Quota Management

Control email sending limits to prevent abuse and manage resources.

Why Use Quotas

Email quotas help you:

  • Prevent compromised accounts from sending mass spam
  • Protect your server's IP reputation
  • Limit damage if credentials are stolen
  • Enforce fair usage policies

Quota Types

SecZim supports multiple quota types:

  • Per-User: Limit individual accounts
  • Per-Domain: Limit all users in a domain combined
  • Global: Limit total outbound emails

Creating a Quota

In the dashboard, go to Quotas → Add Quota:

  1. Select quota type (user, domain, or global)
  2. Enter the target (email or domain)
  3. Set the limit (emails per period)
  4. Choose the period (per hour, per day)
  5. Set the action when exceeded (REJECT or DEFER)

Example Quotas

Limit All Users to 100 Emails/Hour

Type: Per-User (Default) Target: * Limit: 100 Period: Per Hour Action: REJECT Message: Hourly sending limit exceeded

Higher Limit for Marketing

Type: Per-User Target: marketing@company.com Limit: 1000 Period: Per Hour Action: REJECT

Domain-Wide Limit

Type: Per-Domain Target: company.com Limit: 5000 Period: Per Day Action: REJECT

Quota Priority

When multiple quotas apply, SecZim checks in this order:

  1. Specific user quota
  2. Domain quota
  3. Default (wildcard) quota

The first matching quota is enforced.

Tip

Create a default low quota for all users, then add higher quotas for specific accounts that need them.

Monitoring Usage

View current quota usage in Quotas → Current Usage. The dashboard shows:

  • Emails sent in current period
  • Percentage of quota used
  • Time until quota resets

Alerts

Configure quota alerts in Settings → Notifications:

  • Alert when user reaches 80% of quota
  • Alert when quota is exceeded
  • Daily summary of quota usage
Important

Quotas only apply to authenticated (outbound) email. Inbound email from external senders is not affected.

Reset Quotas

Quotas automatically reset at the end of each period. To manually reset:

  1. Go to Quotas → Current Usage
  2. Find the user or domain
  3. Click "Reset" to clear their count