---
title: Email Auth
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Email Auth

#### Email AuthDMARC Reports

##### [Get DMARC Report Status](https://developers.cloudflare.com/api/python/resources/email_auth/subresources/dmarc_reports/methods/get)

email\_auth.dmarc\_reports.get(DMARCReportGetParams\*\*kwargs) -> [DMARCReportGetResponse](<https://developers.cloudflare.com/api/python/resources/email_auth#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)>)

GET/zones/{zone\_id}/email/auth/dmarc-reports

##### [Configure DMARC Reports](https://developers.cloudflare.com/api/python/resources/email_auth/subresources/dmarc_reports/methods/edit)

email\_auth.dmarc\_reports.edit(DMARCReportEditParams\*\*kwargs) -> [DMARCReportEditResponse](<https://developers.cloudflare.com/api/python/resources/email_auth#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)>)

PATCH/zones/{zone\_id}/email/auth/dmarc-reports

##### ModelsExpand Collapse

<details>

<summary>

class DMARCReportGetResponse: …

Response for GET/PATCH /dmarc-reports

</summary>

<details>

<summary>

approved\_sources: Optional\[List\[ApprovedSource]]

List of approved sending sources (omitted when empty)

</summary>

Deprecatedcreated: Optional\[datetime]

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created">Link to this property</a>

created\_at: Optional\[datetime]

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

domain: Optional\[str]

The source domain

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

ips: Optional\[List\[str]]

Resolved IP addresses from SPF

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20ips">Link to this property</a>

Deprecatedmodified: Optional\[datetime]

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at: Optional\[datetime]

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name: Optional\[str]

Source name (typically same as domain)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20slug">Link to this property</a>

tag: Optional\[str]

Source UUID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20tag">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources">Link to this property</a>

Deprecatedcreated: Optional\[datetime]

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

created\_at: Optional\[datetime]

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled: Optional\[bool]

Whether DMARC reports are enabled

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Deprecatedmodified: Optional\[datetime]

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at: Optional\[datetime]

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

<details>

<summary>

records: Optional\[Records]

Live DNS records for the zone, grouped by type

</summary>

<details>

<summary>

bimi\_records: Optional\[List\[RecordsBimiRecord]]

BIMI TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records">Link to this property</a>

<details>

<summary>

cname\_dkim\_records: Optional\[List\[RecordsCnamedkimRecord]]

CNAME records for DKIM selectors. Each selector is resolved independently; when a selector’s CNAME resolves to a DKIM TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records">Link to this property</a>

<details>

<summary>

cname\_dmarc\_records: Optional\[List\[RecordsCnamedmarcRecord]]

CNAME records at \_dmarc. When such a CNAME resolves to a DMARC TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records">Link to this property</a>

<details>

<summary>

cname\_spf\_records: Optional\[List\[RecordsCnamespfRecord]]

CNAME records at the zone apex. When such a CNAME resolves to an SPF TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records">Link to this property</a>

<details>

<summary>

dkim\_records: Optional\[List\[RecordsDKIMRecord]]

DKIM TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records">Link to this property</a>

<details>

<summary>

dmarc\_records: Optional\[List\[RecordsDMARCRecord]]

DMARC TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records">Link to this property</a>

<details>

<summary>

Deprecatedresolved\_dmarc\_records: Optional\[List\[RecordsResolvedDMARCRecord]]

Use the <code>resolved</code> field on the corresponding entry in cname\_dmarc\_records instead.

DMARC records that a recursive lookup of \_dmarc.{zone} returned. The API populates this only when the zone lacks a DMARC TXT record of its own, which usually means a CNAME delegates DMARC to another zone.

</summary>

content: Optional\[str]

The TXT record value. The API joins all character-strings into a single string.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

The name the API queried.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records">Link to this property</a>

<details>

<summary>

spf\_records: Optional\[List\[RecordsSPFRecord]]

SPF TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records">Link to this property</a>

rua\_prefix: Optional\[str]

Prefix for DMARC RUA addresses (32-char hex string)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20rua_prefix">Link to this property</a>

skip\_wizard: Optional\[bool]

Whether to skip the setup wizard

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20skip_wizard">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["missing-dmarc-report", "multiple-dmarc-reports", "missing-dmarc-rua", 2 more]]

DMARC configuration status. The API omits this field when DMARC is correctly configured. If the zone lacks a DMARC TXT record of its own, the API resolves \_dmarc.{zone} recursively and evaluates whatever that lookup returns. A CNAME at \_dmarc.{zone} that points to a valid DMARC record is therefore healthy; the cname-on-dmarc-record value means the CNAME resolves to no DMARC record at all.

</summary>

One of the following:

"missing-dmarc-report"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"multiple-dmarc-reports"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"missing-dmarc-rua"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"cname-on-dmarc-record"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"unauthorized-reporting-domain"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Deprecatedtag: Optional\[str]

Use <code>zone_id</code> instead.

Use <code>zone_id</code> instead

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20tag">Link to this property</a>

zone\_id: Optional\[str]

Zone identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)>)

<details>

<summary>

class DMARCReportEditResponse: …

Response for GET/PATCH /dmarc-reports

</summary>

<details>

<summary>

approved\_sources: Optional\[List\[ApprovedSource]]

List of approved sending sources (omitted when empty)

</summary>

Deprecatedcreated: Optional\[datetime]

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created">Link to this property</a>

created\_at: Optional\[datetime]

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

domain: Optional\[str]

The source domain

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

ips: Optional\[List\[str]]

Resolved IP addresses from SPF

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20ips">Link to this property</a>

Deprecatedmodified: Optional\[datetime]

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at: Optional\[datetime]

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name: Optional\[str]

Source name (typically same as domain)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20slug">Link to this property</a>

tag: Optional\[str]

