Allow Policies
List email allow policies
Get an email allow policy
Create email allow policy
Update an email allow policy
Delete an email allow policy
Batch allow policies operations
ModelsExpand Collapse
AllowPolicyListResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyGetResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyCreateResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyEditResponse object { id, created_at, last_modified, 12 more } An email allow policy.
An email allow policy.
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
AllowPolicyBatchResponse object { deletes, patches, posts, puts }
patches: optional array of object { id, created_at, last_modified, 12 more }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
posts: optional array of object { id, created_at, last_modified, 12 more }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
puts: optional array of object { id, created_at, last_modified, 12 more }
Use modified_at instead.
Deprecated, use modified_at instead. End of life: November 1, 2026.
Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
Use is_exempt_recipient instead.
Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.
Use is_trusted_sender instead.
Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.
Use is_acceptable_sender instead.
Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.
Bypasses all detections and link following for messages from this sender.
The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com)
- DOMAIN: matches a domain name (e.g.
example.com)
- IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.