---
title: Get message details
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Email Security](https://developers.cloudflare.com/api/go/resources/email_security)

[Investigate](https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get message details

client.EmailSecurity.Investigate.Get(ctx, investigateID, params) (\*[InvestigateGetResponse](<https://developers.cloudflare.com/api/go/resources/email_security#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}

Retrieves comprehensive details for a specific email message including headers, recipients, sender information, and current quarantine status. Use the investigate\_id from search results to fetch detailed information.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Cloud Email Security: Write``Cloud Email Security: Read`

##### ParametersExpand Collapse

investigateID string

Unique identifier for a message retrieved from investigation.

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20investigate_id%20%3E%20(schema)>)

<details>

<summary>

params InvestigateGetParams

</summary>

AccountID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

Submission param.Field\[bool]Optional

Query param: When true, search the submissions datastore only. When false or omitted, search the regular datastore only.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20submission">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(method)%20get%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type InvestigateGetResponse struct{…}

</summary>

ID string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

DeprecatedActionLog \[]InvestigateGetResponseActionLog

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

</summary>

CompletedAt Time

Timestamp when action completed.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_at">Link to this property</a>

<details>

<summary>

Operation InvestigateGetResponseActionLogOperation

Type of action performed.

</summary>

One of the following:

const InvestigateGetResponseActionLogOperationMove InvestigateGetResponseActionLogOperation = "MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseActionLogOperationRelease InvestigateGetResponseActionLogOperation = "RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseActionLogOperationReclassify InvestigateGetResponseActionLogOperation = "RECLASSIFY"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseActionLogOperationSubmission InvestigateGetResponseActionLogOperation = "SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseActionLogOperationQuarantineRelease InvestigateGetResponseActionLogOperation = "QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponseActionLogOperationPreview InvestigateGetResponseActionLogOperation = "PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation">Link to this property</a>

DeprecatedCompletedTimestamp stringOptional

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

<details>

<summary>

Properties InvestigateGetResponseActionLogPropertiesOptional

Additional properties for the action.

</summary>

Folder stringOptional

Target folder for move operations.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20folder">Link to this property</a>

RequestedBy stringOptional

User who requested the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20requested_by">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

Status stringOptional

Status of the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20action_log">Link to this property</a>

ClientRecipients \[]string

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20client_recipients">Link to this property</a>

DetectionReasons \[]string

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20detection_reasons">Link to this property</a>

IsPhishSubmission bool

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20is_phish_submission">Link to this property</a>

IsQuarantined bool

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20is_quarantined">Link to this property</a>

PostfixID string

The identifier of the message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

<details>

<summary>

Properties InvestigateGetResponseProperties

Message processing properties.

</summary>

AllowlistedPattern stringOptional

Pattern that allowlisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern">Link to this property</a>

<details>

<summary>

AllowlistedPatternType InvestigateGetResponsePropertiesAllowlistedPatternTypeOptional

Type of allowlist pattern.

</summary>

One of the following:

const InvestigateGetResponsePropertiesAllowlistedPatternTypeQuarantineRelease InvestigateGetResponsePropertiesAllowlistedPatternType = "quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeAcceptableSender InvestigateGetResponsePropertiesAllowlistedPatternType = "acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeAllowedSender InvestigateGetResponsePropertiesAllowlistedPatternType = "allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeAllowedRecipient InvestigateGetResponsePropertiesAllowlistedPatternType = "allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeDomainSimilarity InvestigateGetResponsePropertiesAllowlistedPatternType = "domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeDomainRecency InvestigateGetResponsePropertiesAllowlistedPatternType = "domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeManagedAcceptableSender InvestigateGetResponsePropertiesAllowlistedPatternType = "managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponsePropertiesAllowlistedPatternTypeOutboundNdr InvestigateGetResponsePropertiesAllowlistedPatternType = "outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type">Link to this property</a>

BlocklistedMessage boolOptional

Whether message was blocklisted.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_message">Link to this property</a>

BlocklistedPattern stringOptional

Pattern that blocklisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_pattern">Link to this property</a>

<details>

<summary>

WhitelistedPatternType InvestigateGetResponsePropertiesWhitelistedPatternTypeOptional

Legacy field for allowlist pattern type.

</summary>

One of the following:

const InvestigateGetResponsePropertiesWhitelistedPatternTypeQuarantineRelease InvestigateGetResponsePropertiesWhitelistedPatternType = "quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeAcceptableSender InvestigateGetResponsePropertiesWhitelistedPatternType = "acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeAllowedSender InvestigateGetResponsePropertiesWhitelistedPatternType = "allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeAllowedRecipient InvestigateGetResponsePropertiesWhitelistedPatternType = "allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeDomainSimilarity InvestigateGetResponsePropertiesWhitelistedPatternType = "domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeDomainRecency InvestigateGetResponsePropertiesWhitelistedPatternType = "domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeManagedAcceptableSender InvestigateGetResponsePropertiesWhitelistedPatternType = "managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponsePropertiesWhitelistedPatternTypeOutboundNdr InvestigateGetResponsePropertiesWhitelistedPatternType = "outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

DeprecatedTs string

Use <code>scanned_at</code> instead.

