Skip to content
Start here

Batch allow policies operations

POST/accounts/{account_id}/email-security/settings/allow_policies/batch

Executes multiple operations atomically. All four operation arrays (deletes, patches, puts, posts) are required and executed in order. Send empty arrays for unused operations.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Cloud Email Security: Write
Path ParametersExpand Collapse
account_id: string

Identifier.

maxLength32
Body ParametersJSONExpand Collapse
deletes: array of object { id }
id: string

Allow policy identifier.

formatuuid
patches: array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

posts: array of object { is_acceptable_sender, is_exempt_recipient, is_regex, 12 more }
is_acceptable_sender: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: boolean

Bypasses all detections for messages to this recipient.

is_regex: boolean
is_trusted_sender: boolean

Bypasses all detections and link following for messages from this sender.

pattern: string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

id: optional string

Allow policy identifier.

formatuuid
comments: optional string
maxLength1024
created_at: optional string
formatdate-time
Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

Deprecatedlast_modified: optional string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
modified_at: optional string
formatdate-time
puts: array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

ReturnsExpand Collapse
errors: array of object { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url: optional string
source: optional object { pointer }
pointer: optional string
messages: array of object { code, message, documentation_url, source }
code: number
minimum1000
message: string
documentation_url: optional string
source: optional object { pointer }
pointer: optional string
success: true

Whether the API call was successful.

result: optional object { deletes, patches, posts, puts }
deletes: optional array of object { id }
id: string

Allow policy identifier.

formatuuid
patches: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

posts: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

puts: optional array of object { id, created_at, last_modified, 12 more }
id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments: optional string
maxLength1024
is_acceptable_sender: optional boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient: optional boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient: optional boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex: optional boolean
Deprecatedis_sender: optional boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof: optional boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender: optional boolean

Bypasses all detections and link following for messages from this sender.

modified_at: optional string
formatdate-time
pattern: optional string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

maxLength1024
minLength1
pattern_type: optional "EMAIL" or "DOMAIN" or "IP" or "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender: optional boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

Batch allow policies operations

curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/email-security/settings/allow_policies/batch \
    -H 'Content-Type: application/json' \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
    -d '{
          "deletes": [
            {
              "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
            }
          ],
          "patches": [
            {}
          ],
          "posts": [
            {
              "is_acceptable_sender": false,
              "is_exempt_recipient": false,
              "is_regex": false,
              "is_trusted_sender": true,
              "pattern": "test@example.com",
              "pattern_type": "EMAIL",
              "verify_sender": true
            }
          ],
          "puts": [
            {}
          ]
        }'
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "deletes": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
      }
    ],
    "patches": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ],
    "posts": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ],
    "puts": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ]
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "deletes": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
      }
    ],
    "patches": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ],
    "posts": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ],
    "puts": [
      {
        "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        "created_at": "2014-01-01T05:20:00.12345Z",
        "last_modified": "2014-01-01T05:20:00.12345Z",
        "comments": "Trust all messages send from test@example.com",
        "is_acceptable_sender": false,
        "is_exempt_recipient": false,
        "is_recipient": false,
        "is_regex": false,
        "is_sender": true,
        "is_spoof": false,
        "is_trusted_sender": true,
        "modified_at": "2014-01-01T05:20:00.12345Z",
        "pattern": "test@example.com",
        "pattern_type": "EMAIL",
        "verify_sender": true
      }
    ]
  }
}