published on Thursday, Sep 17, 2026 by Pulumi
published on Thursday, Sep 17, 2026 by Pulumi
Accepted Permissions
Cloud Email Security: ReadCloud Email Security: Write
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as cloudflare from "@pulumi/cloudflare";
const exampleEmailSecurityAllowPolicy = new cloudflare.EmailSecurityAllowPolicy("example_email_security_allow_policy", {
accountId: "023e105f4ecef8ad9ca31a8372d0c353",
isAcceptableSender: false,
isExemptRecipient: false,
isRegex: false,
isTrustedSender: true,
pattern: "test@example.com",
patternType: "EMAIL",
verifySender: true,
comments: "Trust all messages send from test@example.com",
isRecipient: false,
isSender: true,
isSpoof: false,
});
import pulumi
import pulumi_cloudflare as cloudflare
example_email_security_allow_policy = cloudflare.EmailSecurityAllowPolicy("example_email_security_allow_policy",
account_id="023e105f4ecef8ad9ca31a8372d0c353",
is_acceptable_sender=False,
is_exempt_recipient=False,
is_regex=False,
is_trusted_sender=True,
pattern="test@example.com",
pattern_type="EMAIL",
verify_sender=True,
comments="Trust all messages send from test@example.com",
is_recipient=False,
is_sender=True,
is_spoof=False)
package main
import (
"github.com/pulumi/pulumi-cloudflare/sdk/v6/go/cloudflare"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := cloudflare.NewEmailSecurityAllowPolicy(ctx, "example_email_security_allow_policy", &cloudflare.EmailSecurityAllowPolicyArgs{
AccountId: pulumi.String("023e105f4ecef8ad9ca31a8372d0c353"),
IsAcceptableSender: pulumi.Bool(false),
IsExemptRecipient: pulumi.Bool(false),
IsRegex: pulumi.Bool(false),
IsTrustedSender: pulumi.Bool(true),
Pattern: pulumi.String("test@example.com"),
PatternType: pulumi.String("EMAIL"),
VerifySender: pulumi.Bool(true),
Comments: pulumi.String("Trust all messages send from test@example.com"),
IsRecipient: pulumi.Bool(false),
IsSender: pulumi.Bool(true),
IsSpoof: pulumi.Bool(false),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Cloudflare = Pulumi.Cloudflare;
return await Deployment.RunAsync(() =>
{
var exampleEmailSecurityAllowPolicy = new Cloudflare.EmailSecurityAllowPolicy("example_email_security_allow_policy", new()
{
AccountId = "023e105f4ecef8ad9ca31a8372d0c353",
IsAcceptableSender = false,
IsExemptRecipient = false,
IsRegex = false,
IsTrustedSender = true,
Pattern = "test@example.com",
PatternType = "EMAIL",
VerifySender = true,
Comments = "Trust all messages send from test@example.com",
IsRecipient = false,
IsSender = true,
IsSpoof = false,
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.cloudflare.EmailSecurityAllowPolicy;
import com.pulumi.cloudflare.EmailSecurityAllowPolicyArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var exampleEmailSecurityAllowPolicy = new EmailSecurityAllowPolicy("exampleEmailSecurityAllowPolicy", EmailSecurityAllowPolicyArgs.builder()
.accountId("023e105f4ecef8ad9ca31a8372d0c353")
.isAcceptableSender(false)
.isExemptRecipient(false)
.isRegex(false)
.isTrustedSender(true)
.pattern("test@example.com")
.patternType("EMAIL")
.verifySender(true)
.comments("Trust all messages send from test@example.com")
.isRecipient(false)
.isSender(true)
.isSpoof(false)
.build());
}
}
resources:
exampleEmailSecurityAllowPolicy:
type: cloudflare:EmailSecurityAllowPolicy
name: example_email_security_allow_policy
properties:
accountId: 023e105f4ecef8ad9ca31a8372d0c353
isAcceptableSender: false
isExemptRecipient: false
isRegex: false
isTrustedSender: true
pattern: test@example.com
patternType: EMAIL
verifySender: true
comments: Trust all messages send from test@example.com
isRecipient: false
isSender: true
isSpoof: false
pulumi {
required_providers {
cloudflare = {
source = "pulumi/cloudflare"
}
}
}
resource "cloudflare_emailsecurityallowpolicy" "example_email_security_allow_policy" {
account_id = "023e105f4ecef8ad9ca31a8372d0c353"
is_acceptable_sender = false
is_exempt_recipient = false
is_regex = false
is_trusted_sender = true
pattern = "test@example.com"
pattern_type = "EMAIL"
verify_sender = true
comments = "Trust all messages send from test@example.com"
is_recipient = false
is_sender = true
is_spoof = false
}
Create EmailSecurityAllowPolicy Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new EmailSecurityAllowPolicy(name: string, args: EmailSecurityAllowPolicyArgs, opts?: CustomResourceOptions);@overload
