---
title: Search email messages
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Email Security](https://developers.cloudflare.com/api/go/resources/email_security)

[Investigate](https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Search email messages

client.EmailSecurity.Investigate.List(ctx, params) (\*V4PagePaginationArray\[[InvestigateListResponse](<https://developers.cloudflare.com/api/go/resources/email_security#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/email-security/investigate

Returns information for each email that matches the provided search parameters.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Cloud Email Security: Write``Cloud Email Security: Read`

##### ParametersExpand Collapse

<details>

<summary>

params InvestigateListParams

</summary>

AccountID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

AlertID param.Field\[string]Optional

Query param: Filter by alert ID.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20alert_id">Link to this property</a>

Cursor param.Field\[string]Optional

Query param: Pagination cursor from the previous response’s <code>result_info</code>.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20cursor">Link to this property</a>

<details>

<summary>

DeliveryStatus param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a>]Optional

Query param: Delivery status to filter by.

</summary>

const InvestigateListParamsDeliveryStatusDelivered <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "delivered"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const InvestigateListParamsDeliveryStatusMoved <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "moved"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const InvestigateListParamsDeliveryStatusQuarantined <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "quarantined"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const InvestigateListParamsDeliveryStatusRejected <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "rejected"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const InvestigateListParamsDeliveryStatusDeferred <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "deferred"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const InvestigateListParamsDeliveryStatusBounced <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "bounced"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const InvestigateListParamsDeliveryStatusQueued <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "queued"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const InvestigateListParamsDeliveryStatusMoveFailed <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)">InvestigateListParamsDeliveryStatus</a> = "move\_failed"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20delivery_status">Link to this property</a>

DetectionsOnly param.Field\[bool]Optional

Query param: Whether to include only detections in search results.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20detections_only">Link to this property</a>

Domain param.Field\[string]Optional

Query param: Filter by a domain found in the email — sender domain, recipient domain, or a domain in a link.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20domain">Link to this property</a>

End param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20end%20%3E%20(schema)">Time</a>]Optional

Query param: The end of the search date range. Defaults to <code>now</code>.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20end">Link to this property</a>

<details>

<summary>

FinalDisposition param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a>]Optional

Query param: Dispositions to filter by.

</summary>

const InvestigateListParamsFinalDispositionMalicious <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const InvestigateListParamsFinalDispositionSuspicious <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const InvestigateListParamsFinalDispositionSpoof <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const InvestigateListParamsFinalDispositionSpam <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const InvestigateListParamsFinalDispositionBulk <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const InvestigateListParamsFinalDispositionNone <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)">InvestigateListParamsFinalDisposition</a> = "NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20final_disposition">Link to this property</a>

<details>

<summary>

MessageAction param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)">InvestigateListParamsMessageAction</a>]Optional

Query param: Message actions to filter by.

</summary>

const InvestigateListParamsMessageActionPreview <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)">InvestigateListParamsMessageAction</a> = "PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const InvestigateListParamsMessageActionQuarantineReleased <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)">InvestigateListParamsMessageAction</a> = "QUARANTINE\_RELEASED"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const InvestigateListParamsMessageActionMoved <a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)">InvestigateListParamsMessageAction</a> = "MOVED"

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_action">Link to this property</a>

MessageID param.Field\[string]Optional

Query param: Filter by the RFC 5322 Message-ID header.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20message_id">Link to this property</a>

Metric param.Field\[string]Optional

Query param: Metric to aggregate the results by.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20metric">Link to this property</a>

Page param.Field\[int64]Optional

Query param: Deprecated: Use cursor pagination instead. End of life: November 1, 2026.

minimum1

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page">Link to this property</a>

PerPage param.Field\[int64]Optional

Query param: The number of results per page. Maximum value is 1000.

maximum1000

minimum1

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page">Link to this property</a>

Query param.Field\[string]Optional

Query param: Space-delimited term matched case-insensitively against message metadata — sender, recipient, subject, attachment names and hashes, and message ID.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20query">Link to this property</a>

Recipient param.Field\[string]Optional

Query param: Filter by recipient. Matches an email address or a domain.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20recipient">Link to this property</a>

Sender param.Field\[string]Optional

Query param: Filter by sender. Matches an email address or a domain.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20sender">Link to this property</a>

SmtpHeloIP param.Field\[string]Optional

Query param: Matches messages whose SMTP HELO server IP address equals this value.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20smtp_helo_ip">Link to this property</a>

Start param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/email_security/subresources/investigate/methods/list#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20start%20%3E%20(schema)">Time</a>]Optional

Query param: The beginning of the search date range. Defaults to <code>now - 30 days</code>. Must not be in the future.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20start">Link to this property</a>

Subject param.Field\[string]Optional

Query param: Search for messages containing individual keywords in any order within the subject.

