The limits Offision applies, and what people see at each one

Every limit an administrator or user can run into: how many emails a tenant can send, how often invitations, password resets and sign-in codes can be resent, how often a user's email address can change, request rate limits, sign-in lockout, free-tier daily limits, public booking, visitor code resends and export sizes, with the message shown at each.

Updated 6 Oct 2026
Open Email setting

Offision puts a ceiling on anything that can be repeated fast enough to hurt someone: email that lands in other people’s inboxes, guesses at a password, floods of requests. Every limit below counts over a rolling window: “24 hours” means the last 24 hours from now, not since midnight. A limit never deletes anything. It only makes the next attempt wait.

Licence seats and monthly booking or visitor quotas are a different kind of limit. They are on What your licence covers.

Email

Every email Offision sends counts, whatever sends it: invitations, password resets, booking, visitor and event notifications, workflows, test emails. That includes email sent through your own mail server.

LimitFreePaidCounted perWhat people see
Recipients a tenant can email40 per 10 minutes
200 per 24 hours
10,000 per 10 minutes
50,000 per 24 hours
Tenant. A message to 30 people counts 30The administrator who triggered it sees Email limit reached. Try again later. Other emails over the limit are not sent later: they show as Held by Offision in Email history
Invitation, password reset and email verification, together3 per hour
5 per 24 hours
3 per hour
5 per 24 hours
Each user and each email addressOn the sign-in page the reply is the same as always (“If an account with that email exists, we’ve sent password reset instructions”), but no new email is sent. An administrator sees Email limit reached. Try again later.
Sign-in verification codes10 per hour
30 per 24 hours
10 per hour
30 per 24 hours
Each user and each email addressThe code already sent stays valid. No new code is sent until the window frees up
Test emails from Email setting10 per hour
20 per 24 hours
10 per hour
20 per 24 hours
TenantEmail limit reached. Try again later.
Changes to a user’s email address3 per 24 hours
5 per 30 days
3 per 24 hours
5 per 30 days
Each userSaving the user is refused with This user’s email address was changed too often. Try again later.

A few details matter when you plan a roll-out:

  • Changing the address does not reset the count. The invitation limit follows the person, so moving their account to a new address and resending still counts against the same user.
  • Upper and lower case don’t count as a change. Ann@example.com to ann@example.com is free.
  • Changing an address cancels what was sent to the old one. Any invitation or password-reset link already sent stops working.
  • Inviting a large team? The free daily recipient limit is 200, and booking, visitor and event emails count toward it too. Invite in batches, or ask about a paid subscription, which raises it to 50,000.

Seeing what was sent

Email history shows recipients, subject, template, status and sending times. The email body and preview are no longer displayed; every record shows Email content hidden. Emails sent through Outlook or Google Workspace user calendars are not recorded here.

LimitValueCounted perWhat people see
Email history retention30 days by default; the configured period appears below Email historyEach record’s creation timeKept for 30 days. (with the default period) Older records are removed

The three statuses are Handed to mail server, Held by Offision and Mail server refused. Acceptance by a mail server does not prove inbox delivery. Held records show a Hold reason and are not sent later; refused records show a Failure reason. For filters, recipients and sending times, see See which emails were handed over.

Requests

LimitValueCounted perWhat people see
Apps and the management console100 requests per 5 secondsSigned-in user, or network address when not signed inToo many requests. Please slow down and try again in a moment.
Forgot password, resend invitation, self-registration, send sign-in code10 per minute, 100 per hourNetwork addressToo many requests. Please try again in N second(s).
External API and OAuth sign-in1,000 requests per 5 secondsAPI token or network addressHTTP 429 with a Retry-After header

Sign-in

LimitValueWhat people see
Wrong passwords before lockoutSet by your administrator, off unless set. See password policyThe account is locked for the minutes your policy says
Wrong sign-in verification codes5 attempts, and the code expires after 5 minutesSign in again to get a fresh code
Invitation linkValid for 72 hoursThe page offers to resend the invitation
Password reset linkValid for 24 hoursRequest a new reset email

Other limits

AreaLimitWhat people see
Free subscription, daily actionsBookings, visits, service requests, tickets, parcels, events, announcements, polls, workflows and new users each have a daily limit set by your subscriptionThe action is refused until the 24-hour window frees up
Guest booking page60 bookings per hour per network address, 2,000 per page per day. Attachments up to 5 MB eachToo many requests
Guest booking email code1 per minute and 5 per hour for each addressNo new code is sent; the last one still works
Visitor check-in code resend3 per 24 hours for each badge, at most 1 per minuteNo new code is sent
Exporting logs and lists50,000 rows per exportNarrow the date range or filters and export again