def EmailSecurityAllowPolicy(resource_name: str,
args: EmailSecurityAllowPolicyArgs,
opts: Optional[ResourceOptions] = None)
@overload
def EmailSecurityAllowPolicy(resource_name: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[str] = None,
is_acceptable_sender: Optional[bool] = None,
is_exempt_recipient: Optional[bool] = None,
is_regex: Optional[bool] = None,
is_trusted_sender: Optional[bool] = None,
pattern: Optional[str] = None,
pattern_type: Optional[str] = None,
verify_sender: Optional[bool] = None,
comments: Optional[str] = None,
is_recipient: Optional[bool] = None,
is_sender: Optional[bool] = None,
is_spoof: Optional[bool] = None)func NewEmailSecurityAllowPolicy(ctx *Context, name string, args EmailSecurityAllowPolicyArgs, opts ...ResourceOption) (*EmailSecurityAllowPolicy, error)public EmailSecurityAllowPolicy(string name, EmailSecurityAllowPolicyArgs args, CustomResourceOptions? opts = null)
public EmailSecurityAllowPolicy(String name, EmailSecurityAllowPolicyArgs args)
public EmailSecurityAllowPolicy(String name, EmailSecurityAllowPolicyArgs args, CustomResourceOptions options)
type: cloudflare:EmailSecurityAllowPolicy
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "cloudflare_email_security_allow_policy" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args EmailSecurityAllowPolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args EmailSecurityAllowPolicyArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args EmailSecurityAllowPolicyArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args EmailSecurityAllowPolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args EmailSecurityAllowPolicyArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var emailSecurityAllowPolicyResource = new Cloudflare.EmailSecurityAllowPolicy("emailSecurityAllowPolicyResource", new()
{
AccountId = "string",
IsAcceptableSender = false,
IsExemptRecipient = false,
IsRegex = false,
IsTrustedSender = false,
Pattern = "string",
PatternType = "string",
VerifySender = false,
Comments = "string",
});
example, err := cloudflare.NewEmailSecurityAllowPolicy(ctx, "emailSecurityAllowPolicyResource", &cloudflare.EmailSecurityAllowPolicyArgs{
AccountId: pulumi.String("string"),
IsAcceptableSender: pulumi.Bool(false),
IsExemptRecipient: pulumi.Bool(false),
IsRegex: pulumi.Bool(false),
IsTrustedSender: pulumi.Bool(false),
Pattern: pulumi.String("string"),
PatternType: pulumi.String("string"),
VerifySender: pulumi.Bool(false),
Comments: pulumi.String("string"),
})
resource "cloudflare_email_security_allow_policy" "emailSecurityAllowPolicyResource" {
lifecycle {
create_before_destroy = true
}
account_id = "string"
is_acceptable_sender = false
is_exempt_recipient = false
is_regex = false
is_trusted_sender = false
pattern = "string"
pattern_type = "string"
verify_sender = false
comments = "string"
}
var emailSecurityAllowPolicyResource = new EmailSecurityAllowPolicy("emailSecurityAllowPolicyResource", EmailSecurityAllowPolicyArgs.builder()
.accountId("string")
.isAcceptableSender(false)
.isExemptRecipient(false)
.isRegex(false)
.isTrustedSender(false)
.pattern("string")
.patternType("string")
.verifySender(false)
.comments("string")
.build());
email_security_allow_policy_resource = cloudflare.EmailSecurityAllowPolicy("emailSecurityAllowPolicyResource",
account_id="string",
is_acceptable_sender=False,
is_exempt_recipient=False,
is_regex=False,
is_trusted_sender=False,
pattern="string",
pattern_type="string",
verify_sender=False,
comments="string")
const emailSecurityAllowPolicyResource = new cloudflare.EmailSecurityAllowPolicy("emailSecurityAllowPolicyResource", {
accountId: "string",
isAcceptableSender: false,
isExemptRecipient: false,
isRegex: false,
isTrustedSender: false,
pattern: "string",
patternType: "string",
verifySender: false,
comments: "string",
});
type: cloudflare:EmailSecurityAllowPolicy
properties:
accountId: string
comments: string
isAcceptableSender: false
isExemptRecipient: false
isRegex: false
isTrustedSender: false
pattern: string
patternType: string
verifySender: false
EmailSecurityAllowPolicy Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The EmailSecurityAllowPolicy resource accepts the following input properties:
- Account
Id string - Identifier.
