Skip to content
Start here

Allow Policies

List email allow policies
GET/accounts/{account_id}/email-security/settings/allow_policies
Get an email allow policy
GET/accounts/{account_id}/email-security/settings/allow_policies/{policy_id}
Create email allow policy
POST/accounts/{account_id}/email-security/settings/allow_policies
Update an email allow policy
PATCH/accounts/{account_id}/email-security/settings/allow_policies/{policy_id}
Delete an email allow policy
DELETE/accounts/{account_id}/email-security/settings/allow_policies/{policy_id}
Batch allow policies operations
POST/accounts/{account_id}/email-security/settings/allow_policies/batch
ModelsExpand Collapse
AllowPolicyListResponse object { id, created_at, last_modified, 12 more }

An email allow policy.

id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

AllowPolicyGetResponse object { id, created_at, last_modified, 12 more }

An email allow policy.

id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

AllowPolicyCreateResponse object { id, created_at, last_modified, 12 more }

An email allow policy.

id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

AllowPolicyEditResponse object { id, created_at, last_modified, 12 more }

An email allow policy.

id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

AllowPolicyDeleteResponse object { id }
id: string

Allow policy identifier.

formatuuid
AllowPolicyBatchResponse object { deletes, patches, posts, puts }
deletes: optional array of object { id }
id: string

Allow policy identifier.

formatuuid
patches: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

posts: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

puts: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.