Source UUID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20tag">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources">Link to this property</a>

Deprecatedcreated: Optional\[datetime]

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

created\_at: Optional\[datetime]

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled: Optional\[bool]

Whether DMARC reports are enabled

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Deprecatedmodified: Optional\[datetime]

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at: Optional\[datetime]

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

<details>

<summary>

records: Optional\[Records]

Live DNS records for the zone, grouped by type

</summary>

<details>

<summary>

bimi\_records: Optional\[List\[RecordsBimiRecord]]

BIMI TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records">Link to this property</a>

<details>

<summary>

cname\_dkim\_records: Optional\[List\[RecordsCnamedkimRecord]]

CNAME records for DKIM selectors. Each selector is resolved independently; when a selector’s CNAME resolves to a DKIM TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records">Link to this property</a>

<details>

<summary>

cname\_dmarc\_records: Optional\[List\[RecordsCnamedmarcRecord]]

CNAME records at \_dmarc. When such a CNAME resolves to a DMARC TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records">Link to this property</a>

<details>

<summary>

cname\_spf\_records: Optional\[List\[RecordsCnamespfRecord]]

CNAME records at the zone apex. When such a CNAME resolves to an SPF TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records">Link to this property</a>

<details>

<summary>

dkim\_records: Optional\[List\[RecordsDKIMRecord]]

DKIM TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records">Link to this property</a>

<details>

<summary>

dmarc\_records: Optional\[List\[RecordsDMARCRecord]]

DMARC TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records">Link to this property</a>

<details>

<summary>

Deprecatedresolved\_dmarc\_records: Optional\[List\[RecordsResolvedDMARCRecord]]

Use the <code>resolved</code> field on the corresponding entry in cname\_dmarc\_records instead.

DMARC records that a recursive lookup of \_dmarc.{zone} returned. The API populates this only when the zone lacks a DMARC TXT record of its own, which usually means a CNAME delegates DMARC to another zone.

</summary>

content: Optional\[str]

The TXT record value. The API joins all character-strings into a single string.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

The name the API queried.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records">Link to this property</a>

<details>

<summary>

spf\_records: Optional\[List\[RecordsSPFRecord]]

SPF TXT records

</summary>

id: Optional\[str]

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content: Optional\[str]

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name: Optional\[str]

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved: Optional\[List\[str]]

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl: Optional\[int]

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type: Optional\[str]

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records">Link to this property</a>

rua\_prefix: Optional\[str]

Prefix for DMARC RUA addresses (32-char hex string)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20rua_prefix">Link to this property</a>

skip\_wizard: Optional\[bool]

Whether to skip the setup wizard

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20skip_wizard">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["missing-dmarc-report", "multiple-dmarc-reports", "missing-dmarc-rua", 2 more]]

DMARC configuration status. The API omits this field when DMARC is correctly configured. If the zone lacks a DMARC TXT record of its own, the API resolves \_dmarc.{zone} recursively and evaluates whatever that lookup returns. A CNAME at \_dmarc.{zone} that points to a valid DMARC record is therefore healthy; the cname-on-dmarc-record value means the CNAME resolves to no DMARC record at all.

</summary>

One of the following:

"missing-dmarc-report"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"multiple-dmarc-reports"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"missing-dmarc-rua"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"cname-on-dmarc-record"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"unauthorized-reporting-domain"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Deprecatedtag: Optional\[str]

Use <code>zone_id</code> instead.

Use <code>zone_id</code> instead

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20tag">Link to this property</a>

zone\_id: Optional\[str]

Zone identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)>)

#### Email AuthSPF

#### Email AuthSPFInspect

##### [Inspect SPF Record](https://developers.cloudflare.com/api/python/resources/email_auth/subresources/spf/subresources/inspect/methods/get)

email\_auth.spf.inspect.get(InspectGetParams\*\*kwargs) -> [InspectGetResponse](<https://developers.cloudflare.com/api/python/resources/email_auth#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)>)

GET/zones/{zone\_id}/email/auth/spf/inspect

##### ModelsExpand Collapse

<details>

<summary>

class InspectGetResponse: …

Recursive SPF inspection tree

</summary>

components: List\[object]

Parsed SPF components (mechanisms)

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20components">Link to this property</a>

domain: str

Domain being inspected

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

record: str

Raw SPF record content

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20record">Link to this property</a>

total\_lookups: int

Total number of DNS lookups performed across all includes

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20total_lookups">Link to this property</a>

<details>

<summary>

errors: Optional\[List\[Error]]

All errors encountered during inspection, collected from the entire tree. This includes errors from nested includes at any depth, providing a quick overview of all issues without needing to traverse the nested structure. Each error includes a <code>domain</code> field to identify where it occurred. Empty array if no errors (omitted from JSON when empty).

</summary>

code: str

Error code. Known values:

- <code>lookup_failed</code> — DNS TXT lookup failed
- <code>spf_not_found</code> — no SPF record found
- <code>invalid_spf</code> — record does not start with <code>v=spf1</code>
- <code>invalid_domain</code> — PSL validation failed
- <code>loop_detected</code> — include/redirect cycle detected
- <code>invalid_mechanism</code> — unrecognised or malformed mechanism
- <code>resource_limit_exceeded</code> — internal resource protection limits exceeded (recursion depth or query budget)
- <code>max_lookups</code> — RFC 7208 10-lookup limit exceeded

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

domain: str

Domain where the error occurred

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

message: str

Human-readable error message

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

details: Optional\[str]

Additional error-specific details (optional).

- For <code>invalid_domain</code> errors: the invalid domain string
- For <code>invalid_mechanism</code> errors: the invalid mechanism text (e.g., “invalidmech123”)
- For <code>loop_detected</code> errors: the domain that caused the loop
- For other error types: not present

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20details">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)>)