---
title: Email Auth
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/typescript)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Email Auth

#### Email AuthDMARC Reports

##### [Get DMARC Report Status](https://developers.cloudflare.com/api/typescript/resources/email_auth/subresources/dmarc_reports/methods/get)

client.emailAuth.dmarcReports.get(DMARCReportGetParams {zone\_id } params, RequestOptionsoptions?): [DMARCReportGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_auth#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)>) {approved\_sources, created, created\_at, 9 more }

GET/zones/{zone\_id}/email/auth/dmarc-reports

##### [Configure DMARC Reports](https://developers.cloudflare.com/api/typescript/resources/email_auth/subresources/dmarc_reports/methods/edit)

client.emailAuth.dmarcReports.edit(DMARCReportEditParams {zone\_id, enabled, skip\_wizard } params, RequestOptionsoptions?): [DMARCReportEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_auth#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)>) {approved\_sources, created, created\_at, 9 more }

PATCH/zones/{zone\_id}/email/auth/dmarc-reports

##### ModelsExpand Collapse

<details>

<summary>

DMARCReportGetResponse {approved\_sources, created, created\_at, 9 more }

Response for GET/PATCH /dmarc-reports

</summary>

<details>

<summary>

approved\_sources?: Array&lt;ApprovedSource&gt;

List of approved sending sources (omitted when empty)

</summary>

Deprecatedcreated?: string

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created">Link to this property</a>

created\_at?: string

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

The source domain

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

ips?: Array&lt;string&gt;

Resolved IP addresses from SPF

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20ips">Link to this property</a>

Deprecatedmodified?: string

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at?: string

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Source name (typically same as domain)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

slug?: string

URL-friendly identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20slug">Link to this property</a>

tag?: string

Source UUID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20tag">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources">Link to this property</a>

Deprecatedcreated?: string

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

created\_at?: string

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether DMARC reports are enabled

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Deprecatedmodified?: string

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at?: string

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

<details>

<summary>

records?: Records {bimi\_records, cname\_dkim\_records, cname\_dmarc\_records, 5 more }

Live DNS records for the zone, grouped by type

</summary>

<details>

<summary>

bimi\_records?: Array&lt;BimiRecord&gt;

BIMI TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records">Link to this property</a>

<details>

<summary>

cname\_dkim\_records?: Array&lt;CnamedkimRecord&gt;

CNAME records for DKIM selectors. Each selector is resolved independently; when a selector’s CNAME resolves to a DKIM TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records">Link to this property</a>

<details>

<summary>

cname\_dmarc\_records?: Array&lt;CnamedmarcRecord&gt;

CNAME records at \_dmarc. When such a CNAME resolves to a DMARC TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records">Link to this property</a>

<details>

<summary>

cname\_spf\_records?: Array&lt;CnamespfRecord&gt;

CNAME records at the zone apex. When such a CNAME resolves to an SPF TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records">Link to this property</a>

<details>

<summary>

dkim\_records?: Array&lt;DKIMRecord&gt;

DKIM TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records">Link to this property</a>

<details>

<summary>

dmarc\_records?: Array&lt;DMARCRecord&gt;

DMARC TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records">Link to this property</a>

<details>

<summary>

Deprecatedresolved\_dmarc\_records?: Array&lt;ResolvedDMARCRecord&gt;

Use the <code>resolved</code> field on the corresponding entry in cname\_dmarc\_records instead.

DMARC records that a recursive lookup of \_dmarc.{zone} returned. The API populates this only when the zone lacks a DMARC TXT record of its own, which usually means a CNAME delegates DMARC to another zone.

</summary>

content?: string

The TXT record value. The API joins all character-strings into a single string.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

The name the API queried.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records">Link to this property</a>

<details>

<summary>

spf\_records?: Array&lt;SPFRecord&gt;

SPF TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20records">Link to this property</a>

rua\_prefix?: string

Prefix for DMARC RUA addresses (32-char hex string)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20rua_prefix">Link to this property</a>

skip\_wizard?: boolean

Whether to skip the setup wizard

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20skip_wizard">Link to this property</a>

<details>

<summary>

status?: "missing-dmarc-report"| "multiple-dmarc-reports"| "missing-dmarc-rua"| 2 more

DMARC configuration status. The API omits this field when DMARC is correctly configured. If the zone lacks a DMARC TXT record of its own, the API resolves \_dmarc.{zone} recursively and evaluates whatever that lookup returns. A CNAME at \_dmarc.{zone} that points to a valid DMARC record is therefore healthy; the cname-on-dmarc-record value means the CNAME resolves to no DMARC record at all.

