---
title: Email Security
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/typescript)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Email Security

#### Email SecurityInvestigate

##### [Search email messages](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/methods/list)

client.emailSecurity.investigate.list(InvestigateListParams {account\_id, alert\_id, cursor, 16 more } params, RequestOptionsoptions?): V4PagePaginationArray< [InvestigateListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)>) {id, action\_log, client\_recipients, 32 more } >

GET/accounts/{account\_id}/email-security/investigate

##### [Get message details](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/methods/get)

client.emailSecurity.investigate.get(stringinvestigateID, InvestigateGetParams {account\_id, submission } params, RequestOptionsoptions?): [InvestigateGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)>) {id, action\_log, client\_recipients, 32 more }

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}

##### ModelsExpand Collapse

<details>

<summary>

InvestigateListResponse {id, action\_log, client\_recipients, 32 more }

</summary>

id: string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Deprecatedaction\_log: Array&lt;ActionLog&gt;

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

</summary>

completed\_at: string

Timestamp when action completed.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_at">Link to this property</a>

<details>

<summary>

operation: "MOVE"| "RELEASE"| "RECLASSIFY"| 3 more

Type of action performed.

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%201">Link to this property</a>

"RECLASSIFY"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%202">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%203">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%204">Link to this property</a>

"PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation">Link to this property</a>

Deprecatedcompleted\_timestamp?: string

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

<details>

<summary>

properties?: Properties {folder, requested\_by }

Additional properties for the action.

</summary>

folder?: string

Target folder for move operations.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20folder">Link to this property</a>

requested\_by?: string

User who requested the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20requested_by">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

status?: string| null

Status of the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20action_log">Link to this property</a>

client\_recipients: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20client_recipients">Link to this property</a>

detection\_reasons: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20detection_reasons">Link to this property</a>

is\_phish\_submission: boolean

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20is_phish_submission">Link to this property</a>

is\_quarantined: boolean

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20is_quarantined">Link to this property</a>

postfix\_id: string

The identifier of the message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

<details>

<summary>

properties: Properties {allowlisted\_pattern, allowlisted\_pattern\_type, blocklisted\_message, 2 more }

Message processing properties.

</summary>

allowlisted\_pattern?: string| null

Pattern that allowlisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern">Link to this property</a>

<details>

<summary>

allowlisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Type of allowlist pattern.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type">Link to this property</a>

blocklisted\_message?: boolean| null

Whether message was blocklisted.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_message">Link to this property</a>

blocklisted\_pattern?: string| null

Pattern that blocklisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_pattern">Link to this property</a>

<details>

<summary>

whitelisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Legacy field for allowlist pattern type.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

Deprecatedts: string

Use <code>scanned_at</code> instead.

Deprecated, use <code>scanned_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20ts">Link to this property</a>

alert\_id?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_mode?: "DIRECT"| "BCC"| "JOURNAL"| 8 more| null

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%202">Link to this property</a>

"REVIEW\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%203">Link to this property</a>

"DMARC\_UNVERIFIED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%204">Link to this property</a>

"DMARC\_FAILURE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%205">Link to this property</a>

"DMARC\_AGGREGATE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%206">Link to this property</a>

"THREAT\_INTEL\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%207">Link to this property</a>

"SIMULATION\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%208">Link to this property</a>

"API"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%209">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%2010">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode">Link to this property</a>

<details>

<summary>

delivery\_status?: Array&lt;"delivered"| "moved"| "quarantined"| 5 more&gt;| null

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status">Link to this property</a>

edf\_hash?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20edf_hash">Link to this property</a>

envelope\_from?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20envelope_from">Link to this property</a>

envelope\_to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20envelope_to">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

Deprecatedfindings?: Array&lt;Finding&gt;| null

Use the <code>findings</code> field from GET /investigate/{investigate\_id}/detections instead.

Deprecated, use the <code>findings</code> field from <code>GET /investigate/{investigate_id}/detections</code> instead. End of life: November 1, 2026. Detection findings for this message.

</summary>

attachment?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

detail?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

detection?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

field?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

name?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

portion?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

reason?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

score?: number| null

formatdouble

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

value?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20findings">Link to this property</a>

from?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20from">Link to this property</a>

from\_name?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20from_name">Link to this property</a>

htmltext\_structure\_hash?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20htmltext_structure_hash">Link to this property</a>

message\_id?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

<details>

<summary>

post\_delivery\_operations?: Array&lt;"PREVIEW"| "QUARANTINE\_RELEASE"| "SUBMISSION"| "MOVE"&gt;| null

Post-delivery operations performed on this message.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations">Link to this property</a>

postfix\_id\_outbound?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id_outbound">Link to this property</a>

replyto?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20replyto">Link to this property</a>

scanned\_at?: string| null

When the message was scanned (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20scanned_at">Link to this property</a>

sent\_at?: string| null

When the message was sent (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20sent_at">Link to this property</a>

sent\_date?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20sent_date">Link to this property</a>

smtp\_helo\_server\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20smtp_helo_server_ip">Link to this property</a>

smtp\_previous\_hop\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20smtp_previous_hop_ip">Link to this property</a>

subject?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20subject">Link to this property</a>

threat\_categories?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories">Link to this property</a>

to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20to">Link to this property</a>

to\_name?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20to_name">Link to this property</a>

<details>

<summary>

validation?: Validation| null

</summary>

comment?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

dkim?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

dmarc?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

spf?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20validation">Link to this property</a>

x\_originating\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)%20%3E%20(property)%20x_originating_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_list_response%20%3E%20(schema)>)

<details>

<summary>

InvestigateGetResponse {id, action\_log, client\_recipients, 32 more }

</summary>

id: string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Deprecatedaction\_log: Array&lt;ActionLog&gt;

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

</summary>

completed\_at: string

Timestamp when action completed.

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_at">Link to this property</a>

<details>

<summary>

operation: "MOVE"| "RELEASE"| "RECLASSIFY"| 3 more

Type of action performed.

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%201">Link to this property</a>

"RECLASSIFY"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%202">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%203">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%204">Link to this property</a>

"PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation">Link to this property</a>

Deprecatedcompleted\_timestamp?: string

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

<details>

<summary>

properties?: Properties {folder, requested\_by }

Additional properties for the action.

</summary>

folder?: string

Target folder for move operations.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20folder">Link to this property</a>

requested\_by?: string

User who requested the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20requested_by">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

status?: string| null

Status of the action.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20action_log">Link to this property</a>

client\_recipients: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20client_recipients">Link to this property</a>

detection\_reasons: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20detection_reasons">Link to this property</a>

is\_phish\_submission: boolean

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20is_phish_submission">Link to this property</a>

is\_quarantined: boolean

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20is_quarantined">Link to this property</a>

postfix\_id: string

The identifier of the message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

<details>

<summary>

properties: Properties {allowlisted\_pattern, allowlisted\_pattern\_type, blocklisted\_message, 2 more }

Message processing properties.

</summary>

allowlisted\_pattern?: string| null

Pattern that allowlisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern">Link to this property</a>

<details>

<summary>

allowlisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Type of allowlist pattern.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type">Link to this property</a>

blocklisted\_message?: boolean| null

Whether message was blocklisted.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_message">Link to this property</a>

blocklisted\_pattern?: string| null

Pattern that blocklisted this message.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_pattern">Link to this property</a>

<details>

<summary>

whitelisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Legacy field for allowlist pattern type.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

Deprecatedts: string

Use <code>scanned_at</code> instead.

Deprecated, use <code>scanned_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20ts">Link to this property</a>

alert\_id?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_mode?: "DIRECT"| "BCC"| "JOURNAL"| 8 more| null

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%202">Link to this property</a>

"REVIEW\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%203">Link to this property</a>

"DMARC\_UNVERIFIED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%204">Link to this property</a>

"DMARC\_FAILURE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%205">Link to this property</a>

"DMARC\_AGGREGATE\_REPORT"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%206">Link to this property</a>

"THREAT\_INTEL\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%207">Link to this property</a>

"SIMULATION\_SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%208">Link to this property</a>

"API"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%209">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode%20%3E%20(member)%2010">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_mode">Link to this property</a>

<details>

<summary>

delivery\_status?: Array&lt;"delivered"| "moved"| "quarantined"| 5 more&gt;| null

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20delivery_status">Link to this property</a>

edf\_hash?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20edf_hash">Link to this property</a>

envelope\_from?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20envelope_from">Link to this property</a>

envelope\_to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20envelope_to">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

Deprecatedfindings?: Array&lt;Finding&gt;| null

Use the <code>findings</code> field from GET /investigate/{investigate\_id}/detections instead.

Deprecated, use the <code>findings</code> field from <code>GET /investigate/{investigate_id}/detections</code> instead. End of life: November 1, 2026. Detection findings for this message.

</summary>

attachment?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

detail?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

detection?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

field?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

name?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

portion?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

reason?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

score?: number| null

formatdouble

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

value?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20findings">Link to this property</a>

from?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20from">Link to this property</a>

from\_name?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20from_name">Link to this property</a>

htmltext\_structure\_hash?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20htmltext_structure_hash">Link to this property</a>

message\_id?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

<details>

<summary>

post\_delivery\_operations?: Array&lt;"PREVIEW"| "QUARANTINE\_RELEASE"| "SUBMISSION"| "MOVE"&gt;| null

Post-delivery operations performed on this message.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"MOVE"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20post_delivery_operations">Link to this property</a>

postfix\_id\_outbound?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id_outbound">Link to this property</a>

replyto?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20replyto">Link to this property</a>

scanned\_at?: string| null

When the message was scanned (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20scanned_at">Link to this property</a>

sent\_at?: string| null

When the message was sent (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20sent_at">Link to this property</a>

sent\_date?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20sent_date">Link to this property</a>

smtp\_helo\_server\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20smtp_helo_server_ip">Link to this property</a>

smtp\_previous\_hop\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20smtp_previous_hop_ip">Link to this property</a>

subject?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20subject">Link to this property</a>

threat\_categories?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories">Link to this property</a>

to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20to">Link to this property</a>

to\_name?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20to_name">Link to this property</a>

<details>

<summary>

validation?: Validation| null

</summary>

comment?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

dkim?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

dmarc?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

spf?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20validation">Link to this property</a>

x\_originating\_ip?: string| null

<a href="#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)%20%3E%20(property)%20x_originating_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate%20%3E%20(model)%20investigate_get_response%20%3E%20(schema)>)

#### Email SecurityInvestigateDetections

##### [Get message detection details](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/detections/methods/get)

client.emailSecurity.investigate.detections.get(stringinvestigateID, DetectionGetParams {account\_id } params, RequestOptionsoptions?): [DetectionGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)>) {action, attachments, findings, 6 more }

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/detections

##### ModelsExpand Collapse

<details>

<summary>

DetectionGetResponse {action, attachments, findings, 6 more }

</summary>

action: string

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

<details>

<summary>

attachments: Array&lt;Attachment&gt;

</summary>

size: number

Size of the attachment in bytes.

minimum0

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20size">Link to this property</a>

content\_type?: string| null

MIME type of the attachment.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20content_type">Link to this property</a>

<details>

<summary>

detection?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Detection result for this attachment.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

encrypted?: boolean| null

Whether the attachment is encrypted.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20encrypted">Link to this property</a>

filename?: string| null

Name of the attached file.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20filename">Link to this property</a>

md5?: string| null

MD5 hash of the attachment.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20md5">Link to this property</a>

name?: string| null

Attachment name (alternative to filename).

