Settings
SettingsAllow Policies
List email allow policies
Get an email allow policy
Create email allow policy
Update an email allow policy
Delete an email allow policy
ModelsExpand Collapse
AllowPolicyListResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyGetResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyCreateResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyEditResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
SettingsBlock Senders
List blocked email senders
Get a blocked email sender
Create blocked email sender
Update a blocked email sender
Delete a blocked email sender
ModelsExpand Collapse
BlockSenderListResponse object { id, comments, created_at, 5 more } A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
BlockSenderGetResponse object { id, comments, created_at, 5 more } A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
BlockSenderCreateResponse object { id, comments, created_at, 5 more } A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
BlockSenderEditResponse object { id, comments, created_at, 5 more } A blocked sender pattern.
A blocked sender pattern.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 address (e.g.
1.2.3.4) or an IPv4 CIDR block (e.g.1.2.3.0/24). The API accepts only globally reachable addresses. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
SettingsDomains
List protected email domains
Get an email domain
Update an email domain
Unprotect an email domain
Unprotect multiple email domains
ModelsExpand Collapse
DomainListResponse object { id, allowed_delivery_modes, authorization, 19 more }
emails_processed: optional object { timestamp, total_emails_processed, total_emails_processed_previous }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
DomainGetResponse object { id, allowed_delivery_modes, authorization, 19 more }
emails_processed: optional object { timestamp, total_emails_processed, total_emails_processed_previous }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
DomainEditResponse object { id, allowed_delivery_modes, authorization, 19 more }
emails_processed: optional object { timestamp, total_emails_processed, total_emails_processed_previous }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
SettingsImpersonation Registry
List entries in impersonation registry
Get an impersonation registry entry
Create impersonation registry entry
Update an impersonation registry entry
Delete an impersonation registry entry
ModelsExpand Collapse
SettingsSending Domain Restrictions
List sending domain restrictions
Get a sending domain restriction
Create a sending domain restriction
Update a sending domain restriction
Delete a sending domain restriction
ModelsExpand Collapse
SendingDomainRestrictionListResponse object { id, comments, created_at, 4 more } A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
SendingDomainRestrictionGetResponse object { id, comments, created_at, 4 more } A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
SendingDomainRestrictionCreateResponse object { id, comments, created_at, 4 more } A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
SendingDomainRestrictionEditResponse object { id, comments, created_at, 4 more } A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
A sending domain restriction that enforces TLS (Transport Layer Security) requirements for emails from specific domains. If TLS is required, the system drops mail without TLS from the specified domain.
SettingsTrusted Domains
List trusted email domains
Get a trusted email domain
Create trusted email domain
Update a trusted email domain
Delete a trusted email domain
ModelsExpand Collapse
TrustedDomainListResponse object { id, comments, created_at, 6 more } A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
TrustedDomainGetResponse object { id, comments, created_at, 6 more } A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
TrustedDomainCreateResponse object { id, comments, created_at, 6 more } A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
TrustedDomainEditResponse object { id, comments, created_at, 6 more } A trusted email domain.
A trusted email domain.
Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition.
Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition.
SettingsURL Ignore Patterns
List URL ignore patterns
Get a URL ignore pattern
Create a URL ignore pattern
Update a URL ignore pattern
Delete a URL ignore pattern
ModelsExpand Collapse
URLIgnorePatternListResponse object { id, created_at, pattern, 3 more } A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
URLIgnorePatternGetResponse object { id, created_at, pattern, 3 more } A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
URLIgnorePatternCreateResponse object { id, created_at, pattern, 3 more } A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
URLIgnorePatternEditResponse object { id, created_at, pattern, 3 more } A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.
A URL ignore pattern that exempts matching URLs from Email Security’s URL rewriting.