Get message detection details
GET/accounts/{account_id}/email-security/investigate/{investigate_id}/detections
Returns detection details such as threat categories and sender information for non-benign messages.
Security
API Token
The preferred authorization scheme for interacting with the Cloudflare API. Create a token.
Example:
API Email + API Key
The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.
Example:
The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.
Example:
Accepted Permissions (at least one required)
Path Parameters
Get message detection details
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/email-security/investigate/$INVESTIGATE_ID/detections \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"{
"errors": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"messages": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"result": {
"action": "action",
"attachments": [
{
"size": 0,
"content_type": "content_type",
"detection": "MALICIOUS",
"encrypted": true,
"filename": "filename",
"md5": "md5",
"name": "name",
"sha1": "sha1",
"sha256": "sha256"
}
],
"findings": [
{
"attachment": "attachment",
"detail": "detail",
"detection": "MALICIOUS",
"field": "field",
"name": "name",
"portion": "portion",
"reason": "reason",
"score": 0,
"value": "value"
}
],
"headers": [
{
"name": "name",
"value": "value"
}
],
"links": [
{
"href": "href",
"text": "text"
}
],
"sender_info": {
"as_name": "as_name",
"as_number": 0,
"geo": "geo",
"ip": "ip",
"pld": "pld"
},
"threat_categories": [
{
"id": 0,
"description": "description",
"name": "name"
}
],
"validation": {
"comment": "comment",
"dkim": "pass",
"dmarc": "pass",
"spf": "pass"
},
"final_disposition": "MALICIOUS"
},
"success": true
}Returns Examples
{
"errors": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"messages": [
{
"code": 1000,
"message": "message",
"documentation_url": "documentation_url",
"source": {
"pointer": "pointer"
}
}
],
"result": {
"action": "action",
"attachments": [
{
"size": 0,
"content_type": "content_type",
"detection": "MALICIOUS",
"encrypted": true,
"filename": "filename",
"md5": "md5",
"name": "name",
"sha1": "sha1",
"sha256": "sha256"
}
],
"findings": [
{
"attachment": "attachment",
"detail": "detail",
"detection": "MALICIOUS",
"field": "field",
"name": "name",
"portion": "portion",
"reason": "reason",
"score": 0,
"value": "value"
}
],
"headers": [
{
"name": "name",
"value": "value"
}
],
"links": [
{
"href": "href",
"text": "text"
}
],
"sender_info": {
"as_name": "as_name",
"as_number": 0,
"geo": "geo",
"ip": "ip",
"pld": "pld"
},
"threat_categories": [
{
"id": 0,
"description": "description",
"name": "name"
}
],
"validation": {
"comment": "comment",
"dkim": "pass",
"dmarc": "pass",
"spf": "pass"
},
"final_disposition": "MALICIOUS"
},
"success": true
}