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

sha1?: string| null

SHA1 hash of the attachment.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20sha1">Link to this property</a>

sha256?: string| null

SHA256 hash of the attachment.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments%20%3E%20(items)%20%3E%20(property)%20sha256">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20attachments">Link to this property</a>

<details>

<summary>

findings: Array&lt;Finding&gt;| null

</summary>

attachment?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

detail?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

detection?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Detection result associated with this finding.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

field?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

name?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

portion?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

reason?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

score?: number| null

formatdouble

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

value?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20findings">Link to this property</a>

<details>

<summary>

headers: Array&lt;Header&gt;

</summary>

name: string

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20headers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

value: string

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20headers%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20headers">Link to this property</a>

<details>

<summary>

links: Array&lt;Link&gt;

</summary>

href: string

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20links%20%3E%20(items)%20%3E%20(property)%20href">Link to this property</a>

text?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20links%20%3E%20(items)%20%3E%20(property)%20text">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20links">Link to this property</a>

<details>

<summary>

sender\_info: SenderInfo {as\_name, as\_number, geo, 2 more }

</summary>

as\_name?: string| null

The name of the autonomous system.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info%20%3E%20(property)%20as_name">Link to this property</a>

as\_number?: number| null

The number of the autonomous system.

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info%20%3E%20(property)%20as_number">Link to this property</a>

geo?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info%20%3E%20(property)%20geo">Link to this property</a>

ip?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info%20%3E%20(property)%20ip">Link to this property</a>

pld?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info%20%3E%20(property)%20pld">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20sender_info">Link to this property</a>

<details>

<summary>

threat\_categories: Array&lt;ThreatCategory&gt;

</summary>

id?: number

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

description?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

name?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20threat_categories">Link to this property</a>

<details>

<summary>

validation: Validation {comment, dkim, dmarc, spf }

</summary>

comment?: string| null

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

dkim?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

dmarc?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

spf?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20validation">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)%20%3E%20(property)%20final_disposition">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.detections%20%3E%20(model)%20detection_get_response%20%3E%20(schema)>)

#### Email SecurityInvestigatePreview

##### [Get preview for a detection](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/preview/methods/get)

client.emailSecurity.investigate.preview.get(stringinvestigateID, PreviewGetParams {account\_id } params, RequestOptionsoptions?): [PreviewGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_get_response%20%3E%20(schema)>) {screenshot }

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/preview

##### [Generate preview for a non-detection message](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/preview/methods/create)

client.emailSecurity.investigate.preview.create(PreviewCreateParams {account\_id, id } params, RequestOptionsoptions?): [PreviewCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_create_response%20%3E%20(schema)>) {screenshot }

POST/accounts/{account\_id}/email-security/investigate/preview

##### ModelsExpand Collapse

<details>

<summary>

PreviewGetResponse {screenshot }

</summary>

screenshot: string

A base64 encoded PNG image of the email.

<a href="#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_get_response%20%3E%20(schema)%20%3E%20(property)%20screenshot">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_get_response%20%3E%20(schema)>)

<details>

<summary>

PreviewCreateResponse {screenshot }

</summary>

screenshot: string

A base64 encoded PNG image of the email.

<a href="#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_create_response%20%3E%20(schema)%20%3E%20(property)%20screenshot">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.preview%20%3E%20(model)%20preview_create_response%20%3E%20(schema)>)

#### Email SecurityInvestigateRaw

##### [Get raw email content](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/raw/methods/get)

client.emailSecurity.investigate.raw.get(stringinvestigateID, RawGetParams {account\_id } params, RequestOptionsoptions?): [RawGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>) {raw }

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/raw

##### ModelsExpand Collapse

<details>

<summary>

RawGetResponse {raw }

</summary>

raw: string

A UTF-8 encoded eml file of the email.

<a href="#(resource)%20email_security.investigate.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20raw">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

#### Email SecurityInvestigateTrace

##### [Get email trace](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/trace/methods/get)

client.emailSecurity.investigate.trace.get(stringinvestigateID, TraceGetParams {account\_id } params, RequestOptionsoptions?): [TraceGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)>) {inbound, outbound }

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/trace

##### ModelsExpand Collapse

<details>

<summary>

TraceGetResponse {inbound, outbound }

</summary>

<details>

<summary>

inbound: Inbound {lines, pending }

</summary>

<details>

<summary>

lines?: Array&lt;Line&gt;| null

</summary>

lineno?: number

Line number in the trace log.

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20lineno">Link to this property</a>

logged\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20logged_at">Link to this property</a>

message?: string

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

Deprecatedts?: string

Use <code>logged_at</code> instead.

Deprecated, use <code>logged_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20ts">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20lines">Link to this property</a>

pending?: boolean| null

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound%20%3E%20(property)%20pending">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20inbound">Link to this property</a>

<details>

<summary>

outbound: Outbound {lines, pending }

</summary>

<details>

<summary>

lines?: Array&lt;Line&gt;| null

</summary>

lineno?: number

Line number in the trace log.

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20lineno">Link to this property</a>

logged\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20logged_at">Link to this property</a>

message?: string

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

Deprecatedts?: string

Use <code>logged_at</code> instead.

Deprecated, use <code>logged_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20lines%20%3E%20(items)%20%3E%20(property)%20ts">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20lines">Link to this property</a>

pending?: boolean| null

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound%20%3E%20(property)%20pending">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)%20%3E%20(property)%20outbound">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.trace%20%3E%20(model)%20trace_get_response%20%3E%20(schema)>)

#### Email SecurityInvestigateMove

##### [Move a message](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/move/methods/create)

client.emailSecurity.investigate.move.create(stringinvestigateID, MoveCreateParams {account\_id, destination, expected\_disposition } params, RequestOptionsoptions?): SinglePage< [MoveCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)>) {success, completed\_at, completed\_timestamp, 6 more } >

POST/accounts/{account\_id}/email-security/investigate/{investigate\_id}/move

##### [Move messages](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/move/methods/bulk)

client.emailSecurity.investigate.move.bulk(MoveBulkParams {account\_id, destination, ids, 2 more } params, RequestOptionsoptions?): SinglePage< [MoveBulkResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)>) {success, completed\_at, completed\_timestamp, 6 more } >

POST/accounts/{account\_id}/email-security/investigate/move

##### ModelsExpand Collapse

<details>

<summary>

MoveCreateResponse {success, completed\_at, completed\_timestamp, 6 more }

</summary>

success: boolean

Whether the operation succeeded.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

completed\_at?: string| null

When the move operation completed (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

Deprecatedcompleted\_timestamp?: string

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

destination?: string| null

Destination folder for the message.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20destination">Link to this property</a>

Deprecateditem\_count?: number

This field is deprecated.

Number of items moved. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20item_count">Link to this property</a>

message\_id?: string| null

Message identifier.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

operation?: string| null

Type of operation performed.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20operation">Link to this property</a>

recipient?: string| null

Recipient email address.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20recipient">Link to this property</a>

status?: string| null

Operation status.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_create_response%20%3E%20(schema)>)

<details>

<summary>

MoveBulkResponse {success, completed\_at, completed\_timestamp, 6 more }

</summary>

success: boolean

Whether the operation succeeded.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

completed\_at?: string| null

When the move operation completed (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

Deprecatedcompleted\_timestamp?: string

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

destination?: string| null

Destination folder for the message.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20destination">Link to this property</a>

Deprecateditem\_count?: number

This field is deprecated.

Number of items moved. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20item_count">Link to this property</a>

message\_id?: string| null

Message identifier.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

operation?: string| null

Type of operation performed.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20operation">Link to this property</a>

recipient?: string| null

Recipient email address.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20recipient">Link to this property</a>

status?: string| null

Operation status.

<a href="#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.move%20%3E%20(model)%20move_bulk_response%20%3E%20(schema)>)

#### Email SecurityInvestigateReclassify

##### [Change email classification](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/reclassify/methods/create)

Deprecated

client.emailSecurity.investigate.reclassify.create(stringinvestigateID, ReclassifyCreateParams {account\_id, expected\_disposition, eml\_content, escalated\_submission\_id } params, RequestOptionsoptions?): [ReclassifyCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.reclassify%20%3E%20(model)%20reclassify_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/email-security/investigate/{investigate\_id}/reclassify

##### ModelsExpand Collapse

ReclassifyCreateResponse = unknown

[Link to this property](<#(resource)%20email_security.investigate.reclassify%20%3E%20(model)%20reclassify_create_response%20%3E%20(schema)>)

#### Email SecurityInvestigateRelease

##### [Release messages from quarantine](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/release/methods/bulk)

client.emailSecurity.investigate.release.bulk(ReleaseBulkParams {account\_id, ids } params, RequestOptionsoptions?): SinglePage< [ReleaseBulkResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)>) {id, delivered, failed, 2 more } >

POST/accounts/{account\_id}/email-security/investigate/release

##### ModelsExpand Collapse

<details>

<summary>

ReleaseBulkResponse {id, delivered, failed, 2 more }

</summary>

id: string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

delivered?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)%20%3E%20(property)%20delivered">Link to this property</a>

failed?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)%20%3E%20(property)%20failed">Link to this property</a>

Deprecatedpostfix\_id?: string

Use <code>id</code> instead.

Deprecated, use <code>id</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

undelivered?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)%20%3E%20(property)%20undelivered">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.release%20%3E%20(model)%20release_bulk_response%20%3E%20(schema)>)

#### Email SecurityInvestigateBulk

##### [List bulk action jobs](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/methods/list)

client.emailSecurity.investigate.bulk.list(BulkListParams {account\_id, action\_type, page, 2 more } params, RequestOptionsoptions?): V4PagePaginationArray< [BulkListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)>) {action\_params, action\_type, created\_at, 13 more } >

GET/accounts/{account\_id}/email-security/investigate/bulk

##### [Create a bulk action job](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/methods/create)

client.emailSecurity.investigate.bulk.create(BulkCreateParams {account\_id, action, search\_params, 3 more } params, RequestOptionsoptions?): [BulkCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)>) {action\_params, action\_type, created\_at, 13 more }

POST/accounts/{account\_id}/email-security/investigate/bulk

##### [Get bulk action job details](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/methods/get)

client.emailSecurity.investigate.bulk.get(stringjobID, BulkGetParams {account\_id } params, RequestOptionsoptions?): [BulkGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)>) {action\_params, action\_type, created\_at, 13 more }

GET/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}

##### [Delete a bulk action job](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/methods/delete)

client.emailSecurity.investigate.bulk.delete(stringjobID, BulkDeleteParams {account\_id } params, RequestOptionsoptions?): [BulkDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}

##### ModelsExpand Collapse

<details>

<summary>

BulkListResponse {action\_params, action\_type, created\_at, 13 more }

</summary>

<details>

<summary>

action\_params: Move {destination, type, expected\_disposition } | Release {type }

</summary>

One of the following:

<details>

<summary>

Move {destination, type, expected\_disposition }

</summary>

<details>

<summary>

destination: "Inbox"| "JunkEmail"| "DeletedItems"| 2 more

The mailbox folder to move messages to.

</summary>

One of the following:

"Inbox"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%200">Link to this property</a>

"JunkEmail"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%201">Link to this property</a>

"DeletedItems"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%202">Link to this property</a>

"RecoverableItemsDeletions"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%203">Link to this property</a>

"RecoverableItemsPurges"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination">Link to this property</a>

type: "MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

Deprecatedexpected\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

This field is nonfunctional.

Nonfunctional field. End of life: December 1, 2026.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Release {type }

</summary>

type: "RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params">Link to this property</a>

<details>

<summary>

action\_type: "MOVE"| "RELEASE"

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

job\_id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20job_id">Link to this property</a>

messages\_cancelled: number

Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total\_messages\_discovered = messages\_pending + messages\_successful + messages\_failed + messages\_skipped + messages\_cancelled.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20messages_cancelled">Link to this property</a>

messages\_failed: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20messages_failed">Link to this property</a>

messages\_pending: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20messages_pending">Link to this property</a>

messages\_skipped: number

Messages that discovery skipped (for example, phish submissions, which the job cannot action).

