1. Registry
  2. Packages
  3. Cloudflare Provider
  4. API Docs
  5. getEmailSecurityAllowPolicies
Viewing docs for Cloudflare v6.21.0
published on Thursday, Sep 17, 2026 by Pulumi
cloudflare logo cloudflare logo
Viewing docs for Cloudflare v6.21.0
published on Thursday, Sep 17, 2026 by Pulumi

    Accepted Permissions

    • Cloud Email Security: Read
    • Cloud Email Security: Write

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as cloudflare from "@pulumi/cloudflare";
    
    const exampleEmailSecurityAllowPolicies = cloudflare.getEmailSecurityAllowPolicies({
        accountId: "023e105f4ecef8ad9ca31a8372d0c353",
        direction: "asc",
        isAcceptableSender: true,
        isExemptRecipient: true,
        isTrustedSender: true,
        order: "pattern",
        pattern: "pattern",
        patternType: "EMAIL",
        search: "search",
        verifySender: true,
    });
    
    import pulumi
    import pulumi_cloudflare as cloudflare
    
    example_email_security_allow_policies = cloudflare.get_email_security_allow_policies(account_id="023e105f4ecef8ad9ca31a8372d0c353",
        direction="asc",
        is_acceptable_sender=True,
        is_exempt_recipient=True,
        is_trusted_sender=True,
        order="pattern",
        pattern="pattern",
        pattern_type="EMAIL",
        search="search",
        verify_sender=True)
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-cloudflare/sdk/v6/go/cloudflare"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := cloudflare.GetEmailSecurityAllowPolicies(ctx, &cloudflare.LookupEmailSecurityAllowPoliciesArgs{
    			AccountId:          "023e105f4ecef8ad9ca31a8372d0c353",
    			Direction:          pulumi.StringRef("asc"),
    			IsAcceptableSender: pulumi.BoolRef(true),
    			IsExemptRecipient:  pulumi.BoolRef(true),
    			IsTrustedSender:    pulumi.BoolRef(true),
    			Order:              pulumi.StringRef("pattern"),
    			Pattern:            pulumi.StringRef("pattern"),
    			PatternType:        pulumi.StringRef("EMAIL"),
    			Search:             pulumi.StringRef("search"),
    			VerifySender:       pulumi.BoolRef(true),
    		}, nil)
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Cloudflare = Pulumi.Cloudflare;
    
    return await Deployment.RunAsync(() => 
    {
        var exampleEmailSecurityAllowPolicies = Cloudflare.GetEmailSecurityAllowPolicies.Invoke(new()
        {
            AccountId = "023e105f4ecef8ad9ca31a8372d0c353",
            Direction = "asc",
            IsAcceptableSender = true,
            IsExemptRecipient = true,
            IsTrustedSender = true,
            Order = "pattern",
            Pattern = "pattern",
            PatternType = "EMAIL",
            Search = "search",
            VerifySender = true,
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.cloudflare.CloudflareFunctions;
    import com.pulumi.cloudflare.inputs.GetEmailSecurityAllowPoliciesArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            final var exampleEmailSecurityAllowPolicies = CloudflareFunctions.getEmailSecurityAllowPolicies(GetEmailSecurityAllowPoliciesArgs.builder()
                .accountId("023e105f4ecef8ad9ca31a8372d0c353")
                .direction("asc")
                .isAcceptableSender(true)
                .isExemptRecipient(true)
                .isTrustedSender(true)
                .order("pattern")
                .pattern("pattern")
                .patternType("EMAIL")
                .search("search")
                .verifySender(true)
                .build());
    
