Email Security
Email SecurityInvestigate
Search email messages
Get message details
ModelsExpand Collapse
class InvestigateListResponse: …
Deprecatedaction_log: List[ActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: PropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[Finding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
class InvestigateGetResponse: …
Deprecatedaction_log: List[ActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: PropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[Finding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
Email SecurityInvestigateDetections
Get message detection details
ModelsExpand Collapse
class DetectionGetResponse: …
attachments: List[Attachment]
findings: Optional[List[Finding]]
Email SecurityInvestigatePreview
Get preview for a detection
Generate preview for a non-detection message
Email SecurityInvestigateRaw
Get raw email content
Email SecurityInvestigateTrace
Get email trace
Email SecurityInvestigateMove
Move a message
Move messages
ModelsExpand Collapse
Email SecurityInvestigateReclassify
Change email classification
Email SecurityInvestigateRelease
Release messages from quarantine
ModelsExpand Collapse
Email SecurityInvestigateBulk
List bulk action jobs
Create a bulk action job
Get bulk action job details
Delete a bulk action job
ModelsExpand Collapse
class BulkListResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
class BulkCreateResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
class BulkGetResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
Email SecurityInvestigateBulkCancel
Cancel a bulk action job
ModelsExpand Collapse
class CancelCreateResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
Email SecurityInvestigateBulkMessages
List messages for a bulk action job
ModelsExpand Collapse
class MessageListResponse: …
action_params: ActionParams
status: Literal["PENDING", "PROCESSING", "COMPLETED", 3 more]Status of a message within a bulk action job.
Status of a message within a bulk action job.
message: Optional[Message]
Deprecatedaction_log: List[MessageActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use completed_at instead.
Deprecated, use completed_at instead. End of life: November 1, 2026.
properties: MessagePropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[MessageFinding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
Email SecurityPhishguard
Email SecurityPhishguardReports
List PhishGuard reports
Email SecuritySettings
Email SecuritySettingsAllow Policies
List email allow policies
Get an email allow policy
Create email allow policy
Update an email allow policy
Delete an email allow policy
Batch allow policy operations
ModelsExpand Collapse
class AllowPolicyListResponse: …An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class AllowPolicyGetResponse: …An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class AllowPolicyCreateResponse: …An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class AllowPolicyEditResponse: …An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class AllowPolicyBatchResponse: …
patches: Optional[List[Patch]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
posts: Optional[List[Post]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
puts: Optional[List[Put]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Email SecuritySettingsBlock Senders
List blocked email senders
Get a blocked email sender
Create blocked email sender
Update a blocked email sender
Delete a blocked email sender
Batch blocked sender operations
ModelsExpand Collapse
class BlockSenderListResponse: …A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class BlockSenderGetResponse: …A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class BlockSenderCreateResponse: …A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class BlockSenderEditResponse: …A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
class BlockSenderBatchResponse: …
patches: Optional[List[Patch]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
posts: Optional[List[Post]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
puts: Optional[List[Put]]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: Optional[Literal["EMAIL", "DOMAIN", "IP", "UNKNOWN"]]Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Email SecuritySettingsContent Policies
List content policies
Get a content policy
Create a content policy
Update a content policy
Delete a content policy
Batch content policy operations
ModelsExpand Collapse
Email SecuritySettingsDomains
List protected email domains
Get an email domain
Replace an email domain
Update an email domain
Add a new email domain
Unprotect an email domain
Batch domain operations
Unprotect multiple email domains
ModelsExpand Collapse
class DomainListResponse: …
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
class DomainGetResponse: …
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
class DomainUpdateResponse: …
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
class DomainEditResponse: …
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
class DomainCreateResponse: …
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
class DomainBatchResponse: …
patches: List[Patch]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
posts: List[Post]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
puts: List[Put]
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Email SecuritySettingsImpersonation Registry
List impersonation registry entries
Get an impersonation registry entry
Create impersonation registry entry
Update an impersonation registry entry
Delete an impersonation registry entry
ModelsExpand Collapse
class ImpersonationRegistryListResponse: …An impersonation registry entry.
An impersonation registry entry.
Identifier of the directory the entry was synced from, when directory-synced.
Identifier of the directory node the entry was synced from, when directory-synced.
This field is deprecated.
Deprecated. External identifier of the directory node.
class ImpersonationRegistryGetResponse: …An impersonation registry entry.
An impersonation registry entry.
Identifier of the directory the entry was synced from, when directory-synced.
Identifier of the directory node the entry was synced from, when directory-synced.
This field is deprecated.
Deprecated. External identifier of the directory node.
class ImpersonationRegistryCreateResponse: …An impersonation registry entry.
An impersonation registry entry.
Identifier of the directory the entry was synced from, when directory-synced.
Identifier of the directory node the entry was synced from, when directory-synced.
This field is deprecated.
Deprecated. External identifier of the directory node.
class ImpersonationRegistryEditResponse: …An impersonation registry entry.
An impersonation registry entry.
Identifier of the directory the entry was synced from, when directory-synced.
Identifier of the directory node the entry was synced from, when directory-synced.
This field is deprecated.
Deprecated. External identifier of the directory node.
Email SecuritySettingsSending Domain Restrictions
List sending domain restrictions
Get a sending domain restriction
Create a sending domain restriction
Update a sending domain restriction
Delete a sending domain restriction
ModelsExpand Collapse
class SendingDomainRestrictionListResponse: …A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
class SendingDomainRestrictionGetResponse: …A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
class SendingDomainRestrictionCreateResponse: …A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
class SendingDomainRestrictionEditResponse: …A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
Email SecuritySettingsTrusted Domains
List trusted email domains
Get a trusted email domain
Create trusted email domain
Update a trusted email domain
Delete a trusted email domain
Batch trusted domain operations
ModelsExpand Collapse
class TrustedDomainListResponse: …A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
class TrustedDomainGetResponse: …A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
class TrustedDomainCreateResponse: …A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
class TrustedDomainEditResponse: …A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
class TrustedDomainBatchResponse: …
patches: Optional[List[Patch]]
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
posts: Optional[List[Post]]
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
puts: Optional[List[Put]]
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
Email SecuritySettingsURL Ignore Patterns
List URL ignore patterns
Get a URL ignore pattern
Create a URL ignore pattern
Update a URL ignore pattern
Delete a URL ignore pattern
ModelsExpand Collapse
Email SecuritySubmissions
List reclassify submissions
ModelsExpand Collapse
class SubmissionListResponse: …
escalated_as: Optional[Literal["MALICIOUS", "SUSPICIOUS", "SPOOF", 3 more]]The disposition a message is submitted to have.
The disposition a message is submitted to have.
When the submission was escalated to the security team.
Submission ID of the escalated team submission, when this user submission was escalated.
original_disposition: Optional[Literal["MALICIOUS", "SUSPICIOUS", "SPOOF", 3 more]]The disposition a message is submitted to have.
The disposition a message is submitted to have.
outcome_disposition: Optional[Literal["MALICIOUS", "SUSPICIOUS", "SPOOF", 3 more]]The disposition a message is submitted to have.
The disposition a message is submitted to have.

