Email Security
email_security
Investigate
email_security.investigate
Methods
Get message details
Returns information for each email that matches the search parameter(s).
The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.
Example: X-Auth-Email: user@example.com
The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.
Example: X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Cloud Email Security: Write Cloud Email Security: Read
Account Identifier
Determines if the message action log is included in the response.
Determines if the search results will include detections or not.
The sender domains the search filters by.
The end of the search date range.
Defaults to now.
The dispositions the search filters by.
The message actions the search filters by.
The page number of paginated results.
The number of results per page.
The space-delimited term used in the query. The search is case-insensitive.
The content of the following email metadata fields are searched:
- alert_id
- CC
- From (envelope_from)
- From Name
- final_disposition
- md5 hash (of any attachment)
- sha1 hash (of any attachment)
- sha256 hash (of any attachment)
- name (of any attachment)
- Reason
- Received DateTime (yyyy-mm-ddThh:mm:ss)
- Sent DateTime (yyyy-mm-ddThh:mm:ss)
- ReplyTo
- To (envelope_to)
- To Name
- Message-ID
- smtp_helo_server_ip
- smtp_previous_hop_ip
- x_originating_ip
- Subject
The beginning of the search date range.
Defaults to now - 30 days.
email_security.investigate.detections
Methods
Returns detection details such as threat categories and sender information for non-benign messages.
email_security.investigate.move
Methods
Move multiple messages
Move a message
email_security.investigate.preview
Methods
Preview for non-detection messages
Returns a preview of the message body as a base64 encoded PNG image for non-benign messages.
email_security.investigate.raw
Methods
Returns the raw eml of any non-benign message.
email_security.investigate.reclassify
Methods
Change email classfication
email_security.investigate.release
Methods
Release messages from quarantine
email_security.investigate.trace
Methods
Get email trace
Settings
email_security.settings
email_security.settings.allow_policies
Methods
Create an email allow policy
Delete an email allow policy
Update an email allow policy
Get an email allow policy
Lists, searches, and sorts an account’s email allow policies.
email_security.settings.block_senders
Methods
Create a blocked email sender
Delete a blocked email sender
Update a blocked email sender
Get a blocked email sender
List blocked email senders
email_security.settings.domains
Methods
Unprotect multiple email domains
Unprotect an email domain
Update an email domain
Get an email domain
Lists, searches, and sorts an account’s email domains.
email_security.settings.impersonation_registry
Methods
Create an entry in impersonation registry
Delete an entry from impersonation registry
Update an entry in impersonation registry
Get an entry in impersonation registry
Lists, searches, and sorts entries in the impersonation registry.
email_security.settings.trusted_domains
Methods
Create a trusted email domain
Delete a trusted email domain
Update a trusted email domain
Get a trusted email domain
Lists, searches, and sorts an account’s trusted email domains.
Submissions
email_security.submissions
Methods
This endpoint returns information for submissions to made to reclassify emails.