{
  "schema_version": "1.1",
  "notice_version": "2026-09-05.v4",
  "status": "fail_closed_pending_operator_inputs",
  "provider": "resend",
  "sending_domain": "codlab.app",
  "runtime": {
    "secret_bindings": [
      "RESEND_API_KEY",
      "RESEND_WEBHOOK_SECRET",
      "SUPPRESSION_API_ENDPOINT"
    ],
    "secret_injection": "inject-codecr-resend-secrets.sh",
    "secret_values_permitted_in_public_artifacts": false,
    "required_non_secret_controls": [
      "EMAIL_PROVIDER=resend",
      "EMAIL_SYSTEM_STATE=fail-closed",
      "EMAIL_SEND_ENABLED=false",
      "DOUBLE_OPT_IN_REQUIRED=true",
      "EMAIL_CONSENT_NOTICE_VERSION=2026-09-05.v4"
    ]
  },
  "dns": {
    "enrolled_resend_domain": "codlab.app",
    "resend_region": "us-east-1",
    "cloudflare_ttl": "Auto",
    "cloudflare_proxy": false,
    "records": [
      {
        "purpose": "custom MAIL FROM / return path",
        "type": "MX",
        "cloudflare_name": "send",
        "fqdn": "send.codlab.app",
        "value": "feedback-smtp.us-east-1.amazonses.com",
        "priority": 10,
        "source": "Resend domain screen; replace if the account screen differs"
      },
      {
        "purpose": "SPF for custom MAIL FROM",
        "type": "TXT",
        "cloudflare_name": "send",
        "fqdn": "send.codlab.app",
        "value": "v=spf1 include:amazonses.com ~all",
        "source": "Resend domain screen"
      },
      {
        "purpose": "DKIM",
        "type": "TXT",
        "cloudflare_name": "resend._domainkey",
        "fqdn": "resend._domainkey.codlab.app",
        "value": "[PASTE VERBATIM ACCOUNT-SPECIFIC p= VALUE FROM RESEND]",
        "account_specific": true,
        "source": "Resend domain screen"
      },
      {
        "purpose": "DMARC monitoring",
        "type": "TXT",
        "cloudflare_name": "_dmarc",
        "fqdn": "_dmarc.codlab.app",
        "value": "v=DMARC1; p=none; rua=mailto:dmarc@codlab.app; adkim=r; aspf=r; pct=100",
        "single_record_required": true
      }
    ],
    "precedence": "The account-specific Resend domain screen is authoritative for type, selector, target, and region. Never substitute an example when it differs."
  },
  "legal_hydration": {
    "environment_variable": "CORPORATE_POSTAL_ADDRESS",
    "script": "hydrate-codecr-legal-address.sh",
    "targets": [
      "dist/privacy/index.html",
      "dist/index.html",
      "dist/assets/codecr-day2-executive-onboarding-sequence.json"
    ],
    "placeholder_must_remain": false
  },
  "endpoints": {
    "consent_request": "POST /v1/pilots/email-consent",
    "consent_confirmation_view": "GET /email/confirm/{single_use_token}",
    "consent_confirmation_write": "POST /v1/pilots/email-consent/confirm",
    "provider_events": "POST /v1/email/provider-events",
    "authenticated_suppression": "POST /v1/email/suppressions",
    "one_click_unsubscribe": "POST /email/unsubscribe/{signed_control}",
    "activation_preflight": "GET /v1/email/activation/preflight",
    "durable_activation": "POST /v1/email/activation"
  },
  "consent_states": [
    "not_requested",
    "pending_confirmation",
    "confirmed",
    "expired",
    "suppressed"
  ],
  "unchecked_behavior": {
    "affirmative_action": false,
    "response": 204,
    "create_recipient": false,
    "allow_local_preflight": true
  },
  "activation_invariants": [
    "all three Worker secret binding names report present without exposing values",
    "Resend domain and signed webhook report verified",
    "suppression is durable and write-before-send",
    "published controller address contains no placeholder",
    "double opt-in is enforced",
    "activation response reports durable persistence and a numeric state revision"
  ]
}