<a href="#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20subject">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type InvestigateListResponse struct{…}

</summary>

ID string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

DeprecatedActionLog \[]InvestigateListResponseActionLog

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

</summary>

CompletedAt Time

Timestamp when action completed.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_at">Link to this property</a>

<details>

<summary>

Operation InvestigateListResponseActionLogOperation

Type of action performed.

</summary>

One of the following:

const InvestigateListResponseActionLogOperationMove InvestigateListResponseActionLogOperation = "MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseActionLogOperationRelease InvestigateListResponseActionLogOperation = "RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseActionLogOperationReclassify InvestigateListResponseActionLogOperation = "RECLASSIFY"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseActionLogOperationSubmission InvestigateListResponseActionLogOperation = "SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseActionLogOperationQuarantineRelease InvestigateListResponseActionLogOperation = "QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponseActionLogOperationPreview InvestigateListResponseActionLogOperation = "PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation">Link to this property</a>

DeprecatedCompletedTimestamp stringOptional

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

<details>

<summary>

Properties InvestigateListResponseActionLogPropertiesOptional

Additional properties for the action.

</summary>

Folder stringOptional

Target folder for move operations.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20folder">Link to this property</a>

RequestedBy stringOptional

User who requested the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20requested_by">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

Status stringOptional

Status of the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20action_log">Link to this property</a>

ClientRecipients \[]string

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20client_recipients">Link to this property</a>

DetectionReasons \[]string

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20detection_reasons">Link to this property</a>

IsPhishSubmission bool

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20is_phish_submission">Link to this property</a>

IsQuarantined bool

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20is_quarantined">Link to this property</a>

PostfixID string

The identifier of the message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

<details>

<summary>

Properties InvestigateListResponseProperties

Message processing properties.

</summary>

AllowlistedPattern stringOptional

Pattern that allowlisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern">Link to this property</a>

<details>

<summary>

AllowlistedPatternType InvestigateListResponsePropertiesAllowlistedPatternTypeOptional

Type of allowlist pattern.

</summary>

One of the following:

const InvestigateListResponsePropertiesAllowlistedPatternTypeQuarantineRelease InvestigateListResponsePropertiesAllowlistedPatternType = "quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeAcceptableSender InvestigateListResponsePropertiesAllowlistedPatternType = "acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeAllowedSender InvestigateListResponsePropertiesAllowlistedPatternType = "allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeAllowedRecipient InvestigateListResponsePropertiesAllowlistedPatternType = "allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeDomainSimilarity InvestigateListResponsePropertiesAllowlistedPatternType = "domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeDomainRecency InvestigateListResponsePropertiesAllowlistedPatternType = "domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeManagedAcceptableSender InvestigateListResponsePropertiesAllowlistedPatternType = "managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponsePropertiesAllowlistedPatternTypeOutboundNdr InvestigateListResponsePropertiesAllowlistedPatternType = "outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type">Link to this property</a>

BlocklistedMessage boolOptional

Whether message was blocklisted.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_message">Link to this property</a>

BlocklistedPattern stringOptional

Pattern that blocklisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_pattern">Link to this property</a>

<details>

<summary>

WhitelistedPatternType InvestigateListResponsePropertiesWhitelistedPatternTypeOptional

Legacy field for allowlist pattern type.

</summary>

One of the following:

const InvestigateListResponsePropertiesWhitelistedPatternTypeQuarantineRelease InvestigateListResponsePropertiesWhitelistedPatternType = "quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeAcceptableSender InvestigateListResponsePropertiesWhitelistedPatternType = "acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeAllowedSender InvestigateListResponsePropertiesWhitelistedPatternType = "allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeAllowedRecipient InvestigateListResponsePropertiesWhitelistedPatternType = "allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeDomainSimilarity InvestigateListResponsePropertiesWhitelistedPatternType = "domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeDomainRecency InvestigateListResponsePropertiesWhitelistedPatternType = "domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeManagedAcceptableSender InvestigateListResponsePropertiesWhitelistedPatternType = "managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponsePropertiesWhitelistedPatternTypeOutboundNdr InvestigateListResponsePropertiesWhitelistedPatternType = "outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

DeprecatedTs string

Use <code>scanned_at</code> instead.

