Investigate
Search email messages
Get message details
ModelsExpand Collapse
InvestigateListResponse { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: Array<ActionLog>Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: Properties { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings?: Array<Finding> | nullUse the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations?: Array<"PREVIEW" | "QUARANTINE_RELEASE" | "SUBMISSION" | "MOVE"> | nullPost-delivery operations performed on this message.
Post-delivery operations performed on this message.
InvestigateGetResponse { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: Array<ActionLog>Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: Properties { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings?: Array<Finding> | nullUse the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations?: Array<"PREVIEW" | "QUARANTINE_RELEASE" | "SUBMISSION" | "MOVE"> | nullPost-delivery operations performed on this message.
Post-delivery operations performed on this message.
InvestigateDetections
Get message detection details
ModelsExpand Collapse
DetectionGetResponse { action, attachments, findings, 6 more }
attachments: Array<Attachment>
findings: Array<Finding> | null
InvestigatePreview
Get preview for a detection
Generate preview for a non-detection message
InvestigateRaw
Get raw email content
InvestigateTrace
Get email trace
InvestigateMove
Move a message
Move messages
ModelsExpand Collapse
MoveCreateResponse { success, completed_at, completed_timestamp, 6 more }
MoveBulkResponse { success, completed_at, completed_timestamp, 6 more }
InvestigateReclassify
Change email classification
InvestigateRelease
Release messages from quarantine
InvestigateBulk
List bulk action jobs
Create a bulk action job
Get bulk action job details
Delete a bulk action job
ModelsExpand Collapse
BulkListResponse { action_params, action_type, created_at, 13 more }
action_params: Move { destination, type, expected_disposition } | Release { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status?: "delivered" | "moved" | "quarantined" | 5 more | nullDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullDispositions to filter by.
Dispositions to filter by.
BulkCreateResponse { action_params, action_type, created_at, 13 more }
action_params: Move { destination, type, expected_disposition } | Release { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status?: "delivered" | "moved" | "quarantined" | 5 more | nullDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullDispositions to filter by.
Dispositions to filter by.
BulkGetResponse { action_params, action_type, created_at, 13 more }
action_params: Move { destination, type, expected_disposition } | Release { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status?: "delivered" | "moved" | "quarantined" | 5 more | nullDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullDispositions to filter by.
Dispositions to filter by.
InvestigateBulkCancel
Cancel a bulk action job
ModelsExpand Collapse
CancelCreateResponse { action_params, action_type, created_at, 13 more }
action_params: Move { destination, type, expected_disposition } | Release { type }
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams { action_log, alert_id, delivery_status, 15 more }
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status?: "delivered" | "moved" | "quarantined" | 5 more | nullDelivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullDispositions to filter by.
Dispositions to filter by.
InvestigateBulkMessages
List messages for a bulk action job
ModelsExpand Collapse
MessageListResponse { action_params, action_type, created_at, 10 more }
action_params: Move { client_recipient, destination, type, expected_disposition } | Release { client_recipient, type }
status: "PENDING" | "PROCESSING" | "COMPLETED" | 3 moreStatus of a message within a bulk action job.
Status of a message within a bulk action job.
message?: Message { id, action_log, client_recipients, 32 more }
Deprecatedaction_log: Array<ActionLog>Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: Properties { allowlisted_pattern, allowlisted_pattern_type, blocklisted_message, 2 more } Message processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition?: "MALICIOUS" | "MALICIOUS-BEC" | "SUSPICIOUS" | 7 more | nullThe verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings?: Array<Finding> | nullUse the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations?: Array<"PREVIEW" | "QUARANTINE_RELEASE" | "SUBMISSION" | "MOVE"> | nullPost-delivery operations performed on this message.
Post-delivery operations performed on this message.