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20messages_skipped">Link to this property</a>

messages\_successful: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20messages_successful">Link to this property</a>

<details>

<summary>

search\_params: SearchParams {action\_log, alert\_id, delivery\_status, 15 more }

</summary>

Deprecatedaction\_log?: boolean

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20action_log">Link to this property</a>

alert\_id?: string| null

Alert ID of the detection to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_status?: "delivered"| "moved"| "quarantined"| 5 more| null

Delivery status to filter by.

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status">Link to this property</a>

detections\_only?: boolean

Whether to include only detections in search results.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20detections_only">Link to this property</a>

domain?: string| null

Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20domain">Link to this property</a>

end?: string

End of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20end">Link to this property</a>

exact\_subject?: string| null

Match messages whose subject line equals this value exactly.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20exact_subject">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Dispositions to filter by.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

message\_action?: "PREVIEW"| "QUARANTINE\_RELEASED"| "MOVED"| null

Message actions to filter by.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%201">Link to this property</a>

"MOVED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action">Link to this property</a>

message\_id?: string| null

Message-ID header value to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_id">Link to this property</a>

metric?: string| null

Metric name to filter the search by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20metric">Link to this property</a>

query?: string| null

Space-delimited search term. Case-insensitive.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20query">Link to this property</a>

recipient?: string| null

Match messages whose recipient is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20recipient">Link to this property</a>

sender?: string| null

Match messages whose sender is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20sender">Link to this property</a>

smtp\_helo\_ip?: string| null

Matches messages whose SMTP HELO server IP address equals this value.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20smtp_helo_ip">Link to this property</a>

start?: string

Beginning of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20start">Link to this property</a>

subject?: string| null

Match messages whose subject contains these keywords, in any order.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20subject">Link to this property</a>

submissions?: boolean

Whether to search reclassification submissions instead of original messages.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20submissions">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20search_params">Link to this property</a>

<details>

<summary>

status: "PENDING"| "DISCOVERING"| "PROCESSING"| 3 more

Status of a bulk action job.

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"DISCOVERING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"PROCESSING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"COMPLETED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"CANCELLED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

total\_messages\_discovered: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20total_messages_discovered">Link to this property</a>

comment?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20comment">Link to this property</a>

completed\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

started\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20started_at">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)%20%3E%20(property)%20status_message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_list_response%20%3E%20(schema)>)

<details>

<summary>

BulkCreateResponse {action\_params, action\_type, created\_at, 13 more }

</summary>

<details>

<summary>

action\_params: Move {destination, type, expected\_disposition } | Release {type }

</summary>

One of the following:

<details>

<summary>

Move {destination, type, expected\_disposition }

</summary>

<details>

<summary>

destination: "Inbox"| "JunkEmail"| "DeletedItems"| 2 more

The mailbox folder to move messages to.

</summary>

One of the following:

"Inbox"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%200">Link to this property</a>

"JunkEmail"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%201">Link to this property</a>

"DeletedItems"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%202">Link to this property</a>

"RecoverableItemsDeletions"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%203">Link to this property</a>

"RecoverableItemsPurges"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination">Link to this property</a>

type: "MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

Deprecatedexpected\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

This field is nonfunctional.

Nonfunctional field. End of life: December 1, 2026.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Release {type }

</summary>

type: "RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params">Link to this property</a>

<details>

<summary>

action\_type: "MOVE"| "RELEASE"

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

job\_id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20job_id">Link to this property</a>

messages\_cancelled: number

Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total\_messages\_discovered = messages\_pending + messages\_successful + messages\_failed + messages\_skipped + messages\_cancelled.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_cancelled">Link to this property</a>

messages\_failed: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_failed">Link to this property</a>

messages\_pending: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_pending">Link to this property</a>

messages\_skipped: number

Messages that discovery skipped (for example, phish submissions, which the job cannot action).

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_skipped">Link to this property</a>

messages\_successful: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_successful">Link to this property</a>

<details>

<summary>

search\_params: SearchParams {action\_log, alert\_id, delivery\_status, 15 more }

</summary>

Deprecatedaction\_log?: boolean

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20action_log">Link to this property</a>

alert\_id?: string| null

Alert ID of the detection to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_status?: "delivered"| "moved"| "quarantined"| 5 more| null

Delivery status to filter by.

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status">Link to this property</a>

detections\_only?: boolean

Whether to include only detections in search results.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20detections_only">Link to this property</a>

domain?: string| null

Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20domain">Link to this property</a>

end?: string

End of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20end">Link to this property</a>

exact\_subject?: string| null

Match messages whose subject line equals this value exactly.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20exact_subject">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Dispositions to filter by.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

message\_action?: "PREVIEW"| "QUARANTINE\_RELEASED"| "MOVED"| null

Message actions to filter by.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%201">Link to this property</a>

"MOVED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action">Link to this property</a>

message\_id?: string| null

Message-ID header value to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_id">Link to this property</a>

metric?: string| null

Metric name to filter the search by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20metric">Link to this property</a>

query?: string| null

Space-delimited search term. Case-insensitive.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20query">Link to this property</a>

recipient?: string| null

Match messages whose recipient is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20recipient">Link to this property</a>

sender?: string| null

Match messages whose sender is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20sender">Link to this property</a>

smtp\_helo\_ip?: string| null

Matches messages whose SMTP HELO server IP address equals this value.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20smtp_helo_ip">Link to this property</a>

start?: string

Beginning of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20start">Link to this property</a>

subject?: string| null

Match messages whose subject contains these keywords, in any order.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20subject">Link to this property</a>

submissions?: boolean

Whether to search reclassification submissions instead of original messages.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20submissions">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params">Link to this property</a>

<details>

<summary>

status: "PENDING"| "DISCOVERING"| "PROCESSING"| 3 more

Status of a bulk action job.

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"DISCOVERING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"PROCESSING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"COMPLETED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"CANCELLED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

total\_messages\_discovered: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20total_messages_discovered">Link to this property</a>

comment?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20comment">Link to this property</a>

completed\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

started\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20started_at">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20status_message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_create_response%20%3E%20(schema)>)

<details>

<summary>

BulkGetResponse {action\_params, action\_type, created\_at, 13 more }

</summary>

<details>

<summary>

action\_params: Move {destination, type, expected\_disposition } | Release {type }

</summary>

One of the following:

<details>

<summary>

Move {destination, type, expected\_disposition }

</summary>

<details>

<summary>

destination: "Inbox"| "JunkEmail"| "DeletedItems"| 2 more

The mailbox folder to move messages to.

</summary>

One of the following:

"Inbox"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%200">Link to this property</a>

"JunkEmail"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%201">Link to this property</a>

"DeletedItems"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%202">Link to this property</a>

"RecoverableItemsDeletions"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%203">Link to this property</a>

"RecoverableItemsPurges"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination">Link to this property</a>

type: "MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

Deprecatedexpected\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

This field is nonfunctional.

Nonfunctional field. End of life: December 1, 2026.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Release {type }

</summary>

type: "RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_params">Link to this property</a>

<details>

<summary>

action\_type: "MOVE"| "RELEASE"

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20action_type">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

job\_id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20job_id">Link to this property</a>

messages\_cancelled: number

Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total\_messages\_discovered = messages\_pending + messages\_successful + messages\_failed + messages\_skipped + messages\_cancelled.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20messages_cancelled">Link to this property</a>

messages\_failed: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20messages_failed">Link to this property</a>

messages\_pending: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20messages_pending">Link to this property</a>

messages\_skipped: number

Messages that discovery skipped (for example, phish submissions, which the job cannot action).

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20messages_skipped">Link to this property</a>

messages\_successful: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20messages_successful">Link to this property</a>

<details>

<summary>

search\_params: SearchParams {action\_log, alert\_id, delivery\_status, 15 more }

</summary>

Deprecatedaction\_log?: boolean

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20action_log">Link to this property</a>

alert\_id?: string| null

Alert ID of the detection to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_status?: "delivered"| "moved"| "quarantined"| 5 more| null

Delivery status to filter by.

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status">Link to this property</a>

detections\_only?: boolean

Whether to include only detections in search results.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20detections_only">Link to this property</a>

domain?: string| null

Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20domain">Link to this property</a>

end?: string

End of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20end">Link to this property</a>

exact\_subject?: string| null

Match messages whose subject line equals this value exactly.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20exact_subject">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Dispositions to filter by.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

message\_action?: "PREVIEW"| "QUARANTINE\_RELEASED"| "MOVED"| null

Message actions to filter by.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%201">Link to this property</a>

"MOVED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action">Link to this property</a>

message\_id?: string| null

Message-ID header value to filter by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_id">Link to this property</a>

metric?: string| null

Metric name to filter the search by.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20metric">Link to this property</a>

query?: string| null

Space-delimited search term. Case-insensitive.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20query">Link to this property</a>

recipient?: string| null

Match messages whose recipient is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20recipient">Link to this property</a>

sender?: string| null

Match messages whose sender is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20sender">Link to this property</a>

smtp\_helo\_ip?: string| null

Matches messages whose SMTP HELO server IP address equals this value.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20smtp_helo_ip">Link to this property</a>

start?: string

Beginning of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20start">Link to this property</a>

subject?: string| null

Match messages whose subject contains these keywords, in any order.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20subject">Link to this property</a>

submissions?: boolean

Whether to search reclassification submissions instead of original messages.

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20submissions">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20search_params">Link to this property</a>

<details>

<summary>

status: "PENDING"| "DISCOVERING"| "PROCESSING"| 3 more

Status of a bulk action job.

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"DISCOVERING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"PROCESSING"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"COMPLETED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"CANCELLED"

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

total\_messages\_discovered: number

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20total_messages_discovered">Link to this property</a>

comment?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20comment">Link to this property</a>

completed\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

started\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20started_at">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)%20%3E%20(property)%20status_message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_get_response%20%3E%20(schema)>)

<details>

<summary>

BulkDeleteResponse {id }

</summary>

id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk%20%3E%20(model)%20bulk_delete_response%20%3E%20(schema)>)

#### Email SecurityInvestigateBulkCancel

##### [Cancel a bulk action job](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/subresources/cancel/methods/create)

client.emailSecurity.investigate.bulk.cancel.create(stringjobID, CancelCreateParams {account\_id } params, RequestOptionsoptions?): [CancelCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)>) {action\_params, action\_type, created\_at, 13 more }

POST/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}/cancel

##### ModelsExpand Collapse

<details>

<summary>

CancelCreateResponse {action\_params, action\_type, created\_at, 13 more }

</summary>

<details>

<summary>

action\_params: Move {destination, type, expected\_disposition } | Release {type }

</summary>

One of the following:

<details>

<summary>

Move {destination, type, expected\_disposition }

</summary>

<details>

<summary>

destination: "Inbox"| "JunkEmail"| "DeletedItems"| 2 more

The mailbox folder to move messages to.

</summary>

One of the following:

"Inbox"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%200">Link to this property</a>

"JunkEmail"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%201">Link to this property</a>

"DeletedItems"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%202">Link to this property</a>

"RecoverableItemsDeletions"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%203">Link to this property</a>

"RecoverableItemsPurges"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination">Link to this property</a>

type: "MOVE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

Deprecatedexpected\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

This field is nonfunctional.