        }
    }
    
    variables:
      exampleEmailSecurityAllowPolicies:
        fn::invoke:
          function: cloudflare:getEmailSecurityAllowPolicies
          arguments:
            accountId: 023e105f4ecef8ad9ca31a8372d0c353
            direction: asc
            isAcceptableSender: true
            isExemptRecipient: true
            isTrustedSender: true
            order: pattern
            pattern: pattern
            patternType: EMAIL
            search: search
            verifySender: true
    
    pulumi {
      required_providers {
        cloudflare = {
          source = "pulumi/cloudflare"
        }
      }
    }
    
    data "cloudflare_getemailsecurityallowpolicies" "exampleEmailSecurityAllowPolicies" {
      account_id           = "023e105f4ecef8ad9ca31a8372d0c353"
      direction            = "asc"
      is_acceptable_sender = true
      is_exempt_recipient  = true
      is_trusted_sender    = true
      order                = "pattern"
      pattern              = "pattern"
      pattern_type         = "EMAIL"
      search               = "search"
      verify_sender        = true
    }
    

    Using getEmailSecurityAllowPolicies

    Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.

    function getEmailSecurityAllowPolicies(args: GetEmailSecurityAllowPoliciesArgs, opts?: InvokeOptions): Promise<GetEmailSecurityAllowPoliciesResult>
    function getEmailSecurityAllowPoliciesOutput(args: GetEmailSecurityAllowPoliciesOutputArgs, opts?: InvokeOutputOptions): Output<GetEmailSecurityAllowPoliciesResult>
    def get_email_security_allow_policies(account_id: Optional[str] = None,
                                          direction: Optional[str] = None,
                                          is_acceptable_sender: Optional[bool] = None,
                                          is_exempt_recipient: Optional[bool] = None,
                                          is_trusted_sender: Optional[bool] = None,
                                          max_items: Optional[int] = None,
                                          order: Optional[str] = None,
                                          pattern: Optional[str] = None,
                                          pattern_type: Optional[str] = None,
                                          search: Optional[str] = None,
                                          verify_sender: Optional[bool] = None,
                                          opts: Optional[InvokeOptions] = None) -> GetEmailSecurityAllowPoliciesResult
    def get_email_security_allow_policies_output(account_id: pulumi.Input[Optional[str]] = None,
                                          direction: pulumi.Input[Optional[str]] = None,
                                          is_acceptable_sender: pulumi.Input[Optional[bool]] = None,
                                          is_exempt_recipient: pulumi.Input[Optional[bool]] = None,
                                          is_trusted_sender: pulumi.Input[Optional[bool]] = None,
                                          max_items: pulumi.Input[Optional[int]] = None,
                                          order: pulumi.Input[Optional[str]] = None,
                                          pattern: pulumi.Input[Optional[str]] = None,
                                          pattern_type: pulumi.Input[Optional[str]] = None,
                                          search: pulumi.Input[Optional[str]] = None,
                                          verify_sender: pulumi.Input[Optional[bool]] = None,
                                          opts: Optional[InvokeOutputOptions] = None) -> Output[GetEmailSecurityAllowPoliciesResult]
    func LookupEmailSecurityAllowPolicies(ctx *Context, args *LookupEmailSecurityAllowPoliciesArgs, opts ...InvokeOption) (*LookupEmailSecurityAllowPoliciesResult, error)
    func LookupEmailSecurityAllowPoliciesOutput(ctx *Context, args *LookupEmailSecurityAllowPoliciesOutputArgs, opts ...InvokeOption) LookupEmailSecurityAllowPoliciesResultOutput

    > Note: This function is named LookupEmailSecurityAllowPolicies in the Go SDK.

    public static class GetEmailSecurityAllowPolicies 
    {
        public static Task<GetEmailSecurityAllowPoliciesResult> InvokeAsync(GetEmailSecurityAllowPoliciesArgs args, InvokeOptions? opts = null)
        public static Output<GetEmailSecurityAllowPoliciesResult> Invoke(GetEmailSecurityAllowPoliciesInvokeArgs args, InvokeOptions? opts = null)
        public static Output<GetEmailSecurityAllowPoliciesResult> Invoke(GetEmailSecurityAllowPoliciesInvokeArgs args, InvokeOutputOptions opts)
    }
    public static CompletableFuture<GetEmailSecurityAllowPoliciesResult> getEmailSecurityAllowPolicies(GetEmailSecurityAllowPoliciesArgs args, InvokeOptions options)
    public static Output<GetEmailSecurityAllowPoliciesResult> getEmailSecurityAllowPolicies(GetEmailSecurityAllowPoliciesArgs args, InvokeOptions options)
    public static Output<GetEmailSecurityAllowPoliciesResult> getEmailSecurityAllowPolicies(GetEmailSecurityAllowPoliciesArgs args, InvokeOutputOptions options)
    
    fn::invoke:
      function: cloudflare:index/getEmailSecurityAllowPolicies:getEmailSecurityAllowPolicies
      arguments:
        # arguments dictionary
    data "cloudflare_get_email_security_allow_policies" "name" {
        # arguments
    }

