Investigate
Search email messages
Get message details
ModelsExpand Collapse
class InvestigateListResponse: …
Deprecatedaction_log: List[ActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: PropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[Finding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
class InvestigateGetResponse: …
Deprecatedaction_log: List[ActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
properties: PropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[Finding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.
InvestigateDetections
Get message detection details
ModelsExpand Collapse
class DetectionGetResponse: …
attachments: List[Attachment]
findings: Optional[List[Finding]]
InvestigatePreview
Get preview for a detection
Generate preview for a non-detection message
InvestigateRaw
Get raw email content
InvestigateTrace
Get email trace
InvestigateMove
Move a message
Move messages
ModelsExpand Collapse
InvestigateReclassify
Change email classification
InvestigateRelease
Release messages from quarantine
ModelsExpand Collapse
InvestigateBulk
List bulk action jobs
Create a bulk action job
Get bulk action job details
Delete a bulk action job
ModelsExpand Collapse
class BulkListResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
class BulkCreateResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
class BulkGetResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
InvestigateBulkCancel
Cancel a bulk action job
ModelsExpand Collapse
class CancelCreateResponse: …
action_params: ActionParams
Messages that were cancelled: rows cancelled via the API before being claimed, and rows whose in-flight attempt ended when the job reached a terminal state. Together the counters satisfy total_messages_discovered = messages_pending + messages_successful + messages_failed + messages_skipped + messages_cancelled.
Messages that discovery skipped (for example, phish submissions, which the job cannot action).
search_params: SearchParams
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
delivery_status: Optional[Literal["delivered", "moved", "quarantined", 5 more]]Delivery status to filter by.
Delivery status to filter by.
Match messages that mention this domain — sender domain, recipient domain, or a domain in a link.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]Dispositions to filter by.
Dispositions to filter by.
InvestigateBulkMessages
List messages for a bulk action job
ModelsExpand Collapse
class MessageListResponse: …
action_params: ActionParams
status: Literal["PENDING", "PROCESSING", "COMPLETED", 3 more]Status of a message within a bulk action job.
Status of a message within a bulk action job.
message: Optional[Message]
Deprecatedaction_log: List[MessageActionLog]Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use GET /investigate/{investigate_id}/action_log instead.
Deprecated, use GET /investigate/{investigate_id}/action_log instead. End of life: November 1, 2026.
Use completed_at instead.
Deprecated, use completed_at instead. End of life: November 1, 2026.
properties: MessagePropertiesMessage processing properties.
Message processing properties.
Use scanned_at instead.
Deprecated, use scanned_at instead. End of life: November 1, 2026.
final_disposition: Optional[Literal["MALICIOUS", "MALICIOUS-BEC", "SUSPICIOUS", 7 more]]The verdict Email Security assigns to a message.
The verdict Email Security assigns to a message.
Deprecatedfindings: Optional[List[MessageFinding]]Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
Use the findings field from GET /investigate/{investigate_id}/detections instead.
Deprecated, use the findings field from GET /investigate/{investigate_id}/detections instead. End of life: November 1, 2026. Detection findings for this message.
post_delivery_operations: Optional[List[Literal["PREVIEW", "QUARANTINE_RELEASE", "SUBMISSION", "MOVE"]]]Post-delivery operations performed on this message.
Post-delivery operations performed on this message.