Nonfunctional field. End of life: December 1, 2026.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Release {type }

</summary>

type: "RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_params">Link to this property</a>

<details>

<summary>

action\_type: "MOVE"| "RELEASE"

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20action_type">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

job\_id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20job_id">Link to this property</a>

messages\_cancelled: number

Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total\_messages\_discovered = messages\_pending + messages\_successful + messages\_failed + messages\_skipped + messages\_cancelled.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_cancelled">Link to this property</a>

messages\_failed: number

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_failed">Link to this property</a>

messages\_pending: number

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_pending">Link to this property</a>

messages\_skipped: number

Messages that discovery skipped (for example, phish submissions, which the job cannot action).

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_skipped">Link to this property</a>

messages\_successful: number

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20messages_successful">Link to this property</a>

<details>

<summary>

search\_params: SearchParams {action\_log, alert\_id, delivery\_status, 15 more }

</summary>

Deprecatedaction\_log?: boolean

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20action_log">Link to this property</a>

alert\_id?: string| null

Alert ID of the detection to filter by.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_status?: "delivered"| "moved"| "quarantined"| 5 more| null

Delivery status to filter by.

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20delivery_status">Link to this property</a>

detections\_only?: boolean

Whether to include only detections in search results.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20detections_only">Link to this property</a>

domain?: string| null

Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20domain">Link to this property</a>

end?: string

End of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20end">Link to this property</a>

exact\_subject?: string| null

Match messages whose subject line equals this value exactly.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20exact_subject">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

Dispositions to filter by.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

message\_action?: "PREVIEW"| "QUARANTINE\_RELEASED"| "MOVED"| null

Message actions to filter by.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%201">Link to this property</a>

"MOVED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_action">Link to this property</a>

message\_id?: string| null

Message-ID header value to filter by.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20message_id">Link to this property</a>

metric?: string| null

Metric name to filter the search by.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20metric">Link to this property</a>

query?: string| null

Space-delimited search term. Case-insensitive.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20query">Link to this property</a>

recipient?: string| null

Match messages whose recipient is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20recipient">Link to this property</a>

sender?: string| null

Match messages whose sender is this email address or domain.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20sender">Link to this property</a>

smtp\_helo\_ip?: string| null

Matches messages whose SMTP HELO server IP address equals this value.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20smtp_helo_ip">Link to this property</a>

start?: string

Beginning of search date range.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20start">Link to this property</a>

subject?: string| null

Match messages whose subject contains these keywords, in any order.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20subject">Link to this property</a>

submissions?: boolean

Whether to search reclassification submissions instead of original messages.

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params%20%3E%20(property)%20submissions">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20search_params">Link to this property</a>

<details>

<summary>

status: "PENDING"| "DISCOVERING"| "PROCESSING"| 3 more

Status of a bulk action job.

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"DISCOVERING"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"PROCESSING"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"COMPLETED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"CANCELLED"

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

total\_messages\_discovered: number

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20total_messages_discovered">Link to this property</a>

comment?: string| null

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20comment">Link to this property</a>

completed\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20completed_at">Link to this property</a>

started\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20started_at">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)%20%3E%20(property)%20status_message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk.cancel%20%3E%20(model)%20cancel_create_response%20%3E%20(schema)>)

#### Email SecurityInvestigateBulkMessages

##### [List messages for a bulk action job](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/investigate/subresources/bulk/subresources/messages/methods/list)

client.emailSecurity.investigate.bulk.messages.list(stringjobID, MessageListParams {account\_id, page, per\_page, status } params, RequestOptionsoptions?): V4PagePaginationArray< [MessageListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)>) {action\_params, action\_type, created\_at, 10 more } >

GET/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}/messages

##### ModelsExpand Collapse

<details>

<summary>

MessageListResponse {action\_params, action\_type, created\_at, 10 more }

</summary>

<details>

<summary>

action\_params: Move {client\_recipient, destination, type, expected\_disposition } | Release {client\_recipient, type }

</summary>

One of the following:

<details>

<summary>

Move {client\_recipient, destination, type, expected\_disposition }

</summary>

client\_recipient: string

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20client_recipient">Link to this property</a>

<details>

<summary>

destination: "Inbox"| "JunkEmail"| "DeletedItems"| 2 more

The mailbox folder to move messages to.

</summary>

One of the following:

"Inbox"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%200">Link to this property</a>

"JunkEmail"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%201">Link to this property</a>

"DeletedItems"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%202">Link to this property</a>

"RecoverableItemsDeletions"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%203">Link to this property</a>

"RecoverableItemsPurges"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20destination">Link to this property</a>

type: "MOVE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

Deprecatedexpected\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

This field is nonfunctional.

Nonfunctional field. End of life: December 1, 2026.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200%20%3E%20(property)%20expected_disposition">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

Release {client\_recipient, type }

</summary>

client\_recipient: string

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20client_recipient">Link to this property</a>

type: "RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_params">Link to this property</a>

<details>

<summary>

action\_type: "MOVE"| "RELEASE"

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20action_type">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

message\_id: string

formatuuid

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message_id">Link to this property</a>

postfix\_id: string

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20postfix_id">Link to this property</a>

retry\_count: number

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20retry_count">Link to this property</a>

<details>

<summary>

status: "PENDING"| "PROCESSING"| "COMPLETED"| 3 more

Status of a message within a bulk action job.

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"PROCESSING"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"COMPLETED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"CANCELLED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"SKIPPED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

alert\_id?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20alert_id">Link to this property</a>

email\_message\_id?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20email_message_id">Link to this property</a>

<details>

<summary>

message?: Message {id, action\_log, client\_recipients, 32 more }

</summary>

id: string

Unique identifier for a message retrieved from investigation.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Deprecatedaction\_log: Array&lt;ActionLog&gt;

Use GET /investigate/{investigate\_id}/action\_log instead.

Deprecated, use <code>GET /investigate/{investigate_id}/action_log</code> instead. End of life: November 1, 2026.

</summary>

completed\_at: string

Timestamp when action completed.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_at">Link to this property</a>

<details>

<summary>

operation: "MOVE"| "RELEASE"| "RECLASSIFY"| 3 more

Type of action performed.

</summary>

One of the following:

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%200">Link to this property</a>

"RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%201">Link to this property</a>

"RECLASSIFY"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%202">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%203">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%204">Link to this property</a>

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20operation">Link to this property</a>

Deprecatedcompleted\_timestamp?: string

Use <code>completed_at</code> instead.

Deprecated, use <code>completed_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20completed_timestamp">Link to this property</a>

<details>

<summary>

properties?: Properties {folder, requested\_by }

Additional properties for the action.

</summary>

folder?: string

Target folder for move operations.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20folder">Link to this property</a>

requested\_by?: string

User who requested the action.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties%20%3E%20(property)%20requested_by">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

status?: string| null

Status of the action.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20action_log">Link to this property</a>

client\_recipients: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20client_recipients">Link to this property</a>

detection\_reasons: Array&lt;string&gt;

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20detection_reasons">Link to this property</a>

is\_phish\_submission: boolean

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20is_phish_submission">Link to this property</a>

is\_quarantined: boolean

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20is_quarantined">Link to this property</a>

postfix\_id: string

The identifier of the message.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20postfix_id">Link to this property</a>

<details>

<summary>

properties: Properties {allowlisted\_pattern, allowlisted\_pattern\_type, blocklisted\_message, 2 more }

Message processing properties.

</summary>

allowlisted\_pattern?: string| null

Pattern that allowlisted this message.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern">Link to this property</a>

<details>

<summary>

allowlisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Type of allowlist pattern.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20allowlisted_pattern_type">Link to this property</a>

blocklisted\_message?: boolean| null

Whether message was blocklisted.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_message">Link to this property</a>

blocklisted\_pattern?: string| null

Pattern that blocklisted this message.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20blocklisted_pattern">Link to this property</a>

<details>

<summary>

whitelisted\_pattern\_type?: "quarantine\_release"| "acceptable\_sender"| "allowed\_sender"| 5 more| null

Legacy field for allowlist pattern type.

</summary>

One of the following:

"quarantine\_release"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%200">Link to this property</a>

"acceptable\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%201">Link to this property</a>

"allowed\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%202">Link to this property</a>

"allowed\_recipient"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%203">Link to this property</a>

"domain\_similarity"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%204">Link to this property</a>

"domain\_recency"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%205">Link to this property</a>

"managed\_acceptable\_sender"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%206">Link to this property</a>

"outbound\_ndr"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties%20%3E%20(property)%20whitelisted_pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20properties">Link to this property</a>

Deprecatedts: string

Use <code>scanned_at</code> instead.

Deprecated, use <code>scanned_at</code> instead. End of life: November 1, 2026.

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20ts">Link to this property</a>

alert\_id?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20alert_id">Link to this property</a>

<details>

<summary>

delivery\_mode?: "DIRECT"| "BCC"| "JOURNAL"| 8 more| null

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%202">Link to this property</a>

"REVIEW\_SUBMISSION"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%203">Link to this property</a>

"DMARC\_UNVERIFIED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%204">Link to this property</a>

"DMARC\_FAILURE\_REPORT"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%205">Link to this property</a>

"DMARC\_AGGREGATE\_REPORT"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%206">Link to this property</a>

"THREAT\_INTEL\_SUBMISSION"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%207">Link to this property</a>

"SIMULATION\_SUBMISSION"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%208">Link to this property</a>

"API"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%209">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode%20%3E%20(member)%2010">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_mode">Link to this property</a>

<details>

<summary>

delivery\_status?: Array&lt;"delivered"| "moved"| "quarantined"| 5 more&gt;| null

</summary>

One of the following:

"delivered"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"moved"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"quarantined"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"rejected"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"deferred"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"bounced"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"queued"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"move\_failed"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20delivery_status">Link to this property</a>

edf\_hash?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20edf_hash">Link to this property</a>

envelope\_from?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20envelope_from">Link to this property</a>

envelope\_to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20envelope_to">Link to this property</a>

<details>

<summary>

final\_disposition?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20final_disposition">Link to this property</a>

<details>

<summary>

Deprecatedfindings?: Array&lt;Finding&gt;| null

Use the <code>findings</code> field from GET /investigate/{investigate\_id}/detections instead.

Deprecated, use the <code>findings</code> field from <code>GET /investigate/{investigate_id}/detections</code> instead. End of life: November 1, 2026. Detection findings for this message.

</summary>

attachment?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20attachment">Link to this property</a>

detail?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detail">Link to this property</a>

<details>

<summary>

detection?: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more| null

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20detection">Link to this property</a>

field?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20field">Link to this property</a>

name?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

portion?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20portion">Link to this property</a>

reason?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20reason">Link to this property</a>

score?: number| null

formatdouble

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

value?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20findings">Link to this property</a>

from?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20from">Link to this property</a>

from\_name?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20from_name">Link to this property</a>

htmltext\_structure\_hash?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20htmltext_structure_hash">Link to this property</a>

message\_id?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20message_id">Link to this property</a>

<details>

<summary>

post\_delivery\_operations?: Array&lt;"PREVIEW"| "QUARANTINE\_RELEASE"| "SUBMISSION"| "MOVE"&gt;| null

Post-delivery operations performed on this message.

</summary>

One of the following:

"PREVIEW"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"QUARANTINE\_RELEASE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUBMISSION"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"MOVE"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20post_delivery_operations%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20post_delivery_operations">Link to this property</a>

postfix\_id\_outbound?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20postfix_id_outbound">Link to this property</a>

replyto?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20replyto">Link to this property</a>

scanned\_at?: string| null

When the message was scanned (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20scanned_at">Link to this property</a>

sent\_at?: string| null

When the message was sent (UTC).