Deprecated, use <code>scanned_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20ts">Link to this property</a>

AlertID stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

DeliveryMode InvestigateGetResponseDeliveryModeOptional

</summary>

One of the following:

const InvestigateGetResponseDeliveryModeDirect InvestigateGetResponseDeliveryMode = "DIRECT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseDeliveryModeBcc InvestigateGetResponseDeliveryMode = "BCC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseDeliveryModeJournal InvestigateGetResponseDeliveryMode = "JOURNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseDeliveryModeReviewSubmission InvestigateGetResponseDeliveryMode = "REVIEW\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseDeliveryModeDMARCUnverified InvestigateGetResponseDeliveryMode = "DMARC\_UNVERIFIED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponseDeliveryModeDMARCFailureReport InvestigateGetResponseDeliveryMode = "DMARC\_FAILURE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponseDeliveryModeDMARCAggregateReport InvestigateGetResponseDeliveryMode = "DMARC\_AGGREGATE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponseDeliveryModeThreatIntelSubmission InvestigateGetResponseDeliveryMode = "THREAT\_INTEL\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%207">Link to this property</a>

const InvestigateGetResponseDeliveryModeSimulationSubmission InvestigateGetResponseDeliveryMode = "SIMULATION\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%208">Link to this property</a>

const InvestigateGetResponseDeliveryModeAPI InvestigateGetResponseDeliveryMode = "API"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%209">Link to this property</a>

const InvestigateGetResponseDeliveryModeRetroScan InvestigateGetResponseDeliveryMode = "RETRO\_SCAN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%2010">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode">Link to this property</a>

<details>

<summary>

DeliveryStatus \[]InvestigateGetResponseDeliveryStatusOptional

</summary>

One of the following:

const InvestigateGetResponseDeliveryStatusDelivered InvestigateGetResponseDeliveryStatus = "delivered"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseDeliveryStatusMoved InvestigateGetResponseDeliveryStatus = "moved"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseDeliveryStatusQuarantined InvestigateGetResponseDeliveryStatus = "quarantined"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseDeliveryStatusRejected InvestigateGetResponseDeliveryStatus = "rejected"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseDeliveryStatusDeferred InvestigateGetResponseDeliveryStatus = "deferred"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponseDeliveryStatusBounced InvestigateGetResponseDeliveryStatus = "bounced"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponseDeliveryStatusQueued InvestigateGetResponseDeliveryStatus = "queued"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponseDeliveryStatusMoveFailed InvestigateGetResponseDeliveryStatus = "move\_failed"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status">Link to this property</a>

EdfHash stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20edf_hash">Link to this property</a>

EnvelopeFrom stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20envelope_from">Link to this property</a>

EnvelopeTo \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20envelope_to">Link to this property</a>

<details>

<summary>

FinalDisposition InvestigateGetResponseFinalDispositionOptional

The verdict Email Security assigns to a message.

</summary>

One of the following:

const InvestigateGetResponseFinalDispositionMalicious InvestigateGetResponseFinalDisposition = "MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseFinalDispositionMaliciousBec InvestigateGetResponseFinalDisposition = "MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseFinalDispositionSuspicious InvestigateGetResponseFinalDisposition = "SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseFinalDispositionSpoof InvestigateGetResponseFinalDisposition = "SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseFinalDispositionSpam InvestigateGetResponseFinalDisposition = "SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponseFinalDispositionBulk InvestigateGetResponseFinalDisposition = "BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponseFinalDispositionEncrypted InvestigateGetResponseFinalDisposition = "ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponseFinalDispositionExternal InvestigateGetResponseFinalDisposition = "EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

const InvestigateGetResponseFinalDispositionUnknown InvestigateGetResponseFinalDisposition = "UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

const InvestigateGetResponseFinalDispositionNone InvestigateGetResponseFinalDisposition = "NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

DeprecatedFindings \[]InvestigateGetResponseFindingOptional

Use the <code>findings</code> field from GET /investigate/{investigate\_id}/detections instead.

Deprecated, use the <code>findings</code> field from <code>GET /investigate/{investigate_id}/detections</code> instead. End of life: November 1, 2026. Detection findings for this message.

</summary>

Attachment stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

Detail stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

Detection InvestigateGetResponseFindingsDetectionOptional

The verdict Email Security assigns to a message.