Deprecated, use <code>scanned_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20ts">Link to this property</a>

AlertID stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

DeliveryMode InvestigateListResponseDeliveryModeOptional

</summary>

One of the following:

const InvestigateListResponseDeliveryModeDirect InvestigateListResponseDeliveryMode = "DIRECT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseDeliveryModeBcc InvestigateListResponseDeliveryMode = "BCC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseDeliveryModeJournal InvestigateListResponseDeliveryMode = "JOURNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseDeliveryModeReviewSubmission InvestigateListResponseDeliveryMode = "REVIEW\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseDeliveryModeDMARCUnverified InvestigateListResponseDeliveryMode = "DMARC\_UNVERIFIED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponseDeliveryModeDMARCFailureReport InvestigateListResponseDeliveryMode = "DMARC\_FAILURE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponseDeliveryModeDMARCAggregateReport InvestigateListResponseDeliveryMode = "DMARC\_AGGREGATE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponseDeliveryModeThreatIntelSubmission InvestigateListResponseDeliveryMode = "THREAT\_INTEL\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%207">Link to this property</a>

const InvestigateListResponseDeliveryModeSimulationSubmission InvestigateListResponseDeliveryMode = "SIMULATION\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%208">Link to this property</a>

const InvestigateListResponseDeliveryModeAPI InvestigateListResponseDeliveryMode = "API"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%209">Link to this property</a>

const InvestigateListResponseDeliveryModeRetroScan InvestigateListResponseDeliveryMode = "RETRO\_SCAN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%2010">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_mode">Link to this property</a>

<details>

<summary>

DeliveryStatus \[]InvestigateListResponseDeliveryStatusOptional

</summary>

One of the following:

const InvestigateListResponseDeliveryStatusDelivered InvestigateListResponseDeliveryStatus = "delivered"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseDeliveryStatusMoved InvestigateListResponseDeliveryStatus = "moved"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseDeliveryStatusQuarantined InvestigateListResponseDeliveryStatus = "quarantined"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseDeliveryStatusRejected InvestigateListResponseDeliveryStatus = "rejected"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseDeliveryStatusDeferred InvestigateListResponseDeliveryStatus = "deferred"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponseDeliveryStatusBounced InvestigateListResponseDeliveryStatus = "bounced"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponseDeliveryStatusQueued InvestigateListResponseDeliveryStatus = "queued"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponseDeliveryStatusMoveFailed InvestigateListResponseDeliveryStatus = "move\_failed"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20delivery_status">Link to this property</a>

EdfHash stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20edf_hash">Link to this property</a>

EnvelopeFrom stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20envelope_from">Link to this property</a>

EnvelopeTo \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20envelope_to">Link to this property</a>

<details>

<summary>

FinalDisposition InvestigateListResponseFinalDispositionOptional

The verdict Email Security assigns to a message.

</summary>

One of the following:

const InvestigateListResponseFinalDispositionMalicious InvestigateListResponseFinalDisposition = "MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseFinalDispositionMaliciousBec InvestigateListResponseFinalDisposition = "MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseFinalDispositionSuspicious InvestigateListResponseFinalDisposition = "SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseFinalDispositionSpoof InvestigateListResponseFinalDisposition = "SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseFinalDispositionSpam InvestigateListResponseFinalDisposition = "SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponseFinalDispositionBulk InvestigateListResponseFinalDisposition = "BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponseFinalDispositionEncrypted InvestigateListResponseFinalDisposition = "ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponseFinalDispositionExternal InvestigateListResponseFinalDisposition = "EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

const InvestigateListResponseFinalDispositionUnknown InvestigateListResponseFinalDisposition = "UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

const InvestigateListResponseFinalDispositionNone InvestigateListResponseFinalDisposition = "NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

DeprecatedFindings \[]InvestigateListResponseFindingOptional

Use the <code>findings</code> field from GET /investigate/{investigate\_id}/detections instead.

Deprecated, use the <code>findings</code> field from <code>GET /investigate/{investigate_id}/detections</code> instead. End of life: November 1, 2026. Detection findings for this message.

</summary>

Attachment stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

Detail stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

Detection InvestigateListResponseFindingsDetectionOptional

The verdict Email Security assigns to a message.

