POST /accounts/{account_id}/email-security/settings/allow_policies
Creates a new allow policy that exempts matching emails from security detections. Use with caution as this bypasses email security scanning. Policies can match on sender patterns and apply to specific detections or all detections.
Servers
- https://api.cloudflare.com/client/v4
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
account_id |
String | Yes |
Account identifier tag. |
Request headers
| Name | Type | Required | Description |
|---|---|---|---|
Content-Type |
String | Yes |
The media type of the request body.
Default value: "application/json" |
Request body fields
| Name | Type | Required | Description |
|---|---|---|---|
is_recipient |
Boolean | No |
Deprecated as of July 1, 2025. Use |
is_exempt_recipient |
Boolean | Yes |
Messages to this recipient will bypass all detections |
is_spoof |
Boolean | No |
Deprecated as of July 1, 2025. Use |
verify_sender |
Boolean | Yes |
Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication. |
last_modified |
String | Yes |
Deprecated, use |
modified_at |
String | No | |
id |
String | Yes |
Allow policy identifier |
pattern_type |
String | Yes |
Type of pattern matching. Note: UNKNOWN is deprecated and cannot be used when creating or updating policies, but may be returned for existing entries. Valid values:
|
is_sender |
Boolean | No |
Deprecated as of July 1, 2025. Use |
is_trusted_sender |
Boolean | Yes |
Messages from this sender will bypass all detections and link following |
is_acceptable_sender |
Boolean | Yes |
Messages from this sender will be exempted from Spam, Spoof and Bulk dispositions. Note - This will not exempt messages with Malicious or Suspicious dispositions. |
created_at |
String | Yes | |
is_regex |
Boolean | Yes | |
pattern |
String | Yes | |
comments |
String | No |
How to start integrating
- Add HTTP Task to your workflow definition.
- Search for the API you want to integrate with and click on the name.
- This loads the API reference documentation and prepares the Http request settings.
- Click Test request to test run your request to the API and see the API's response.