Secure Your Transactional Email API with IP Allowlisting
Enhance your developer email security by implementing IP allowlisting for your Piisend transactional email API keys. This crucial security measure restricts API access to trusted server IP addresses, preventing unauthorized email sends even if your API key is compromised.
Section 1
What is IP Allowlisting and Why is it Crucial for Email APIs?
IP allowlisting is a security feature that restricts access to your API keys to a predefined list of trusted IP addresses. For a transactional email API, this means only requests originating from your specified servers can successfully send emails. This adds a critical layer of developer email security, ensuring that even if an API key is leaked or stolen, it cannot be misused by an attacker from an unauthorized location. It's an essential step to protect your email sending infrastructure and maintain control over your communications.
Section 2
Configuring IP Allowlisting in Your Piisend Account
Piisend makes it straightforward to configure IP allowlisting for your API keys directly within the dashboard. Navigate to your API Keys section and select the key you wish to secure. You can then add the public IP addresses of your application servers or CI/CD environments. Once configured, any API requests made with that key from an IP address not on your allowlist will be rejected, effectively restricting API key access to only your authorized systems. This significantly strengthens your secure transactional email API setup.
1curl -X POST https://api.piisend.com/api/v1/emails \2 -H "Authorization: Bearer YOUR_API_KEY" \3 -H "Content-Type: application/json" \4 -d '{5 "to": ["recipient@example.com"],6 "subject": "Your Order Confirmation",7 "html": "<p>Thank you for your order!</p>",8 "text": "Thank you for your order!"9 }'Section 3
Implementing Secure Transactional Email API Calls with IP Restrictions
After setting up IP allowlisting in your Piisend dashboard, your application code for sending emails remains largely the same. The security enforcement happens at the API gateway level. This means your existing integrations will continue to function seamlessly, provided they are deployed on the allowed IP addresses. This approach ensures that your API endpoint security is robust without requiring changes to your core email sending logic, making it easy to integrate into your development workflow.
1import requests2 3api_key = "YOUR_API_KEY"4api_url = "https://api.piisend.com/api/v1/emails"5 6headers = {7 "Authorization": f"Bearer {api_key}",8 "Content-Type": "application/json"9}10 11payload = {12 "to": ["user@example.com"],13 "subject": "Password Reset Request",14 "html": "<p>Click <a href=\"https://your-app.com/reset?token=123\">here</a> to reset your password.</p>",15 "text": "Click this link to reset your password: https://your-app.com/reset?token=123"16}17 18try:19 response = requests.post(api_url, headers=headers, json=payload)20 response.raise_for_status() # Raise an exception for HTTP errors21 print("Email sent successfully!")22 print(response.json())23except requests.exceptions.RequestException as e:24 print(f"Error sending email: {e}")25 if response is not None:26 print(response.text)Section 4
Best Practices for Managing Allowed IPs and API Key Security
To maximize the benefits of IP allowlisting, regularly review and update your list of allowed IP addresses. Remove any IPs that are no longer in use to minimize potential attack surfaces. Combine IP allowlisting with other security measures, such as rotating API keys periodically and using separate keys for different environments or services. This comprehensive approach to API key management and IP allowlisting email API ensures the highest level of security for your transactional email infrastructure.
1const fetch = require('node-fetch');2 3const apiKey = 'YOUR_API_KEY';4const apiUrl = 'https://api.piisend.com/api/v1/emails';5 6const payload = {7 to: ['customer@example.com'],8 subject: 'Your Account Verification Code',9 html: '<p>Your verification code is: <b>123456</b></p>',10 text: 'Your verification code is: 123456'11};12 13async function sendVerificationEmail() {14 try {15 const response = await fetch(apiUrl, {16 method: 'POST',17 headers: {18 'Authorization': `Bearer ${apiKey}`,19 'Content-Type': 'application/json'20 },21 body: JSON.stringify(payload)22 });23 24 if (!response.ok) {25 const errorData = await response.json();26 throw new Error(`HTTP error! Status: ${response.status}, Details: ${JSON.stringify(errorData)}`);27 }28 29 const data = await response.json();30 console.log('Email sent successfully:', data);31 } catch (error) {32 console.error('Error sending email:', error.message);33 }34}35 36sendVerificationEmail();