How Do I Set Per-Tenant or Per-IP Send Rate Limits (Hourly and Daily)?
Rate limits live at two scopes in KumoMTA: the queue (per tenant, campaign, or domain, in queues.toml) and the egress path (in shaping). Which one you use depends on what you want to cap.
Per-hour / per-second rate
Use max_message_rate on the queue. This applies per queue even when set at a less specific scope, where a queue is campaign:tenant@domain:
To cap the combined flow for a scope, regardless of campaign or destination, use overall_max_message_rate:
Daily caps
For a daily limit, use additional_message_rate_throttles on the egress path, which layers a longer-period throttle alongside the per-second or per-hour one:
["default"]
max_message_rate = '500/s'
additional_message_rate_throttles = { "daily" = "1000000/day" }
When several throttles apply, the effective rate is the smallest of them.
Note
Rate limits for a tenant belong in queues.toml, not in shaping.toml. Shaping is keyed on (source → destination site); the receiving server only sees your IP, not your tenant, so tenant limits cannot be expressed there.