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20sent_at">Link to this property</a>

sent\_date?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20sent_date">Link to this property</a>

smtp\_helo\_server\_ip?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20smtp_helo_server_ip">Link to this property</a>

smtp\_previous\_hop\_ip?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20smtp_previous_hop_ip">Link to this property</a>

subject?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20subject">Link to this property</a>

threat\_categories?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20threat_categories">Link to this property</a>

to?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20to">Link to this property</a>

to\_name?: Array&lt;string&gt;| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20to_name">Link to this property</a>

<details>

<summary>

validation?: Validation| null

</summary>

comment?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20comment">Link to this property</a>

<details>

<summary>

dkim?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dkim">Link to this property</a>

<details>

<summary>

dmarc?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20dmarc">Link to this property</a>

<details>

<summary>

spf?: "pass"| "neutral"| "fail"| 2 more| null

</summary>

One of the following:

"pass"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%200">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%201">Link to this property</a>

"fail"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%203">Link to this property</a>

"none"

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation%20%3E%20(property)%20spf">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20validation">Link to this property</a>

x\_originating\_ip?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message%20%3E%20(property)%20x_originating_ip">Link to this property</a>

</details>

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20message">Link to this property</a>

processed\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20processed_at">Link to this property</a>

retry\_after?: string| null

When to retry the action if it failed.

formatdate-time

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20retry_after">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)%20%3E%20(property)%20status_message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.investigate.bulk.messages%20%3E%20(model)%20message_list_response%20%3E%20(schema)>)

#### Email SecurityPhishguard

#### Email SecurityPhishguardReports

##### [List PhishGuard reports](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/phishguard/subresources/reports/methods/list)

client.emailSecurity.phishguard.reports.list(ReportListParams {account\_id, end, from\_date, 4 more } params, RequestOptionsoptions?): V4PagePaginationArray< [ReportListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)>) {id, content, disposition, 7 more } >

GET/accounts/{account\_id}/email-security/phishguard/reports

##### ModelsExpand Collapse

<details>

<summary>

ReportListResponse {id, content, disposition, 7 more }

</summary>

id: number

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

content: string

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20content">Link to this property</a>

<details>

<summary>

disposition: "MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more

The verdict Email Security assigns to a message.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20disposition">Link to this property</a>

<details>

<summary>

fields: Fields {to, from, occurred\_at, 2 more }

</summary>

to: Array&lt;string&gt;

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields%20%3E%20(property)%20to">Link to this property</a>

from?: string| null

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields%20%3E%20(property)%20from">Link to this property</a>

occurred\_at?: string

formatdate-time

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields%20%3E%20(property)%20occurred_at">Link to this property</a>

postfix\_id?: string| null

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields%20%3E%20(property)%20postfix_id">Link to this property</a>

Deprecatedts?: string

Use <code>occurred_at</code> instead.

Deprecated, use <code>occurred_at</code> instead.

formatdate-time

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields%20%3E%20(property)%20ts">Link to this property</a>

</details>

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20fields">Link to this property</a>

priority: string

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

title: string

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

created\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

tags?: Array&lt;Tag&gt;| null

</summary>

category: string

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

value: string

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

Deprecatedts?: string

Use <code>created_at</code> instead.

Deprecated, use <code>created_at</code> instead.

formatdate-time

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20ts">Link to this property</a>

updated\_at?: string| null

formatdate-time

<a href="#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.phishguard.reports%20%3E%20(model)%20report_list_response%20%3E%20(schema)>)

#### Email SecuritySettings

#### Email SecuritySettingsAllow Policies

##### [List email allow policies](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/list)

client.emailSecurity.settings.allowPolicies.list(AllowPolicyListParams {account\_id, direction, is\_acceptable\_sender, 9 more } params, RequestOptionsoptions?): V4PagePaginationArray< [AllowPolicyListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)>) {id, created\_at, last\_modified, 12 more } >

GET/accounts/{account\_id}/email-security/settings/allow\_policies

##### [Get an email allow policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/get)

client.emailSecurity.settings.allowPolicies.get(stringpolicyID, AllowPolicyGetParams {account\_id } params, RequestOptionsoptions?): [AllowPolicyGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)>) {id, created\_at, last\_modified, 12 more }

GET/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Create email allow policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/create)

client.emailSecurity.settings.allowPolicies.create(AllowPolicyCreateParams {account\_id, is\_acceptable\_sender, is\_exempt\_recipient, 9 more } params, RequestOptionsoptions?): [AllowPolicyCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)>) {id, created\_at, last\_modified, 12 more }

POST/accounts/{account\_id}/email-security/settings/allow\_policies

##### [Update an email allow policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/edit)

client.emailSecurity.settings.allowPolicies.edit(stringpolicyID, AllowPolicyEditParams {account\_id, comments, is\_acceptable\_sender, 9 more } params, RequestOptionsoptions?): [AllowPolicyEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)>) {id, created\_at, last\_modified, 12 more }

PATCH/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Delete an email allow policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/delete)

client.emailSecurity.settings.allowPolicies.delete(stringpolicyID, AllowPolicyDeleteParams {account\_id } params, RequestOptionsoptions?): [AllowPolicyDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Batch allow policy operations](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/allow_policies/methods/batch)

client.emailSecurity.settings.allowPolicies.batch(AllowPolicyBatchParams {account\_id, deletes, patches, 2 more } params, RequestOptionsoptions?): [AllowPolicyBatchResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)>) {deletes, patches, posts, puts }

POST/accounts/{account\_id}/email-security/settings/allow\_policies/batch

##### ModelsExpand Collapse

<details>

<summary>

AllowPolicyListResponse {id, created\_at, last\_modified, 12 more }

An email allow policy.

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_list_response%20%3E%20(schema)>)

<details>

<summary>

AllowPolicyGetResponse {id, created\_at, last\_modified, 12 more }

An email allow policy.

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_get_response%20%3E%20(schema)>)

<details>

<summary>

AllowPolicyCreateResponse {id, created\_at, last\_modified, 12 more }

An email allow policy.

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_create_response%20%3E%20(schema)>)

<details>

<summary>

AllowPolicyEditResponse {id, created\_at, last\_modified, 12 more }

An email allow policy.

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_edit_response%20%3E%20(schema)>)

<details>

<summary>

AllowPolicyDeleteResponse {id }

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_delete_response%20%3E%20(schema)>)

<details>

<summary>

AllowPolicyBatchResponse {deletes, patches, posts, puts }

</summary>

<details>

<summary>

deletes?: Array&lt;Delete&gt;

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes">Link to this property</a>

<details>

<summary>

patches?: Array&lt;Patch&gt;

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches">Link to this property</a>

<details>

<summary>

posts?: Array&lt;Post&gt;

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts">Link to this property</a>

<details>

<summary>

puts?: Array&lt;Put&gt;

</summary>

id: string

Allow policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

Deprecatedlast\_modified: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

is\_acceptable\_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_acceptable_sender">Link to this property</a>

is\_exempt\_recipient?: boolean

Bypasses all detections for messages to this recipient.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_exempt_recipient">Link to this property</a>

Deprecatedis\_recipient?: boolean

Use <code>is_exempt_recipient</code> instead.

Deprecated as of July 1, 2025. Use <code>is_exempt_recipient</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_recipient">Link to this property</a>

is\_regex?: boolean

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedis\_sender?: boolean

Use <code>is_trusted_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_trusted_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_sender">Link to this property</a>

Deprecatedis\_spoof?: boolean

Use <code>is_acceptable_sender</code> instead.

Deprecated as of July 1, 2025. Use <code>is_acceptable_sender</code> instead. End of life: July 1, 2026.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_spoof">Link to this property</a>

is\_trusted\_sender?: boolean

Bypasses all detections and link following for messages from this sender.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_trusted_sender">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

verify\_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20verify_sender">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.allow_policies%20%3E%20(model)%20allow_policy_batch_response%20%3E%20(schema)>)

#### Email SecuritySettingsBlock Senders

##### [List blocked email senders](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/list)

client.emailSecurity.settings.blockSenders.list(BlockSenderListParams {account\_id, direction, order, 5 more } params, RequestOptionsoptions?): V4PagePaginationArray< [BlockSenderListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)>) {id, comments, created\_at, 5 more } >

GET/accounts/{account\_id}/email-security/settings/block\_senders

##### [Get a blocked email sender](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/get)

client.emailSecurity.settings.blockSenders.get(stringpatternID, BlockSenderGetParams {account\_id } params, RequestOptionsoptions?): [BlockSenderGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)>) {id, comments, created\_at, 5 more }

GET/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Create blocked email sender](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/create)

client.emailSecurity.settings.blockSenders.create(BlockSenderCreateParams {account\_id, is\_regex, pattern, 2 more } params, RequestOptionsoptions?): [BlockSenderCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)>) {id, comments, created\_at, 5 more }

POST/accounts/{account\_id}/email-security/settings/block\_senders

##### [Update a blocked email sender](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/edit)

client.emailSecurity.settings.blockSenders.edit(stringpatternID, BlockSenderEditParams {account\_id, comments, is\_regex, 2 more } params, RequestOptionsoptions?): [BlockSenderEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)>) {id, comments, created\_at, 5 more }

PATCH/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Delete a blocked email sender](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/delete)

client.emailSecurity.settings.blockSenders.delete(stringpatternID, BlockSenderDeleteParams {account\_id } params, RequestOptionsoptions?): [BlockSenderDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Batch blocked sender operations](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/block_senders/methods/batch)

client.emailSecurity.settings.blockSenders.batch(BlockSenderBatchParams {account\_id, deletes, patches, 2 more } params, RequestOptionsoptions?): [BlockSenderBatchResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)>) {deletes, patches, posts, puts }

POST/accounts/{account\_id}/email-security/settings/block\_senders/batch

##### ModelsExpand Collapse

<details>

<summary>

BlockSenderListResponse {id, comments, created\_at, 5 more }

A blocked sender pattern.

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_list_response%20%3E%20(schema)>)

<details>

<summary>

BlockSenderGetResponse {id, comments, created\_at, 5 more }

A blocked sender pattern.

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_get_response%20%3E%20(schema)>)

<details>

<summary>

BlockSenderCreateResponse {id, comments, created\_at, 5 more }

A blocked sender pattern.

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_create_response%20%3E%20(schema)>)

<details>

<summary>

BlockSenderEditResponse {id, comments, created\_at, 5 more }

A blocked sender pattern.

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_edit_response%20%3E%20(schema)>)

<details>

<summary>

BlockSenderDeleteResponse {id }

</summary>

id: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_delete_response%20%3E%20(schema)>)

<details>

<summary>

BlockSenderBatchResponse {deletes, patches, posts, puts }

</summary>

<details>

<summary>

deletes?: Array&lt;Delete&gt;

</summary>

id: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes">Link to this property</a>

<details>

<summary>

patches?: Array&lt;Patch&gt;

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches">Link to this property</a>

<details>

<summary>

posts?: Array&lt;Post&gt;

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts">Link to this property</a>

<details>

<summary>

puts?: Array&lt;Put&gt;

</summary>

id?: string

Blocked sender pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal value.

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The pattern value to match. The format depends on <code>pattern_type</code>: a valid email address for EMAIL (e.g. <code>user@example.com</code>), a valid domain name for DOMAIN (e.g. <code>example.com</code>), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. <code>1.2.3.4</code>, <code>1.2.3.0/24</code>, <code>2606:4700:4700::1111</code>, or <code>2606:4700:4700::/48</code>); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

pattern\_type?: "EMAIL"| "DOMAIN"| "IP"| "UNKNOWN"

Type of pattern matching.