</summary>

One of the following:

"missing-dmarc-report"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"multiple-dmarc-reports"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"missing-dmarc-rua"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"cname-on-dmarc-record"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"unauthorized-reporting-domain"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Deprecatedtag?: string

Use <code>zone_id</code> instead.

Use <code>zone_id</code> instead

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20tag">Link to this property</a>

zone\_id?: string

Zone identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)%20%3E%20(property)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_get_response%20%3E%20(schema)>)

<details>

<summary>

DMARCReportEditResponse {approved\_sources, created, created\_at, 9 more }

Response for GET/PATCH /dmarc-reports

</summary>

<details>

<summary>

approved\_sources?: Array&lt;ApprovedSource&gt;

List of approved sending sources (omitted when empty)

</summary>

Deprecatedcreated?: string

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created">Link to this property</a>

created\_at?: string

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

The source domain

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

ips?: Array&lt;string&gt;

Resolved IP addresses from SPF

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20ips">Link to this property</a>

Deprecatedmodified?: string

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at?: string

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Source name (typically same as domain)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

slug?: string

URL-friendly identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20slug">Link to this property</a>

tag?: string

Source UUID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources%20%3E%20(items)%20%3E%20(property)%20tag">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20approved_sources">Link to this property</a>

Deprecatedcreated?: string

Use <code>created_at</code> instead.

Deprecated, use created\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

created\_at?: string

Creation timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether DMARC reports are enabled

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Deprecatedmodified?: string

Use <code>modified_at</code> instead.

Deprecated, use modified\_at

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified">Link to this property</a>

modified\_at?: string

Last modification timestamp

formatdate-time

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

<details>

<summary>

records?: Records {bimi\_records, cname\_dkim\_records, cname\_dmarc\_records, 5 more }

Live DNS records for the zone, grouped by type

</summary>

<details>

<summary>

bimi\_records?: Array&lt;BimiRecord&gt;

BIMI TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20bimi_records">Link to this property</a>

<details>

<summary>

cname\_dkim\_records?: Array&lt;CnamedkimRecord&gt;

CNAME records for DKIM selectors. Each selector is resolved independently; when a selector’s CNAME resolves to a DKIM TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dkim_records">Link to this property</a>

<details>

<summary>

cname\_dmarc\_records?: Array&lt;CnamedmarcRecord&gt;

CNAME records at \_dmarc. When such a CNAME resolves to a DMARC TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_dmarc_records">Link to this property</a>

<details>

<summary>

cname\_spf\_records?: Array&lt;CnamespfRecord&gt;

CNAME records at the zone apex. When such a CNAME resolves to an SPF TXT record, the API returns that record’s content in the <code>resolved</code> field of the corresponding entry.

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20cname_spf_records">Link to this property</a>

<details>

<summary>

dkim\_records?: Array&lt;DKIMRecord&gt;

DKIM TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dkim_records">Link to this property</a>

<details>

<summary>

dmarc\_records?: Array&lt;DMARCRecord&gt;

DMARC TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20dmarc_records">Link to this property</a>

<details>

<summary>

Deprecatedresolved\_dmarc\_records?: Array&lt;ResolvedDMARCRecord&gt;

Use the <code>resolved</code> field on the corresponding entry in cname\_dmarc\_records instead.

DMARC records that a recursive lookup of \_dmarc.{zone} returned. The API populates this only when the zone lacks a DMARC TXT record of its own, which usually means a CNAME delegates DMARC to another zone.

</summary>

content?: string

The TXT record value. The API joins all character-strings into a single string.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

The name the API queried.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20resolved_dmarc_records">Link to this property</a>

<details>

<summary>

spf\_records?: Array&lt;SPFRecord&gt;

SPF TXT records

</summary>

id?: string

DNS record ID

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

content?: string

Record content

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20content">Link to this property</a>

name?: string

DNS record name

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

resolved?: Array&lt;string&gt;| null

For a CNAME record, the TXT content(s) found by following the CNAME chain to its target. An empty array means the chain was resolved but nothing usable was found there; omitted/null means resolution was not attempted for this record (always the case for non-CNAME entries). A CNAME chain that terminates in more than one TXT value at the target yields multiple entries. Populated on entries in cname\_dmarc\_records, cname\_spf\_records, and cname\_dkim\_records.