- Is
Acceptable boolSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- Is
Exempt boolRecipient - Bypasses all detections for messages to this recipient.
- Is
Regex bool - Is
Trusted boolSender - Bypasses all detections and link following for messages from this sender.
- Pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - Pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- Verify
Sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- Comments string
- Is
Recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - Is
Sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - Is
Spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- Account
Id string - Identifier.
- Is
Acceptable boolSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- Is
Exempt boolRecipient - Bypasses all detections for messages to this recipient.
- Is
Regex bool - Is
Trusted boolSender - Bypasses all detections and link following for messages from this sender.
- Pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - Pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- Verify
Sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- Comments string
- Is
Recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - Is
Sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - Is
Spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- account_
id string - Identifier.
- is_
acceptable_ boolsender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is_
exempt_ boolrecipient - Bypasses all detections for messages to this recipient.
- is_
regex bool - is_
trusted_ boolsender - Bypasses all detections and link following for messages from this sender.
- pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern_
type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify_
sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- comments string
- is_
recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is_
sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is_
spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- account
Id String - Identifier.
- is
Acceptable BooleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt BooleanRecipient - Bypasses all detections for messages to this recipient.
- is
Regex Boolean - is
Trusted BooleanSender - Bypasses all detections and link following for messages from this sender.
- pattern String
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type String - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender Boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- comments String
- is
Recipient Boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Sender Boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof Boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- account
Id string - Identifier.
- is
Acceptable booleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt booleanRecipient - Bypasses all detections for messages to this recipient.
- is
Regex boolean - is
Trusted booleanSender - Bypasses all detections and link following for messages from this sender.
- pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- comments string
- is
Recipient boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Sender boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- account_
id str - Identifier.
- is_
acceptable_ boolsender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is_
exempt_ boolrecipient - Bypasses all detections for messages to this recipient.
- is_
regex bool - is_
trusted_ boolsender - Bypasses all detections and link following for messages from this sender.
- pattern str
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern_
type str - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify_
sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- comments str
- is_
recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is_
sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is_
spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
- account
Id String - Identifier.
- is
Acceptable BooleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt BooleanRecipient - Bypasses all detections for messages to this recipient.
- is
Regex Boolean - is
Trusted BooleanSender - Bypasses all detections and link following for messages from this sender.
- pattern String
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type String - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender Boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- comments String
- is
Recipient Boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Sender Boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof Boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026.
Outputs
All input properties are implicitly available as output properties. Additionally, the EmailSecurityAllowPolicy resource produces the following output properties:
- Created
At string - Id string
- The provider-assigned unique ID for this managed resource.
- Last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - Modified
At string
- Created
At string - Id string
- The provider-assigned unique ID for this managed resource.
- Last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - Modified
At string
- created_
at string - id string
- The provider-assigned unique ID for this managed resource.
- last_
modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified_
at string
- created
At String - id String
- The provider-assigned unique ID for this managed resource.
- last
Modified String - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At String
- created
At string - id string
- The provider-assigned unique ID for this managed resource.
- last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At string
- created_
at str - id str
- The provider-assigned unique ID for this managed resource.
- last_
modified str - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified_
at str
- created
At String - id String
- The provider-assigned unique ID for this managed resource.
- last
Modified String - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At String
Look up Existing EmailSecurityAllowPolicy Resource
Get an existing EmailSecurityAllowPolicy resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: EmailSecurityAllowPolicyState, opts?: CustomResourceOptions): EmailSecurityAllowPolicy@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[str] = None,
comments: Optional[str] = None,
created_at: Optional[str] = None,
is_acceptable_sender: Optional[bool] = None,
is_exempt_recipient: Optional[bool] = None,
is_recipient: Optional[bool] = None,
is_regex: Optional[bool] = None,
is_sender: Optional[bool] = None,
is_spoof: Optional[bool] = None,
is_trusted_sender: Optional[bool] = None,
last_modified: Optional[str] = None,
modified_at: Optional[str] = None,
pattern: Optional[str] = None,
pattern_type: Optional[str] = None,
verify_sender: Optional[bool] = None) -> EmailSecurityAllowPolicyfunc GetEmailSecurityAllowPolicy(ctx *Context, name string, id IDInput, state *EmailSecurityAllowPolicyState, opts ...ResourceOption) (*EmailSecurityAllowPolicy, error)public static EmailSecurityAllowPolicy Get(string name, Input<string> id, EmailSecurityAllowPolicyState? state, CustomResourceOptions? opts = null)public static EmailSecurityAllowPolicy get(String name, Output<String> id, EmailSecurityAllowPolicyState state, CustomResourceOptions options)resources: _: type: cloudflare:EmailSecurityAllowPolicy get: id: ${id}import {
to = cloudflare_email_security_allow_policy.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Account
Id string - Identifier.