- EMAIL: matches a full email address (e.g. <code>user@example.com</code>)
- DOMAIN: matches a domain name (e.g. <code>example.com</code>)
- IP: matches a plain IPv4 or IPv6 address (e.g. <code>1.2.3.4</code> or <code>2606:4700:4700::1111</code>) or CIDR block (e.g. <code>1.2.3.0/24</code> or <code>2606:4700:4700::/48</code>). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

</summary>

One of the following:

"EMAIL"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%200">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%201">Link to this property</a>

"IP"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%202">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern_type">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.block_senders%20%3E%20(model)%20block_sender_batch_response%20%3E%20(schema)>)

#### Email SecuritySettingsContent Policies

##### [List content policies](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/list)

client.emailSecurity.settings.contentPolicies.list(ContentPolicyListParams {account\_id, direction, enabled, 5 more } params, RequestOptionsoptions?): V4PagePaginationArray< [ContentPolicyListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)>) {id, created\_at, enabled, 5 more } >

GET/accounts/{account\_id}/email-security/settings/content\_policies

##### [Get a content policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/get)

client.emailSecurity.settings.contentPolicies.get(stringpolicyID, ContentPolicyGetParams {account\_id } params, RequestOptionsoptions?): [ContentPolicyGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)>) {id, created\_at, enabled, 5 more }

GET/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Create a content policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/create)

client.emailSecurity.settings.contentPolicies.create(ContentPolicyCreateParams {account\_id, enabled, name, 3 more } params, RequestOptionsoptions?): [ContentPolicyCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)>) {id, created\_at, enabled, 5 more }

POST/accounts/{account\_id}/email-security/settings/content\_policies

##### [Update a content policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/edit)

client.emailSecurity.settings.contentPolicies.edit(stringpolicyID, ContentPolicyEditParams {account\_id, enabled, name, 3 more } params, RequestOptionsoptions?): [ContentPolicyEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)>) {id, created\_at, enabled, 5 more }

PATCH/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Delete a content policy](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/delete)

client.emailSecurity.settings.contentPolicies.delete(stringpolicyID, ContentPolicyDeleteParams {account\_id } params, RequestOptionsoptions?): [ContentPolicyDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Batch content policy operations](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/content_policies/methods/batch)

client.emailSecurity.settings.contentPolicies.batch(ContentPolicyBatchParams {account\_id, deletes, patches, 2 more } params, RequestOptionsoptions?): [ContentPolicyBatchResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)>) {deletes, patches, posts, puts }

POST/accounts/{account\_id}/email-security/settings/content\_policies/batch

##### ModelsExpand Collapse

<details>

<summary>

ContentPolicyListResponse {id, created\_at, enabled, 5 more }

A content policy pattern that matches against the subject or body of an email.

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)%20%3E%20(property)%20targets">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_list_response%20%3E%20(schema)>)

<details>

<summary>

ContentPolicyGetResponse {id, created\_at, enabled, 5 more }

A content policy pattern that matches against the subject or body of an email.

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)%20%3E%20(property)%20targets">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_get_response%20%3E%20(schema)>)

<details>

<summary>

ContentPolicyCreateResponse {id, created\_at, enabled, 5 more }

A content policy pattern that matches against the subject or body of an email.

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)%20%3E%20(property)%20targets">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_create_response%20%3E%20(schema)>)

<details>

<summary>

ContentPolicyEditResponse {id, created\_at, enabled, 5 more }

A content policy pattern that matches against the subject or body of an email.

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)%20%3E%20(property)%20targets">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_edit_response%20%3E%20(schema)>)

<details>

<summary>

ContentPolicyDeleteResponse {id }

</summary>

id: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_delete_response%20%3E%20(schema)>)

<details>

<summary>

ContentPolicyBatchResponse {deletes, patches, posts, puts }

</summary>

<details>

<summary>

deletes?: Array&lt;Delete&gt;

</summary>

id: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes">Link to this property</a>

<details>

<summary>

patches?: Array&lt;Patch&gt;

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20targets">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches">Link to this property</a>

<details>

<summary>

posts?: Array&lt;Post&gt;

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20targets">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts">Link to this property</a>

<details>

<summary>

puts?: Array&lt;Put&gt;

</summary>

id?: string

Content policy identifier.

formatuuid

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

enabled?: boolean

Whether the policy is active.

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Human-readable name of the policy.

maxLength256

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

notes?: string| null

Optional note describing the purpose of the policy.

maxLength4096

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20notes">Link to this property</a>

pattern?: string

Regular expression the policy matches against.

maxLength2048

minLength1

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

<details>

<summary>

targets?: Array&lt;"SUBJECT"| "BODY"&gt;

Parts of the email the pattern is matched against.

</summary>

One of the following:

"SUBJECT"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BODY"

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20targets%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20targets">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.content_policies%20%3E%20(model)%20content_policy_batch_response%20%3E%20(schema)>)

#### Email SecuritySettingsDomains

##### [List protected email domains](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/list)

client.emailSecurity.settings.domains.list(DomainListParams {account\_id, active\_delivery\_mode, allowed\_delivery\_mode, 8 more } params, RequestOptionsoptions?): V4PagePaginationArray< [DomainListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)>) {id, allowed\_delivery\_modes, authorization, 19 more } >

GET/accounts/{account\_id}/email-security/settings/domains

##### [Get an email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/get)

client.emailSecurity.settings.domains.get(stringdomainID, DomainGetParams {account\_id } params, RequestOptionsoptions?): [DomainGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)>) {id, allowed\_delivery\_modes, authorization, 19 more }

GET/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Replace an email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/update)

client.emailSecurity.settings.domains.update(stringdomainID, DomainUpdateParams {account\_id, allowed\_delivery\_modes, drop\_dispositions, 8 more } params, RequestOptionsoptions?): [DomainUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)>) {id, allowed\_delivery\_modes, authorization, 19 more }

PUT/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Update an email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/edit)

client.emailSecurity.settings.domains.edit(stringdomainID, DomainEditParams {account\_id, allowed\_delivery\_modes, drop\_dispositions, 8 more } params, RequestOptionsoptions?): [DomainEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)>) {id, allowed\_delivery\_modes, authorization, 19 more }

PATCH/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Add a new email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/create)

client.emailSecurity.settings.domains.create(DomainCreateParams {account\_id, allowed\_delivery\_modes, domain, 9 more } params, RequestOptionsoptions?): [DomainCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)>) {id, allowed\_delivery\_modes, authorization, 19 more }

POST/accounts/{account\_id}/email-security/settings/domains

##### [Unprotect an email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/delete)

client.emailSecurity.settings.domains.delete(stringdomainID, DomainDeleteParams {account\_id } params, RequestOptionsoptions?): [DomainDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Batch domain operations](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/batch)

client.emailSecurity.settings.domains.batch(DomainBatchParams {account\_id, deletes, patches, 2 more } params, RequestOptionsoptions?): [DomainBatchResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)>) {deletes, patches, posts, puts }

POST/accounts/{account\_id}/email-security/settings/domains/batch

##### [Unprotect multiple email domains](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/domains/methods/bulk_delete)

Deprecated

client.emailSecurity.settings.domains.bulkDelete(DomainBulkDeleteParams {account\_id } params, RequestOptionsoptions?): SinglePage< [DomainBulkDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_bulk_delete_response%20%3E%20(schema)>) {id } >

DELETE/accounts/{account\_id}/email-security/settings/domains

##### ModelsExpand Collapse

<details>

<summary>

DomainListResponse {id, allowed\_delivery\_modes, authorization, 19 more }

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)%20%3E%20(property)%20transport">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_list_response%20%3E%20(schema)>)

<details>

<summary>

DomainGetResponse {id, allowed\_delivery\_modes, authorization, 19 more }

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)%20%3E%20(property)%20transport">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_get_response%20%3E%20(schema)>)

<details>

<summary>

DomainUpdateResponse {id, allowed\_delivery\_modes, authorization, 19 more }

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)%20%3E%20(property)%20transport">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_update_response%20%3E%20(schema)>)

<details>

<summary>

DomainEditResponse {id, allowed\_delivery\_modes, authorization, 19 more }

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20transport">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_edit_response%20%3E%20(schema)>)

<details>

<summary>

DomainCreateResponse {id, allowed\_delivery\_modes, authorization, 19 more }

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)%20%3E%20(property)%20transport">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_create_response%20%3E%20(schema)>)

<details>

<summary>

DomainDeleteResponse {id }

</summary>

id: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_delete_response%20%3E%20(schema)>)

<details>

<summary>

DomainBatchResponse {deletes, patches, posts, puts }

</summary>

<details>

<summary>

deletes: Array&lt;Delete&gt;

</summary>

id: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes">Link to this property</a>

<details>

<summary>

patches: Array&lt;Patch&gt;

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20transport">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches">Link to this property</a>

<details>

<summary>

posts: Array&lt;Post&gt;

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20transport">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts">Link to this property</a>

<details>

<summary>

puts: Array&lt;Put&gt;

</summary>

id?: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_delivery\_modes?: Array&lt;"DIRECT"| "BCC"| "JOURNAL"| 2 more&gt;

</summary>

One of the following:

"DIRECT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"BCC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"JOURNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"API"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"RETRO\_SCAN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20allowed_delivery_modes">Link to this property</a>

<details>

<summary>

authorization?: Authorization| null

</summary>

authorized: boolean

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20authorized">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20timestamp">Link to this property</a>

status\_message?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20authorization%20%3E%20(property)%20status_message">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20authorization">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

dmarc\_status?: "none"| "good"| "invalid"| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%201">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20dmarc_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20dmarc_status">Link to this property</a>

domain?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20domain">Link to this property</a>

<details>

<summary>

drop\_dispositions?: Array&lt;"MALICIOUS"| "MALICIOUS-BEC"| "SUSPICIOUS"| 7 more&gt;

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"MALICIOUS-BEC"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ENCRYPTED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"EXTERNAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"UNKNOWN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20drop_dispositions">Link to this property</a>

<details>

<summary>

emails\_processed?: EmailsProcessed| null

</summary>

timestamp: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20timestamp">Link to this property</a>

total\_emails\_processed: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed">Link to this property</a>

total\_emails\_processed\_previous: number

minimum0

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20emails_processed%20%3E%20(property)%20total_emails_processed_previous">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20emails_processed">Link to this property</a>

<details>

<summary>

folder?: "AllItems"| "Inbox"| null

The mailbox folder to scan, for API-scanning domains.