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20resolved">Link to this property</a>

ttl?: number

Time to live in seconds

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20ttl">Link to this property</a>

type?: string

Record type

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records%20%3E%20(property)%20spf_records">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20records">Link to this property</a>

rua\_prefix?: string

Prefix for DMARC RUA addresses (32-char hex string)

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20rua_prefix">Link to this property</a>

skip\_wizard?: boolean

Whether to skip the setup wizard

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20skip_wizard">Link to this property</a>

<details>

<summary>

status?: "missing-dmarc-report"| "multiple-dmarc-reports"| "missing-dmarc-rua"| 2 more

DMARC configuration status. The API omits this field when DMARC is correctly configured. If the zone lacks a DMARC TXT record of its own, the API resolves \_dmarc.{zone} recursively and evaluates whatever that lookup returns. A CNAME at \_dmarc.{zone} that points to a valid DMARC record is therefore healthy; the cname-on-dmarc-record value means the CNAME resolves to no DMARC record at all.

</summary>

One of the following:

"missing-dmarc-report"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"multiple-dmarc-reports"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"missing-dmarc-rua"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"cname-on-dmarc-record"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"unauthorized-reporting-domain"

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Deprecatedtag?: string

Use <code>zone_id</code> instead.

Use <code>zone_id</code> instead

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20tag">Link to this property</a>

zone\_id?: string

Zone identifier

<a href="#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)%20%3E%20(property)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.dmarc_reports%20%3E%20(model)%20dmarc_report_edit_response%20%3E%20(schema)>)

#### Email AuthSPF

#### Email AuthSPFInspect

##### [Inspect SPF Record](https://developers.cloudflare.com/api/typescript/resources/email_auth/subresources/spf/subresources/inspect/methods/get)

client.emailAuth.spf.inspect.get(InspectGetParams {zone\_id, id } params, RequestOptionsoptions?): [InspectGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_auth#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)>) {components, domain, record, 2 more }

GET/zones/{zone\_id}/email/auth/spf/inspect

##### ModelsExpand Collapse

<details>

<summary>

InspectGetResponse {components, domain, record, 2 more }

Recursive SPF inspection tree

</summary>

components: Array&lt;unknown&gt;

Parsed SPF components (mechanisms)

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20components">Link to this property</a>

domain: string

Domain being inspected

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

record: string

Raw SPF record content

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20record">Link to this property</a>

total\_lookups: number

Total number of DNS lookups performed across all includes

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20total_lookups">Link to this property</a>

<details>

<summary>

errors?: Array&lt;Error&gt;

All errors encountered during inspection, collected from the entire tree. This includes errors from nested includes at any depth, providing a quick overview of all issues without needing to traverse the nested structure. Each error includes a <code>domain</code> field to identify where it occurred. Empty array if no errors (omitted from JSON when empty).

</summary>

code: string

Error code. Known values:

- <code>lookup_failed</code> — DNS TXT lookup failed
- <code>spf_not_found</code> — no SPF record found
- <code>invalid_spf</code> — record does not start with <code>v=spf1</code>
- <code>invalid_domain</code> — PSL validation failed
- <code>loop_detected</code> — include/redirect cycle detected
- <code>invalid_mechanism</code> — unrecognised or malformed mechanism
- <code>resource_limit_exceeded</code> — internal resource protection limits exceeded (recursion depth or query budget)
- <code>max_lookups</code> — RFC 7208 10-lookup limit exceeded

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

domain: string

Domain where the error occurred

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

message: string

Human-readable error message

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

details?: string

Additional error-specific details (optional).

- For <code>invalid_domain</code> errors: the invalid domain string
- For <code>invalid_mechanism</code> errors: the invalid mechanism text (e.g., “invalidmech123”)
- For <code>loop_detected</code> errors: the domain that caused the loop
- For other error types: not present

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20details">Link to this property</a>

</details>

<a href="#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_auth.spf.inspect%20%3E%20(model)%20inspect_get_response%20%3E%20(schema)>)