explain your case.

- **Right away:** an AI agent reviews the request against your account data and decides clear cases. If approved, the account spends 48 hours under observation (status `limited`), with up to 50 per day, and returns to normal if the rates stay healthy.
- **Within 1 business day:** if there is still doubt, a person on the team reviews it and replies with the reason.

The full rules are in the [acceptable use and suspension policy](https://couryo.com/en/acceptable-use).

## Rate limits

Each key has a 1-second window (10 calls per second by default). Every response carries these headers:

| Header | What it says |
|---|---|
| `RateLimit-Limit` | how many calls fit in the window |
| `RateLimit-Remaining` | how many are left |
| `RateLimit-Reset` | seconds until the window restarts |
| `Retry-After` | on `429 rate_limited`, how many seconds to wait |

On a `429`, wait for `Retry-After` and retry with the same `Idempotency-Key`. To send many emails at once, use a [batch](https://couryo.com/en/docs/sending.md#batch-sending): up to 100 per call.

## Sizes

| What | Limit |
|---|---|
| Recipients per email (`to` + `cc` + `bcc`) | 50 |
| Emails per batch | 100 |
| Attachments per email | 20 |
| Request body (with Base64 attachments) | 30 MB |
| `html` or `text` | 5 MB each |
| Scheduling (`scheduled_at`) | up to 30 days ahead |
