Skip to content
Start here

Update an email allow policy

client.emailSecurity.settings.allowPolicies.edit(stringpolicyID, AllowPolicyEditParams { account_id, comments, is_acceptable_sender, 9 more } params, RequestOptionsoptions?): AllowPolicyEditResponse { id, created_at, last_modified, 12 more }
PATCH/accounts/{account_id}/email-security/settings/allow_policies/{policy_id}

Updates an existing allow policy. Only provided fields will be modified. Changes take effect for new emails matching the pattern.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Cloud Email Security: Write
ParametersExpand Collapse
policyID: string

Allow policy identifier.

formatuuid
params: AllowPolicyEditParams { account_id, comments, is_acceptable_sender, 9 more }
account_id: string

Path param: Identifier.

maxLength32
comments?: string | null

Body param

maxLength1024
is_acceptable_sender?: boolean

Body param: Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient?: boolean

Body param: Bypasses all detections for messages to this recipient.

Deprecatedis_recipient?: boolean

Use is_exempt_recipient instead.

Body param: Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex?: boolean

Body param

Deprecatedis_sender?: boolean

Use is_trusted_sender instead.

Body param: Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof?: boolean

Use is_acceptable_sender instead.

Body param: Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender?: boolean

Body param: Bypasses all detections and link following for messages from this sender.

pattern?: string

Body param: The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.

maxLength1024
minLength1
pattern_type?: "EMAIL" | "DOMAIN" | "IP" | "UNKNOWN"

Body param: Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 address (e.g. 1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender?: boolean

Body param: Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

ReturnsExpand Collapse
AllowPolicyEditResponse { id, created_at, last_modified, 12 more }

An email allow policy.

id: string

Allow policy identifier.

formatuuid
created_at: string
formatdate-time
Deprecatedlast_modified: string

Use modified_at instead.

Deprecated, use modified_at instead. End of life: November 1, 2026.

formatdate-time
comments?: string | null
maxLength1024
is_acceptable_sender?: boolean

Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.

is_exempt_recipient?: boolean

Bypasses all detections for messages to this recipient.

Deprecatedis_recipient?: boolean

Use is_exempt_recipient instead.

Deprecated as of July 1, 2025. Use is_exempt_recipient instead. End of life: July 1, 2026.

is_regex?: boolean
Deprecatedis_sender?: boolean

Use is_trusted_sender instead.

Deprecated as of July 1, 2025. Use is_trusted_sender instead. End of life: July 1, 2026.

Deprecatedis_spoof?: boolean

Use is_acceptable_sender instead.

Deprecated as of July 1, 2025. Use is_acceptable_sender instead. End of life: July 1, 2026.

is_trusted_sender?: boolean

Bypasses all detections and link following for messages from this sender.

modified_at?: string
formatdate-time
pattern?: string

The pattern value to match. The format depends on pattern_type: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 address or IPv4 CIDR block for IP (e.g. 1.2.3.4 or 1.2.3.0/24); the API accepts only globally reachable IP addresses and rejects private, loopback, link-local, and unspecified addresses.

maxLength1024
minLength1
pattern_type?: "EMAIL" | "DOMAIN" | "IP" | "UNKNOWN"

Type of pattern matching.

  • EMAIL: matches a full email address (e.g. user@example.com)
  • DOMAIN: matches a domain name (e.g. example.com)
  • IP: matches a plain IPv4 address (e.g. 1.2.3.4) or an IPv4 CIDR block (e.g. 1.2.3.0/24). The API accepts only globally reachable addresses.
  • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.
One of the following:
"EMAIL"
"DOMAIN"
"IP"
"UNKNOWN"
verify_sender?: boolean

Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

Update an email allow policy

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const response = await client.emailSecurity.settings.allowPolicies.edit(
  'f174e90a-fafe-4643-bbbc-4a0ed4fc8415',
  { account_id: '023e105f4ecef8ad9ca31a8372d0c353' },
);

console.log(response.id);
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
    "created_at": "2014-01-01T05:20:00.12345Z",
    "last_modified": "2014-01-01T05:20:00.12345Z",
    "comments": "Trust all messages send from test@example.com",
    "is_acceptable_sender": false,
    "is_exempt_recipient": false,
    "is_recipient": false,
    "is_regex": false,
    "is_sender": true,
    "is_spoof": false,
    "is_trusted_sender": true,
    "modified_at": "2014-01-01T05:20:00.12345Z",
    "pattern": "test@example.com",
    "pattern_type": "EMAIL",
    "verify_sender": true
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
    "created_at": "2014-01-01T05:20:00.12345Z",
    "last_modified": "2014-01-01T05:20:00.12345Z",
    "comments": "Trust all messages send from test@example.com",
    "is_acceptable_sender": false,
    "is_exempt_recipient": false,
    "is_recipient": false,
    "is_regex": false,
    "is_sender": true,
    "is_spoof": false,
    "is_trusted_sender": true,
    "modified_at": "2014-01-01T05:20:00.12345Z",
    "pattern": "test@example.com",
    "pattern_type": "EMAIL",
    "verify_sender": true
  }
}