Investigate
Search email messages
Get message details
ModelsExpand Collapse
InvestigateListResponse object { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: array of object { completed_at, operation, completed_timestamp, 2 more } Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use completed_at instead.
Deprecated, use completed_at instead. End of life: November 1, 2026.
properties: object { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: optional array of object { attachment, detail, detection, 6 more } Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: optional array of "PREVIEW" or "QUARANTINE_RELEASE" or "SUBMISSION" or "MOVE"Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
InvestigateGetResponse object { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: array of object { completed_at, operation, completed_timestamp, 2 more } Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use completed_at instead.
Deprecated, use completed_at instead. End of life: November 1, 2026.
properties: object { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: optional array of object { attachment, detail, detection, 6 more } Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: optional array of "PREVIEW" or "QUARANTINE_RELEASE" or "SUBMISSION" or "MOVE"Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
InvestigateDetections
Get message detection details
ModelsExpand Collapse
DetectionGetResponse object { action, attachments, findings, 6 more }
attachments: array of object { size, content_type, detection, 6 more }
findings: array of object { attachment, detail, detection, 6 more }
InvestigatePreview
Get preview for a detection
Generate preview for a non-detection message
InvestigateRaw
Get raw email content
InvestigateTrace
Get email trace
InvestigateMove
Move a message
Move messages
ModelsExpand Collapse
MoveCreateResponse object { success, completed_at, completed_timestamp, 6 more }
MoveBulkResponse object { success, completed_at, completed_timestamp, 6 more }
InvestigateReclassify
Change email classification
InvestigateRelease
Release messages from quarantine
InvestigateBulk
List bulk action jobs
Create a bulk action job
Get bulk action job details
Delete a bulk action job
ModelsExpand Collapse
BulkListResponse object { action_params, action_type, created_at, 13 more }
action_params: object { destination, type, expected_disposition } or object { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: object { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: optional "delivered" or "moved" or "quarantined" or 5 moreDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreDispositions to filter by.
Dispositions to filter by.
BulkCreateResponse object { action_params, action_type, created_at, 13 more }
action_params: object { destination, type, expected_disposition } or object { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: object { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: optional "delivered" or "moved" or "quarantined" or 5 moreDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreDispositions to filter by.
Dispositions to filter by.
BulkGetResponse object { action_params, action_type, created_at, 13 more }
action_params: object { destination, type, expected_disposition } or object { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: object { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: optional "delivered" or "moved" or "quarantined" or 5 moreDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreDispositions to filter by.
Dispositions to filter by.
InvestigateBulkCancel
Cancel a bulk action job
ModelsExpand Collapse
CancelCreateResponse object { action_params, action_type, created_at, 13 more }
action_params: object { destination, type, expected_disposition } or object { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: object { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: optional "delivered" or "moved" or "quarantined" or 5 moreDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreDispositions to filter by.
Dispositions to filter by.
InvestigateBulkMessages
List messages for a bulk action job
ModelsExpand Collapse
MessageListResponse object { action_params, action_type, created_at, 10 more }
action_params: object { client_recipient, destination, type, expected_disposition } or object { client_recipient, type }
status: "PENDING" or "PROCESSING" or "COMPLETED" or 3 moreStatus of a message within a bulk action job.
Status of a message within a bulk action job.
message: optional object { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: array of object { completed_at, operation, completed_timestamp, 2 more } Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use completed_at instead.
Deprecated, use completed_at instead. End of life: November 1, 2026.
properties: object { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: optional "MALICIOUS" or "MALICIOUS-BEC" or "SUSPICIOUS" or 7 moreThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: optional array of object { attachment, detail, detection, 6 more } Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: optional array of "PREVIEW" or "QUARANTINE_RELEASE" or "SUBMISSION" or "MOVE"Post-delivery operations performed on this message.
Post-delivery operations performed on this message.