- Comments string
- Created
At string - Is
Acceptable boolSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- Is
Exempt boolRecipient - Bypasses all detections for messages to this recipient.
- Is
Recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - Is
Regex bool - Is
Sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - Is
Spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - Is
Trusted boolSender - Bypasses all detections and link following for messages from this sender.
- Last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - Modified
At string - Pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - Pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- Verify
Sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- Account
Id string - Identifier.
- Comments string
- Created
At string - Is
Acceptable boolSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- Is
Exempt boolRecipient - Bypasses all detections for messages to this recipient.
- Is
Recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - Is
Regex bool - Is
Sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - Is
Spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - Is
Trusted boolSender - Bypasses all detections and link following for messages from this sender.
- Last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - Modified
At string - Pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - Pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- Verify
Sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- account_
id string - Identifier.
- comments string
- created_
at string - is_
acceptable_ boolsender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is_
exempt_ boolrecipient - Bypasses all detections for messages to this recipient.
- is_
recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is_
regex bool - is_
sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is_
spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - is_
trusted_ boolsender - Bypasses all detections and link following for messages from this sender.
- last_
modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified_
at string - pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern_
type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify_
sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- account
Id String - Identifier.
- comments String
- created
At String - is
Acceptable BooleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt BooleanRecipient - Bypasses all detections for messages to this recipient.
- is
Recipient Boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Regex Boolean - is
Sender Boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof Boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - is
Trusted BooleanSender - Bypasses all detections and link following for messages from this sender.
- last
Modified String - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At String - pattern String
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type String - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender Boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- account
Id string - Identifier.
- comments string
- created
At string - is
Acceptable booleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt booleanRecipient - Bypasses all detections for messages to this recipient.
- is
Recipient boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Regex boolean - is
Sender boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - is
Trusted booleanSender - Bypasses all detections and link following for messages from this sender.
- last
Modified string - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At string - pattern string
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type string - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- account_
id str - Identifier.
- comments str
- created_
at str - is_
acceptable_ boolsender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is_
exempt_ boolrecipient - Bypasses all detections for messages to this recipient.
- is_
recipient bool - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is_
regex bool - is_
sender bool - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is_
spoof bool - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - is_
trusted_ boolsender - Bypasses all detections and link following for messages from this sender.
- last_
modified str - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified_
at str - pattern str
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern_
type str - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify_
sender bool - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
- account
Id String - Identifier.
- comments String
- created
At String - is
Acceptable BooleanSender - Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
- is
Exempt BooleanRecipient - Bypasses all detections for messages to this recipient.
- is
Recipient Boolean - Deprecated as of July 1, 2025. Use
isExemptRecipientinstead. End of life: July 1, 2026. - is
Regex Boolean - is
Sender Boolean - Deprecated as of July 1, 2025. Use
isTrustedSenderinstead. End of life: July 1, 2026. - is
Spoof Boolean - Deprecated as of July 1, 2025. Use
isAcceptableSenderinstead. End of life: July 1, 2026. - is
Trusted BooleanSender - Bypasses all detections and link following for messages from this sender.
- last
Modified String - Deprecated, use
modifiedAtinstead. End of life: November 1, 2026. - modified
At String - pattern String
- The pattern value to match. The format depends on
patternType: a valid email address for EMAIL (e.g.user@example.com), a valid domain name for DOMAIN (e.g.example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g.1.2.3.4,1.2.3.0/24,2606:4700:4700::1111, or2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - pattern
Type String - Type of pattern matching.
- EMAIL: matches a full email address (e.g.
user@example.com) - DOMAIN: matches a domain name (e.g.
example.com) - IP: matches a plain IPv4 or IPv6 address (e.g.
1.2.3.4or2606:4700:4700::1111) or CIDR block (e.g.1.2.3.0/24or2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents. - UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
- EMAIL: matches a full email address (e.g.
- verify
Sender Boolean - Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
Import
$ pulumi import cloudflare:index/emailSecurityAllowPolicy:EmailSecurityAllowPolicy example '<account_id>/<policy_id>'
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- Cloudflare pulumi/pulumi-cloudflare
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
cloudflareTerraform Provider.
published on Thursday, Sep 17, 2026 by Pulumi