</summary>

One of the following:

const InvestigateListResponseFindingsDetectionMalicious InvestigateListResponseFindingsDetection = "MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseFindingsDetectionMaliciousBec InvestigateListResponseFindingsDetection = "MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseFindingsDetectionSuspicious InvestigateListResponseFindingsDetection = "SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseFindingsDetectionSpoof InvestigateListResponseFindingsDetection = "SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseFindingsDetectionSpam InvestigateListResponseFindingsDetection = "SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

const InvestigateListResponseFindingsDetectionBulk InvestigateListResponseFindingsDetection = "BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

const InvestigateListResponseFindingsDetectionEncrypted InvestigateListResponseFindingsDetection = "ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

const InvestigateListResponseFindingsDetectionExternal InvestigateListResponseFindingsDetection = "EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

const InvestigateListResponseFindingsDetectionUnknown InvestigateListResponseFindingsDetection = "UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

const InvestigateListResponseFindingsDetectionNone InvestigateListResponseFindingsDetection = "NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

Field stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

Name stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Portion stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

Reason stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

Score float64Optional

formatdouble

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

Value stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20findings">Link to this property</a>

From stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20from">Link to this property</a>

FromName stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20from_name">Link to this property</a>

HtmltextStructureHash stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20htmltext_structure_hash">Link to this property</a>

MessageID stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

<details>

<summary>

PostDeliveryOperations \[]InvestigateListResponsePostDeliveryOperationOptional

Post-delivery operations performed on this message.

</summary>

One of the following:

const InvestigateListResponsePostDeliveryOperationPreview InvestigateListResponsePostDeliveryOperation = "PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponsePostDeliveryOperationQuarantineRelease InvestigateListResponsePostDeliveryOperation = "QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponsePostDeliveryOperationSubmission InvestigateListResponsePostDeliveryOperation = "SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponsePostDeliveryOperationMove InvestigateListResponsePostDeliveryOperation = "MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations">Link to this property</a>

PostfixIDOutbound stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20postfix_id_outbound">Link to this property</a>

Replyto stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20replyto">Link to this property</a>

ScannedAt TimeOptional

When the message was scanned (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20scanned_at">Link to this property</a>

SentAt TimeOptional

When the message was sent (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20sent_at">Link to this property</a>

SentDate stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20sent_date">Link to this property</a>

SmtpHeloServerIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20smtp_helo_server_ip">Link to this property</a>

SmtpPreviousHopIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20smtp_previous_hop_ip">Link to this property</a>

Subject stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20subject">Link to this property</a>

ThreatCategories \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20threat_categories">Link to this property</a>

To \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20to">Link to this property</a>

ToName \[]stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20to_name">Link to this property</a>

<details>

<summary>

Validation InvestigateListResponseValidationOptional

</summary>

Comment stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

DKIM InvestigateListResponseValidationDKIMOptional

</summary>

One of the following:

const InvestigateListResponseValidationDKIMPass InvestigateListResponseValidationDKIM = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseValidationDKIMNeutral InvestigateListResponseValidationDKIM = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseValidationDKIMFail InvestigateListResponseValidationDKIM = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseValidationDKIMError InvestigateListResponseValidationDKIM = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseValidationDKIMNone InvestigateListResponseValidationDKIM = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

DMARC InvestigateListResponseValidationDMARCOptional

</summary>

One of the following:

const InvestigateListResponseValidationDMARCPass InvestigateListResponseValidationDMARC = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseValidationDMARCNeutral InvestigateListResponseValidationDMARC = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseValidationDMARCFail InvestigateListResponseValidationDMARC = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseValidationDMARCError InvestigateListResponseValidationDMARC = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseValidationDMARCNone InvestigateListResponseValidationDMARC = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

SPF InvestigateListResponseValidationSPFOptional

</summary>

One of the following:

const InvestigateListResponseValidationSPFPass InvestigateListResponseValidationSPF = "pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

const InvestigateListResponseValidationSPFNeutral InvestigateListResponseValidationSPF = "neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

const InvestigateListResponseValidationSPFFail InvestigateListResponseValidationSPF = "fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

const InvestigateListResponseValidationSPFError InvestigateListResponseValidationSPF = "error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

const InvestigateListResponseValidationSPFNone InvestigateListResponseValidationSPF = "none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20validation">Link to this property</a>

XOriginatingIP stringOptional

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)%20%3E%20(property)%20x_originating_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(model)%20InvestigateListResponse%20%3E%20(schema)>)

