PUT /accounts/{account_id}/email-security/settings/allow_policies/{policy_id}

Replaces an existing allow policy in full. Unlike PATCH, every field is taken from the request body, so optional fields that are omitted are reset rather than left untouched. Use this when managing policies declaratively.

Servers

Path parameters

Name Type Required Description
policy_id String Yes
account_id String Yes

Account identifier tag.

Request headers

Name Type Required Description
Content-Type String Yes The media type of the request body.

Default value: "application/json"

Request body fields

Name Type Required Description
is_recipient Boolean No

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_exempt_recipient Boolean Yes

Bypasses all detections for messages to this recipient.

is_spoof Boolean No

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

verify_sender Boolean Yes

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

last_modified String Yes

Deprecated, use modified_at instead. End of life: November 1, 2026.

modified_at String No
id String Yes

Allow policy identifier.

pattern_type String Yes

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.

Valid values:

  • "EMAIL"
  • "DOMAIN"
  • "UNKNOWN"
  • "IP"
is_sender Boolean No

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

is_trusted_sender Boolean Yes

Bypasses all detections and link following for messages from this sender.

is_acceptable_sender Boolean Yes

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

created_at String Yes
is_regex Boolean Yes
pattern String Yes

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.

comments String No

How to start integrating

  1. Add HTTP Task to your workflow definition.
  2. Search for the API you want to integrate with and click on the name.
    • This loads the API reference documentation and prepares the Http request settings.
  3. Click Test request to test run your request to the API and see the API's response.