</summary>

One of the following:

"AllItems"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%200">Link to this property</a>

"Inbox"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20folder%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20folder">Link to this property</a>

<details>

<summary>

inbox\_provider?: "Microsoft"| "Google"| null

</summary>

One of the following:

"Microsoft"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%200">Link to this property</a>

"Google"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20inbox_provider%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20inbox_provider">Link to this property</a>

integration\_id?: string| null

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20integration_id">Link to this property</a>

ip\_restrictions?: Array&lt;string&gt;

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20ip_restrictions">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

lookback\_hops?: number

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20lookback_hops">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

o365\_tenant\_id?: string| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20o365_tenant_id">Link to this property</a>

<details>

<summary>

regions?: Array&lt;"GLOBAL"| "AU"| "DE"| 2 more&gt;

</summary>

One of the following:

"GLOBAL"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"AU"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"DE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"IN"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"US"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20regions">Link to this property</a>

require\_tls\_inbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20require_tls_inbound">Link to this property</a>

require\_tls\_outbound?: boolean| null

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20require_tls_outbound">Link to this property</a>

<details>

<summary>

spf\_status?: "none"| "good"| "neutral"| 2 more| null

</summary>

One of the following:

"none"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%200">Link to this property</a>

"good"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%201">Link to this property</a>

"neutral"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%202">Link to this property</a>

"open"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%203">Link to this property</a>

"invalid"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20spf_status">Link to this property</a>

<details>

<summary>

status?: "PENDING"| "ACTIVE"| "FAILED"| "TIMEOUT"| null

</summary>

One of the following:

"PENDING"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ACTIVE"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"FAILED"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"TIMEOUT"

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

transport?: string

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20transport">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_batch_response%20%3E%20(schema)>)

<details>

<summary>

DomainBulkDeleteResponse {id }

</summary>

id: string

Domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_bulk_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.domains%20%3E%20(model)%20domain_bulk_delete_response%20%3E%20(schema)>)

#### Email SecuritySettingsImpersonation Registry

##### [List impersonation registry entries](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/list)

client.emailSecurity.settings.impersonationRegistry.list(ImpersonationRegistryListParams {account\_id, direction, order, 4 more } params, RequestOptionsoptions?): V4PagePaginationArray< [ImpersonationRegistryListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)>) {id, comments, created\_at, 9 more } >

GET/accounts/{account\_id}/email-security/settings/impersonation\_registry

##### [Get an impersonation registry entry](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/get)

client.emailSecurity.settings.impersonationRegistry.get(stringimpersonationRegistryID, ImpersonationRegistryGetParams {account\_id } params, RequestOptionsoptions?): [ImpersonationRegistryGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)>) {id, comments, created\_at, 9 more }

GET/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

##### [Create impersonation registry entry](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/create)

client.emailSecurity.settings.impersonationRegistry.create(ImpersonationRegistryCreateParams {account\_id, email, is\_email\_regex, 6 more } params, RequestOptionsoptions?): [ImpersonationRegistryCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)>) {id, comments, created\_at, 9 more }

POST/accounts/{account\_id}/email-security/settings/impersonation\_registry

##### [Update an impersonation registry entry](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/edit)

client.emailSecurity.settings.impersonationRegistry.edit(stringimpersonationRegistryID, ImpersonationRegistryEditParams {account\_id, comments, directory\_id, 6 more } params, RequestOptionsoptions?): [ImpersonationRegistryEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)>) {id, comments, created\_at, 9 more }

PATCH/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

##### [Delete an impersonation registry entry](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/delete)

client.emailSecurity.settings.impersonationRegistry.delete(stringimpersonationRegistryID, ImpersonationRegistryDeleteParams {account\_id } params, RequestOptionsoptions?): [ImpersonationRegistryDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

##### ModelsExpand Collapse

<details>

<summary>

ImpersonationRegistryListResponse {id, comments, created\_at, 9 more }

An impersonation registry entry.

</summary>

id?: string

Impersonation registry entry identifier.

formatuuid

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

Optional note describing the entry.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

directory\_id?: number| null

Identifier of the directory the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20directory_id">Link to this property</a>

directory\_node\_id?: number| null

Identifier of the directory node the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20directory_node_id">Link to this property</a>

email?: string

Email address (or pattern) of the protected identity.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

Deprecatedexternal\_directory\_node\_id?: string| null

This field is deprecated.

Deprecated. External identifier of the directory node.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20external_directory_node_id">Link to this property</a>

is\_email\_regex?: boolean

Whether <code>email</code> is a regular expression instead of a literal address.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20is_email_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Display name of the protected identity.

maxLength1024

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

provenance?: "A1S\_INTERNAL"| "SNOOPY-CASB\_OFFICE\_365"| "SNOOPY-OFFICE\_365"| "SNOOPY-GOOGLE\_DIRECTORY"| null

Source the entry was created from.

</summary>

One of the following:

"A1S\_INTERNAL"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%200">Link to this property</a>

"SNOOPY-CASB\_OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%201">Link to this property</a>

"SNOOPY-OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%202">Link to this property</a>

"SNOOPY-GOOGLE\_DIRECTORY"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)%20%3E%20(property)%20provenance">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_list_response%20%3E%20(schema)>)

<details>

<summary>

ImpersonationRegistryGetResponse {id, comments, created\_at, 9 more }

An impersonation registry entry.

</summary>

id?: string

Impersonation registry entry identifier.

formatuuid

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

Optional note describing the entry.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

directory\_id?: number| null

Identifier of the directory the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20directory_id">Link to this property</a>

directory\_node\_id?: number| null

Identifier of the directory node the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20directory_node_id">Link to this property</a>

email?: string

Email address (or pattern) of the protected identity.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

Deprecatedexternal\_directory\_node\_id?: string| null

This field is deprecated.

Deprecated. External identifier of the directory node.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20external_directory_node_id">Link to this property</a>

is\_email\_regex?: boolean

Whether <code>email</code> is a regular expression instead of a literal address.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20is_email_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Display name of the protected identity.

maxLength1024

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

provenance?: "A1S\_INTERNAL"| "SNOOPY-CASB\_OFFICE\_365"| "SNOOPY-OFFICE\_365"| "SNOOPY-GOOGLE\_DIRECTORY"| null

Source the entry was created from.

</summary>

One of the following:

"A1S\_INTERNAL"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%200">Link to this property</a>

"SNOOPY-CASB\_OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%201">Link to this property</a>

"SNOOPY-OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%202">Link to this property</a>

"SNOOPY-GOOGLE\_DIRECTORY"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)%20%3E%20(property)%20provenance">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_get_response%20%3E%20(schema)>)

<details>

<summary>

ImpersonationRegistryCreateResponse {id, comments, created\_at, 9 more }

An impersonation registry entry.

</summary>

id?: string

Impersonation registry entry identifier.

formatuuid

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

Optional note describing the entry.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

directory\_id?: number| null

Identifier of the directory the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20directory_id">Link to this property</a>

directory\_node\_id?: number| null

Identifier of the directory node the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20directory_node_id">Link to this property</a>

email?: string

Email address (or pattern) of the protected identity.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

Deprecatedexternal\_directory\_node\_id?: string| null

This field is deprecated.

Deprecated. External identifier of the directory node.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20external_directory_node_id">Link to this property</a>

is\_email\_regex?: boolean

Whether <code>email</code> is a regular expression instead of a literal address.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20is_email_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Display name of the protected identity.

maxLength1024

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

provenance?: "A1S\_INTERNAL"| "SNOOPY-CASB\_OFFICE\_365"| "SNOOPY-OFFICE\_365"| "SNOOPY-GOOGLE\_DIRECTORY"| null

Source the entry was created from.

</summary>

One of the following:

"A1S\_INTERNAL"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%200">Link to this property</a>

"SNOOPY-CASB\_OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%201">Link to this property</a>

"SNOOPY-OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%202">Link to this property</a>

"SNOOPY-GOOGLE\_DIRECTORY"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)%20%3E%20(property)%20provenance">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_create_response%20%3E%20(schema)>)

<details>

<summary>

ImpersonationRegistryEditResponse {id, comments, created\_at, 9 more }

An impersonation registry entry.

</summary>

id?: string

Impersonation registry entry identifier.

formatuuid

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

Optional note describing the entry.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

directory\_id?: number| null

Identifier of the directory the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20directory_id">Link to this property</a>

directory\_node\_id?: number| null

Identifier of the directory node the entry was synced from, when directory-synced.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20directory_node_id">Link to this property</a>

email?: string

Email address (or pattern) of the protected identity.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

Deprecatedexternal\_directory\_node\_id?: string| null

This field is deprecated.

Deprecated. External identifier of the directory node.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20external_directory_node_id">Link to this property</a>

is\_email\_regex?: boolean

Whether <code>email</code> is a regular expression instead of a literal address.

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_email_regex">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

name?: string

Display name of the protected identity.

maxLength1024

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

provenance?: "A1S\_INTERNAL"| "SNOOPY-CASB\_OFFICE\_365"| "SNOOPY-OFFICE\_365"| "SNOOPY-GOOGLE\_DIRECTORY"| null

Source the entry was created from.

</summary>

One of the following:

"A1S\_INTERNAL"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%200">Link to this property</a>

"SNOOPY-CASB\_OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%201">Link to this property</a>

"SNOOPY-OFFICE\_365"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%202">Link to this property</a>

"SNOOPY-GOOGLE\_DIRECTORY"

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20provenance%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)%20%3E%20(property)%20provenance">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_edit_response%20%3E%20(schema)>)

<details>

<summary>

ImpersonationRegistryDeleteResponse {id }

</summary>

id: string

Impersonation registry entry identifier.

formatuuid

<a href="#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.impersonation_registry%20%3E%20(model)%20impersonation_registry_delete_response%20%3E%20(schema)>)

#### Email SecuritySettingsSending Domain Restrictions

##### [List sending domain restrictions](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/list)

client.emailSecurity.settings.sendingDomainRestrictions.list(SendingDomainRestrictionListParams {account\_id, direction, order, 3 more } params, RequestOptionsoptions?): V4PagePaginationArray< [SendingDomainRestrictionListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)>) {id, comments, created\_at, 4 more } >

GET/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions

##### [Get a sending domain restriction](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/get)

client.emailSecurity.settings.sendingDomainRestrictions.get(stringsendingDomainRestrictionID, SendingDomainRestrictionGetParams {account\_id } params, RequestOptionsoptions?): [SendingDomainRestrictionGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)>) {id, comments, created\_at, 4 more }

GET/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

##### [Create a sending domain restriction](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/create)

client.emailSecurity.settings.sendingDomainRestrictions.create(SendingDomainRestrictionCreateParams {account\_id, domain, exclude, comments } params, RequestOptionsoptions?): [SendingDomainRestrictionCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)>) {id, comments, created\_at, 4 more }

POST/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions

##### [Update a sending domain restriction](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/edit)

client.emailSecurity.settings.sendingDomainRestrictions.edit(stringsendingDomainRestrictionID, SendingDomainRestrictionEditParams {account\_id, comments, domain, exclude } params, RequestOptionsoptions?): [SendingDomainRestrictionEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)>) {id, comments, created\_at, 4 more }

PATCH/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

##### [Delete a sending domain restriction](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/delete)

client.emailSecurity.settings.sendingDomainRestrictions.delete(stringsendingDomainRestrictionID, SendingDomainRestrictionDeleteParams {account\_id } params, RequestOptionsoptions?): [SendingDomainRestrictionDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

##### ModelsExpand Collapse

<details>

<summary>

SendingDomainRestrictionListResponse {id, comments, created\_at, 4 more }

A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.

</summary>

id?: string

Sending domain restriction identifier.

formatuuid

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

Domain that requires TLS enforcement.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

exclude?: Array&lt;string&gt;

Subdomains to exempt from TLS requirements.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_list_response%20%3E%20(schema)>)

<details>

<summary>

SendingDomainRestrictionGetResponse {id, comments, created\_at, 4 more }

A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.

</summary>

id?: string

Sending domain restriction identifier.

formatuuid

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

Domain that requires TLS enforcement.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

exclude?: Array&lt;string&gt;

Subdomains to exempt from TLS requirements.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_get_response%20%3E%20(schema)>)

<details>

<summary>

SendingDomainRestrictionCreateResponse {id, comments, created\_at, 4 more }

A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.

</summary>

id?: string

Sending domain restriction identifier.

formatuuid

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

Domain that requires TLS enforcement.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

exclude?: Array&lt;string&gt;

Subdomains to exempt from TLS requirements.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_create_response%20%3E%20(schema)>)

<details>

<summary>

SendingDomainRestrictionEditResponse {id, comments, created\_at, 4 more }

A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.

</summary>

id?: string

Sending domain restriction identifier.

formatuuid

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

Domain that requires TLS enforcement.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

exclude?: Array&lt;string&gt;

Subdomains to exempt from TLS requirements.

