cloudflare / cloudflare/developer-platform
Email Sending: lowercase info@ZONE rejected with 10202, uppercase INFO@ZONE succeeds
- Dominant language
- No language data
- Stars
- 1
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
### What versions & operating system are you using?
```
System:
OS: macOS 27.0
CPU: (15) arm64 Apple M5 Pro
Shell: 5.9 - /bin/zsh
Binaries:
Node: 26.5.0
npm: 11.17.0
Wrangler: 4.118.0
@cloudflare/workers-types: 5.20260731.1
```
Also reproducible via the Email Sending REST API path that Wrangler calls (`POST /accounts/{account_id}/email/sending/send`). This may be an Email Service platform bug rather than Wrangler itself — filing here because Wrangler surfaces the error and the CLI is the easiest repro.
### Please provide a link to a minimal reproduction
https://gist.github.com/ielyas/5d8755da7497db2d8c1bd7b8ae35beac
### Describe the Bug
**Steps to reproduce**
1. Onboard an apex zone to Cloudflare Email Sending (ours: `ni.sa`; MX remains Google Workspace; `_dmarc` is `p=reject` as added by onboarding).
2. Send with Wrangler from an allowed sender on that zone to `info@ZONE`:
```bash
npx wrangler email sending send \
--from "no-reply@ni.sa" \
--to "info@ni.sa" \
--subject "probe" \
--text "probe"
```
3. Repeat with `--to "INFO@ni.sa"` (same mailbox on Google Workspace).
4. Repeat with other local-parts on the same zone (`contact@`, `elyas@`, `abuse@`, `info@updates.ni.sa` on a sending subdomain, etc.).
**Actual behavior**
- `info@ni.sa` → fails with `email.sending.error.email.invalid [code: 10202]`
- `info+tag@ni.sa` → same failure
- `INFO@ni.sa` / `Info@Ni.Sa` → succeeds (CLI reports delivered)
- Other `@ni.sa` local-parts we tried → succeed
- `info@updates.ni.sa` (subdomain also onboarded for sending) → succeeds
The same failure happens from a Worker `send_email` binding:
```ts
await env.EMAIL.send({
to: "info@ni.sa", // fails
from: { email: "no-reply@ni.sa", name: "Website Contact Form" },
replyTo: "user@example.com",
subject: "Contact Form",
text: "...",
});
```
Using `to: "INFO@ni.sa"` works around it. Account + zone suppression lists were empty (`GET .../email/sending/suppression` → `total: 0`).
**Expected behavior**
Recipient addresses should be treated case-insensitively (or at least `info@ZONE` should not be uniquely rejected when `INFO@ZONE` and other local-parts work). Docs (`llms-full.txt` / error table) describe `10202` as “Invalid email content,” which does not explain a case-sensitive local-part rejection, and examples freely use `info@…` addresses.
Happy to provide account/zone IDs privately if useful.
### Please provide any relevant error logs
```
✘ [ERROR] A request to the Cloudflare API (/accounts/.../email/sending/send) failed.
email.sending.error.email.invalid [code: 10202]
```
From https://developers.cloudflare.com/email-service/api/send-emails/rest-api/ :
| HTTP | Code | Message | Description |
|------|------|---------|-------------|
| 400 | 10202 | email.sending.error.email.invalid | Invalid email content |
Workers binding throws into our catch path as a delivery failure (no distinct string code surfaced in our logs beyond the send failing).
Contributor guide
Assessment
This issue has not been assessed yet.