</summary>

One of the following:

const InvestigateGetResponseFindingsDetectionMalicious InvestigateGetResponseFindingsDetection = "MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseFindingsDetectionMaliciousBec InvestigateGetResponseFindingsDetection = "MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseFindingsDetectionSuspicious InvestigateGetResponseFindingsDetection = "SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseFindingsDetectionSpoof InvestigateGetResponseFindingsDetection = "SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseFindingsDetectionSpam InvestigateGetResponseFindingsDetection = "SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

const InvestigateGetResponseFindingsDetectionBulk InvestigateGetResponseFindingsDetection = "BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

const InvestigateGetResponseFindingsDetectionEncrypted InvestigateGetResponseFindingsDetection = "ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

const InvestigateGetResponseFindingsDetectionExternal InvestigateGetResponseFindingsDetection = "EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

const InvestigateGetResponseFindingsDetectionUnknown InvestigateGetResponseFindingsDetection = "UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

const InvestigateGetResponseFindingsDetectionNone InvestigateGetResponseFindingsDetection = "NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

Field stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

Name stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Portion stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

Reason stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

Score float64Optional

formatdouble

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

Value stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20findings">Link to this property</a>

From stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20from">Link to this property</a>

FromName stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20from_name">Link to this property</a>

HtmltextStructureHash stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20htmltext_structure_hash">Link to this property</a>

MessageID stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

<details>

<summary>

PostDeliveryOperations \[]InvestigateGetResponsePostDeliveryOperationOptional

Post-delivery operations performed on this message.

</summary>

One of the following:

const InvestigateGetResponsePostDeliveryOperationPreview InvestigateGetResponsePostDeliveryOperation = "PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponsePostDeliveryOperationQuarantineRelease InvestigateGetResponsePostDeliveryOperation = "QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponsePostDeliveryOperationSubmission InvestigateGetResponsePostDeliveryOperation = "SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponsePostDeliveryOperationMove InvestigateGetResponsePostDeliveryOperation = "MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations">Link to this property</a>

PostfixIDOutbound stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20postfix_id_outbound">Link to this property</a>

Replyto stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20replyto">Link to this property</a>

ScannedAt TimeOptional

When the message was scanned (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20scanned_at">Link to this property</a>

SentAt TimeOptional

When the message was sent (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20sent_at">Link to this property</a>

SentDate stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20sent_date">Link to this property</a>

SmtpHeloServerIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20smtp_helo_server_ip">Link to this property</a>

SmtpPreviousHopIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20smtp_previous_hop_ip">Link to this property</a>

Subject stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20subject">Link to this property</a>

ThreatCategories \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20threat_categories">Link to this property</a>

To \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20to">Link to this property</a>

ToName \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20to_name">Link to this property</a>

<details>

<summary>

Validation InvestigateGetResponseValidationOptional

</summary>

Comment stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

DKIM InvestigateGetResponseValidationDKIMOptional

</summary>

One of the following:

const InvestigateGetResponseValidationDKIMPass InvestigateGetResponseValidationDKIM = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseValidationDKIMNeutral InvestigateGetResponseValidationDKIM = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseValidationDKIMFail InvestigateGetResponseValidationDKIM = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseValidationDKIMError InvestigateGetResponseValidationDKIM = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseValidationDKIMNone InvestigateGetResponseValidationDKIM = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

DMARC InvestigateGetResponseValidationDMARCOptional

</summary>

One of the following:

const InvestigateGetResponseValidationDMARCPass InvestigateGetResponseValidationDMARC = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseValidationDMARCNeutral InvestigateGetResponseValidationDMARC = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseValidationDMARCFail InvestigateGetResponseValidationDMARC = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseValidationDMARCError InvestigateGetResponseValidationDMARC = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseValidationDMARCNone InvestigateGetResponseValidationDMARC = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

SPF InvestigateGetResponseValidationSPFOptional

</summary>

One of the following:

const InvestigateGetResponseValidationSPFPass InvestigateGetResponseValidationSPF = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

const InvestigateGetResponseValidationSPFNeutral InvestigateGetResponseValidationSPF = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

const InvestigateGetResponseValidationSPFFail InvestigateGetResponseValidationSPF = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

const InvestigateGetResponseValidationSPFError InvestigateGetResponseValidationSPF = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

const InvestigateGetResponseValidationSPFNone InvestigateGetResponseValidationSPF = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20validation">Link to this property</a>

XOriginatingIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)%20%3E%20(property)%20x_originating_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateGetResponse%20%3E%20(schema)>)