### Search email messages

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/email_security"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.EmailSecurity.Investigate.List(context.TODO(), email_security.InvestigateListParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "4Njp3P0STMz2c02Q-2024-01-05T10:00:00-12345678",
      "action_log": [
        {
          "completed_at": "2019-12-27T18:11:19.117Z",
          "operation": "MOVE",
          "completed_timestamp": "completed_timestamp",
          "properties": {
            "folder": "folder",
            "requested_by": "requested_by"
          },
          "status": "status"
        }
      ],
      "client_recipients": [
        "string"
      ],
      "detection_reasons": [
        "string"
      ],
      "is_phish_submission": true,
      "is_quarantined": true,
      "postfix_id": "4Njp3P0STMz2c02Q",
      "properties": {
        "allowlisted_pattern": "allowlisted_pattern",
        "allowlisted_pattern_type": "quarantine_release",
        "blocklisted_message": true,
        "blocklisted_pattern": "blocklisted_pattern",
        "whitelisted_pattern_type": "quarantine_release"
      },
      "ts": "ts",
      "alert_id": "alert_id",
      "delivery_mode": "DIRECT",
      "delivery_status": [
        "delivered"
      ],
      "edf_hash": "edf_hash",
      "envelope_from": "envelope_from",
      "envelope_to": [
        "string"
      ],
      "final_disposition": "MALICIOUS",
      "findings": [
        {
          "attachment": "attachment",
          "detail": "detail",
          "detection": "MALICIOUS",
          "field": "field",
          "name": "name",
          "portion": "portion",
          "reason": "reason",
          "score": 0,
          "value": "value"
        }
      ],
      "from": "from",
      "from_name": "from_name",
      "htmltext_structure_hash": "htmltext_structure_hash",
      "message_id": "message_id",
      "post_delivery_operations": [
        "PREVIEW"
      ],
      "postfix_id_outbound": "postfix_id_outbound",
      "replyto": "replyto",
      "scanned_at": "2019-12-27T18:11:19.117Z",
      "sent_at": "2019-12-27T18:11:19.117Z",
      "sent_date": "sent_date",
      "smtp_helo_server_ip": "smtp_helo_server_ip",
      "smtp_previous_hop_ip": "smtp_previous_hop_ip",
      "subject": "subject",
      "threat_categories": [
        "string"
      ],
      "to": [
        "string"
      ],
      "to_name": [
        "string"
      ],
      "validation": {
        "comment": "comment",
        "dkim": "pass",
        "dmarc": "pass",
        "spf": "pass"
      },
      "x_originating_ip": "x_originating_ip"
    }
  ],
  "result_info": {
    "count": 0,
    "per_page": 0,
    "total_count": 0,
    "next": "next",
    "page": 0,
    "previous": "previous"
  },
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "4Njp3P0STMz2c02Q-2024-01-05T10:00:00-12345678",
      "action_log": [
        {
          "completed_at": "2019-12-27T18:11:19.117Z",
          "operation": "MOVE",
          "completed_timestamp": "completed_timestamp",
          "properties": {
            "folder": "folder",
            "requested_by": "requested_by"
          },
          "status": "status"
        }
      ],
      "client_recipients": [
        "string"
      ],
      "detection_reasons": [
        "string"
      ],
      "is_phish_submission": true,
      "is_quarantined": true,
      "postfix_id": "4Njp3P0STMz2c02Q",
      "properties": {
        "allowlisted_pattern": "allowlisted_pattern",
        "allowlisted_pattern_type": "quarantine_release",
        "blocklisted_message": true,
        "blocklisted_pattern": "blocklisted_pattern",
        "whitelisted_pattern_type": "quarantine_release"
      },
      "ts": "ts",
      "alert_id": "alert_id",
      "delivery_mode": "DIRECT",
      "delivery_status": [
        "delivered"
      ],
      "edf_hash": "edf_hash",
      "envelope_from": "envelope_from",
      "envelope_to": [
        "string"
      ],
      "final_disposition": "MALICIOUS",
      "findings": [
        {
          "attachment": "attachment",
          "detail": "detail",
          "detection": "MALICIOUS",
          "field": "field",
          "name": "name",
          "portion": "portion",
          "reason": "reason",
          "score": 0,
          "value": "value"
        }
      ],
      "from": "from",
      "from_name": "from_name",
      "htmltext_structure_hash": "htmltext_structure_hash",
      "message_id": "message_id",
      "post_delivery_operations": [
        "PREVIEW"
      ],
      "postfix_id_outbound": "postfix_id_outbound",
      "replyto": "replyto",
      "scanned_at": "2019-12-27T18:11:19.117Z",
      "sent_at": "2019-12-27T18:11:19.117Z",
      "sent_date": "sent_date",
      "smtp_helo_server_ip": "smtp_helo_server_ip",
      "smtp_previous_hop_ip": "smtp_previous_hop_ip",
      "subject": "subject",
      "threat_categories": [
        "string"
      ],
      "to": [
        "string"
      ],
      "to_name": [
        "string"
      ],
      "validation": {
        "comment": "comment",
        "dkim": "pass",
        "dmarc": "pass",
        "spf": "pass"
      },
      "x_originating_ip": "x_originating_ip"
    }
  ],
  "result_info": {
    "count": 0,
    "per_page": 0,
    "total_count": 0,
    "next": "next",
    "page": 0,
    "previous": "previous"
  },
  "success": true
}
```