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_edit_response%20%3E%20(schema)>)

<details>

<summary>

SendingDomainRestrictionDeleteResponse {id }

</summary>

id: string

Sending domain restriction identifier.

formatuuid

<a href="#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.sending_domain_restrictions%20%3E%20(model)%20sending_domain_restriction_delete_response%20%3E%20(schema)>)

#### Email SecuritySettingsTrusted Domains

##### [List trusted email domains](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/list)

client.emailSecurity.settings.trustedDomains.list(TrustedDomainListParams {account\_id, direction, is\_recent, 6 more } params, RequestOptionsoptions?): V4PagePaginationArray< [TrustedDomainListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)>) {id, comments, created\_at, 6 more } >

GET/accounts/{account\_id}/email-security/settings/trusted\_domains

##### [Get a trusted email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/get)

client.emailSecurity.settings.trustedDomains.get(stringtrustedDomainID, TrustedDomainGetParams {account\_id } params, RequestOptionsoptions?): [TrustedDomainGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)>) {id, comments, created\_at, 6 more }

GET/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Create trusted email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/create)

client.emailSecurity.settings.trustedDomains.create(TrustedDomainCreateParams {account\_id, is\_recent, is\_regex, 3 more } params, RequestOptionsoptions?): [TrustedDomainCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)>) {id, comments, created\_at, 6 more }

POST/accounts/{account\_id}/email-security/settings/trusted\_domains

##### [Update a trusted email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/edit)

client.emailSecurity.settings.trustedDomains.edit(stringtrustedDomainID, TrustedDomainEditParams {account\_id, comments, is\_recent, 3 more } params, RequestOptionsoptions?): [TrustedDomainEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)>) {id, comments, created\_at, 6 more }

PATCH/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Delete a trusted email domain](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/delete)

client.emailSecurity.settings.trustedDomains.delete(stringtrustedDomainID, TrustedDomainDeleteParams {account\_id } params, RequestOptionsoptions?): [TrustedDomainDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Batch trusted domain operations](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/trusted_domains/methods/batch)

client.emailSecurity.settings.trustedDomains.batch(TrustedDomainBatchParams {account\_id, deletes, patches, 2 more } params, RequestOptionsoptions?): [TrustedDomainBatchResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)>) {deletes, patches, posts, puts }

POST/accounts/{account\_id}/email-security/settings/trusted\_domains/batch

##### ModelsExpand Collapse

<details>

<summary>

TrustedDomainListResponse {id, comments, created\_at, 6 more }

A trusted email domain.

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_list_response%20%3E%20(schema)>)

<details>

<summary>

TrustedDomainGetResponse {id, comments, created\_at, 6 more }

A trusted email domain.

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_get_response%20%3E%20(schema)>)

<details>

<summary>

TrustedDomainCreateResponse {id, comments, created\_at, 6 more }

A trusted email domain.

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_create_response%20%3E%20(schema)>)

<details>

<summary>

TrustedDomainEditResponse {id, comments, created\_at, 6 more }

A trusted email domain.

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_edit_response%20%3E%20(schema)>)

<details>

<summary>

TrustedDomainDeleteResponse {id }

</summary>

id: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_delete_response%20%3E%20(schema)>)

<details>

<summary>

TrustedDomainBatchResponse {deletes, patches, posts, puts }

</summary>

<details>

<summary>

deletes?: Array&lt;Delete&gt;

</summary>

id: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20deletes">Link to this property</a>

<details>

<summary>

patches?: Array&lt;Patch&gt;

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20patches">Link to this property</a>

<details>

<summary>

posts?: Array&lt;Post&gt;

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20posts">Link to this property</a>

<details>

<summary>

puts?: Array&lt;Put&gt;

</summary>

id?: string

Trusted domain identifier.

formatuuid

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

comments?: string| null

maxLength1024

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20comments">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_recent?: boolean

Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_recent">Link to this property</a>

is\_regex?: boolean

Whether <code>pattern</code> is a regular expression instead of a literal domain.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_regex">Link to this property</a>

is\_similarity?: boolean

Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20is_similarity">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

pattern?: string

The domain pattern to trust, e.g. <code>example.com</code>.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts%20%3E%20(items)%20%3E%20(property)%20pattern">Link to this property</a>

</details>

<a href="#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)%20%3E%20(property)%20puts">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.trusted_domains%20%3E%20(model)%20trusted_domain_batch_response%20%3E%20(schema)>)

#### Email SecuritySettingsURL Ignore Patterns

##### [List URL ignore patterns](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/list)

client.emailSecurity.settings.urlIgnorePatterns.list(URLIgnorePatternListParams {account\_id, page, per\_page } params, RequestOptionsoptions?): V4PagePaginationArray< [URLIgnorePatternListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)>) {id, created\_at, pattern, 3 more } >

GET/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns

##### [Get a URL ignore pattern](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/get)

client.emailSecurity.settings.urlIgnorePatterns.get(stringpatternID, URLIgnorePatternGetParams {account\_id } params, RequestOptionsoptions?): [URLIgnorePatternGetResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)>) {id, created\_at, pattern, 3 more }

GET/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

##### [Create a URL ignore pattern](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/create)

client.emailSecurity.settings.urlIgnorePatterns.create(URLIgnorePatternCreateParams {account\_id, pattern, comments } params, RequestOptionsoptions?): [URLIgnorePatternCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)>) {id, created\_at, pattern, 3 more }

POST/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns

##### [Update a URL ignore pattern](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/edit)

client.emailSecurity.settings.urlIgnorePatterns.edit(stringpatternID, URLIgnorePatternEditParams {account\_id, comments, pattern } params, RequestOptionsoptions?): [URLIgnorePatternEditResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)>) {id, created\_at, pattern, 3 more }

PATCH/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

##### [Delete a URL ignore pattern](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/delete)

client.emailSecurity.settings.urlIgnorePatterns.delete(stringpatternID, URLIgnorePatternDeleteParams {account\_id } params, RequestOptionsoptions?): [URLIgnorePatternDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

##### ModelsExpand Collapse

<details>

<summary>

URLIgnorePatternListResponse {id, created\_at, pattern, 3 more }

A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.

</summary>

id: string

URL ignore pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

pattern: string

Regular expression identifying URLs to exempt from rewriting.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

comments?: string| null

Optional note describing the reason for the ignore pattern.

maxLength1024

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_list_response%20%3E%20(schema)>)

<details>

<summary>

URLIgnorePatternGetResponse {id, created\_at, pattern, 3 more }

A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.

</summary>

id: string

URL ignore pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

pattern: string

Regular expression identifying URLs to exempt from rewriting.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

comments?: string| null

Optional note describing the reason for the ignore pattern.

maxLength1024

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_get_response%20%3E%20(schema)>)

<details>

<summary>

URLIgnorePatternCreateResponse {id, created\_at, pattern, 3 more }

A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.

</summary>

id: string

URL ignore pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

pattern: string

Regular expression identifying URLs to exempt from rewriting.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

comments?: string| null

Optional note describing the reason for the ignore pattern.

maxLength1024

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_create_response%20%3E%20(schema)>)

<details>

<summary>

URLIgnorePatternEditResponse {id, created\_at, pattern, 3 more }

A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.

</summary>

id: string

URL ignore pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

pattern: string

Regular expression identifying URLs to exempt from rewriting.

maxLength1024

minLength1

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20pattern">Link to this property</a>

comments?: string| null

Optional note describing the reason for the ignore pattern.

maxLength1024

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20comments">Link to this property</a>

Deprecatedlast\_modified?: string

Use <code>modified_at</code> instead.

Deprecated, use <code>modified_at</code> instead. End of life: November 1, 2026.

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_modified">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_edit_response%20%3E%20(schema)>)

<details>

<summary>

URLIgnorePatternDeleteResponse {id }

</summary>

id: string

URL ignore pattern identifier.

formatuuid

<a href="#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.settings.url_ignore_patterns%20%3E%20(model)%20url_ignore_pattern_delete_response%20%3E%20(schema)>)

#### Email SecuritySubmissions

##### [List reclassify submissions](https://developers.cloudflare.com/api/typescript/resources/email_security/subresources/submissions/methods/list)

client.emailSecurity.submissions.list(SubmissionListParams {account\_id, direction, end, 12 more } params, RequestOptionsoptions?): V4PagePaginationArray< [SubmissionListResponse](<https://developers.cloudflare.com/api/typescript/resources/email_security#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)>) {requested\_at, submission\_id, customer\_status, 15 more } >

GET/accounts/{account\_id}/email-security/submissions

##### ModelsExpand Collapse

<details>

<summary>

SubmissionListResponse {requested\_at, submission\_id, customer\_status, 15 more }

</summary>

requested\_at: string

When the submission was requested (UTC).

formatdate-time

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_at">Link to this property</a>

submission\_id: string

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20submission_id">Link to this property</a>

<details>

<summary>

customer\_status?: "escalated"| "reviewed"| "unreviewed"| null

</summary>

One of the following:

"escalated"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20customer_status%20%3E%20(member)%200">Link to this property</a>

"reviewed"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20customer_status%20%3E%20(member)%201">Link to this property</a>

"unreviewed"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20customer_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20customer_status">Link to this property</a>

<details>

<summary>

escalated\_as?: "MALICIOUS"| "SUSPICIOUS"| "SPOOF"| 3 more| null

The disposition a message is submitted to have.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%200">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%201">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%202">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%203">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%204">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_as">Link to this property</a>

escalated\_at?: string| null

When the submission was escalated to the security team.

formatdate-time

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_at">Link to this property</a>

escalated\_by?: string| null

Email address of the user who escalated the submission.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_by">Link to this property</a>

escalated\_submission\_id?: string| null

Submission ID of the escalated team submission, when this user submission was escalated.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20escalated_submission_id">Link to this property</a>

<details>

<summary>

original\_disposition?: "MALICIOUS"| "SUSPICIOUS"| "SPOOF"| 3 more| null

The disposition a message is submitted to have.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%200">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%201">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%202">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%203">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%204">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_disposition">Link to this property</a>

original\_edf\_hash?: string| null

EDF hash of the original message.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_edf_hash">Link to this property</a>

original\_postfix\_id?: string| null

The postfix ID of the original message that was submitted.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20original_postfix_id">Link to this property</a>

outcome?: string| null

Processing outcome of the submission.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome">Link to this property</a>

<details>

<summary>

outcome\_disposition?: "MALICIOUS"| "SUSPICIOUS"| "SPOOF"| 3 more| null

The disposition a message is submitted to have.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%200">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%201">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%202">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%203">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%204">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20outcome_disposition">Link to this property</a>

requested\_by?: string| null

Email address of the user who requested the submission.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_by">Link to this property</a>

<details>

<summary>

requested\_disposition?: "MALICIOUS"| "SUSPICIOUS"| "SPOOF"| 3 more| null

The disposition a message is submitted to have.

</summary>

One of the following:

"MALICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%200">Link to this property</a>

"SUSPICIOUS"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%201">Link to this property</a>

"SPOOF"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%202">Link to this property</a>

"SPAM"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%203">Link to this property</a>

"BULK"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%204">Link to this property</a>

"NONE"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_disposition">Link to this property</a>

Deprecatedrequested\_ts?: string

Use <code>requested_at</code> instead.

Deprecated, use <code>requested_at</code> instead.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20requested_ts">Link to this property</a>

status?: string| null

Processing status of the submission.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

subject?: string| null

Subject line of the submitted message.

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20subject">Link to this property</a>

<details>

<summary>

type?: "Team"| "User"| null

Indicates whether a team member or an end user created the submission.

</summary>

One of the following:

"Team"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"User"

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20email_security.submissions%20%3E%20(model)%20submission_list_response%20%3E%20(schema)>)