### Get message details

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/email_security"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  investigate, err := client.EmailSecurity.Investigate.Get(
    context.TODO(),
    "4Njp3P0STMz2c02Q-2024-01-05T10:00:00-12345678",
    email_security.InvestigateGetParams{
      AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    },
  )
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", investigate.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "4Njp3P0STMz2c02Q-2024-01-05T10:00:00-12345678",
    "action_log": [
      {
        "completed_at": "2019-12-27T18:11:19.117Z",
        "operation": "MOVE",
        "completed_timestamp": "completed_timestamp",
        "properties": {
          "folder": "folder",
          "requested_by": "requested_by"
        },
        "status": "status"
      }
    ],
    "client_recipients": [
      "string"
    ],
    "detection_reasons": [
      "string"
    ],
    "is_phish_submission": true,
    "is_quarantined": true,
    "postfix_id": "4Njp3P0STMz2c02Q",
    "properties": {
      "allowlisted_pattern": "allowlisted_pattern",
      "allowlisted_pattern_type": "quarantine_release",
      "blocklisted_message": true,
      "blocklisted_pattern": "blocklisted_pattern",
      "whitelisted_pattern_type": "quarantine_release"
    },
    "ts": "ts",
    "alert_id": "alert_id",
    "delivery_mode": "DIRECT",
    "delivery_status": [
      "delivered"
    ],
    "edf_hash": "edf_hash",
    "envelope_from": "envelope_from",
    "envelope_to": [
      "string"
    ],
    "final_disposition": "MALICIOUS",
    "findings": [
      {
        "attachment": "attachment",
        "detail": "detail",
        "detection": "MALICIOUS",
        "field": "field",
        "name": "name",
        "portion": "portion",
        "reason": "reason",
        "score": 0,
        "value": "value"
      }
    ],
    "from": "from",
    "from_name": "from_name",
    "htmltext_structure_hash": "htmltext_structure_hash",
    "message_id": "message_id",
    "post_delivery_operations": [
      "PREVIEW"
    ],
    "postfix_id_outbound": "postfix_id_outbound",
    "replyto": "replyto",
    "scanned_at": "2019-12-27T18:11:19.117Z",
    "sent_at": "2019-12-27T18:11:19.117Z",
    "sent_date": "sent_date",
    "smtp_helo_server_ip": "smtp_helo_server_ip",
    "smtp_previous_hop_ip": "smtp_previous_hop_ip",
    "subject": "subject",
    "threat_categories": [
      "string"
    ],
    "to": [
      "string"
    ],
    "to_name": [
      "string"
    ],
    "validation": {
      "comment": "comment",
      "dkim": "pass",
      "dmarc": "pass",
      "spf": "pass"
    },
    "x_originating_ip": "x_originating_ip"
  },
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "4Njp3P0STMz2c02Q-2024-01-05T10:00:00-12345678",
    "action_log": [
      {
        "completed_at": "2019-12-27T18:11:19.117Z",
        "operation": "MOVE",
        "completed_timestamp": "completed_timestamp",
        "properties": {
          "folder": "folder",
          "requested_by": "requested_by"
        },
        "status": "status"
      }
    ],
    "client_recipients": [
      "string"
    ],
    "detection_reasons": [
      "string"
    ],
    "is_phish_submission": true,
    "is_quarantined": true,
    "postfix_id": "4Njp3P0STMz2c02Q",
    "properties": {
      "allowlisted_pattern": "allowlisted_pattern",
      "allowlisted_pattern_type": "quarantine_release",
      "blocklisted_message": true,
      "blocklisted_pattern": "blocklisted_pattern",
      "whitelisted_pattern_type": "quarantine_release"
    },
    "ts": "ts",
    "alert_id": "alert_id",
    "delivery_mode": "DIRECT",
    "delivery_status": [
      "delivered"
    ],
    "edf_hash": "edf_hash",
    "envelope_from": "envelope_from",
    "envelope_to": [
      "string"
    ],
    "final_disposition": "MALICIOUS",
    "findings": [
      {
        "attachment": "attachment",
        "detail": "detail",
        "detection": "MALICIOUS",
        "field": "field",
        "name": "name",
        "portion": "portion",
        "reason": "reason",
        "score": 0,
        "value": "value"
      }
    ],
    "from": "from",
    "from_name": "from_name",
    "htmltext_structure_hash": "htmltext_structure_hash",
    "message_id": "message_id",
    "post_delivery_operations": [
      "PREVIEW"
    ],
    "postfix_id_outbound": "postfix_id_outbound",
    "replyto": "replyto",
    "scanned_at": "2019-12-27T18:11:19.117Z",
    "sent_at": "2019-12-27T18:11:19.117Z",
    "sent_date": "sent_date",
    "smtp_helo_server_ip": "smtp_helo_server_ip",
    "smtp_previous_hop_ip": "smtp_previous_hop_ip",
    "subject": "subject",
    "threat_categories": [
      "string"
    ],
    "to": [
      "string"
    ],
    "to_name": [
      "string"
    ],
    "validation": {
      "comment": "comment",
      "dkim": "pass",
      "dmarc": "pass",
      "spf": "pass"
    },
    "x_originating_ip": "x_originating_ip"
  },
  "success": true
}
```