    The following arguments are supported:

    accountId String
    direction String
    isAcceptableSender Boolean
    isExemptRecipient Boolean
    isTrustedSender Boolean
    maxItems Integer
    order String
    pattern String
    patternType String
    search String
    verifySender Boolean
    accountId string
    direction string
    isAcceptableSender boolean
    isExemptRecipient boolean
    isTrustedSender boolean
    maxItems number
    order string
    pattern string
    patternType string
    search string
    verifySender boolean
    accountId String
    direction String
    isAcceptableSender Boolean
    isExemptRecipient Boolean
    isTrustedSender Boolean
    maxItems Number
    order String
    pattern String
    patternType String
    search String
    verifySender Boolean

    getEmailSecurityAllowPolicies Result

    The following output properties are available:

    Supporting Types

    GetEmailSecurityAllowPoliciesResult

    Comments string
    CreatedAt string
    Id string
    Allow policy identifier.
    IsAcceptableSender bool
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    IsExemptRecipient bool
    Bypasses all detections for messages to this recipient.
    IsRecipient bool
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    IsRegex bool
    IsSender bool
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    IsSpoof bool
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    IsTrustedSender bool
    Bypasses all detections and link following for messages from this sender.
    LastModified string
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    ModifiedAt string
    Pattern string
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    PatternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    VerifySender bool
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    Comments string
    CreatedAt string
    Id string
    Allow policy identifier.
    IsAcceptableSender bool
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    IsExemptRecipient bool
    Bypasses all detections for messages to this recipient.
    IsRecipient bool
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    IsRegex bool
    IsSender bool
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    IsSpoof bool
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    IsTrustedSender bool
    Bypasses all detections and link following for messages from this sender.
    LastModified string
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    ModifiedAt string
    Pattern string
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    PatternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    VerifySender bool
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    comments string
    created_at string
    id string
    Allow policy identifier.
    is_acceptable_sender bool
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    is_exempt_recipient bool
    Bypasses all detections for messages to this recipient.
    is_recipient bool
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    is_regex bool
    is_sender bool
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    is_spoof bool
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    is_trusted_sender bool
    Bypasses all detections and link following for messages from this sender.
    last_modified string
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    modified_at string
    pattern string
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    pattern_type string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    verify_sender bool
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    comments String
    createdAt String
    id String
    Allow policy identifier.
    isAcceptableSender Boolean
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    isExemptRecipient Boolean
    Bypasses all detections for messages to this recipient.
    isRecipient Boolean
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    isRegex Boolean
    isSender Boolean
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    isSpoof Boolean
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender Boolean
    Bypasses all detections and link following for messages from this sender.
    lastModified String
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    modifiedAt String
    pattern String
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    patternType String
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    verifySender Boolean
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    comments string
    createdAt string
    id string
    Allow policy identifier.
    isAcceptableSender boolean
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    isExemptRecipient boolean
    Bypasses all detections for messages to this recipient.
    isRecipient boolean
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    isRegex boolean
    isSender boolean
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    isSpoof boolean
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender boolean
    Bypasses all detections and link following for messages from this sender.
    lastModified string
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    modifiedAt string
    pattern string
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    patternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    verifySender boolean
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    comments str
    created_at str
    id str
    Allow policy identifier.
    is_acceptable_sender bool
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    is_exempt_recipient bool
    Bypasses all detections for messages to this recipient.
    is_recipient bool
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    is_regex bool
    is_sender bool
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    is_spoof bool
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    is_trusted_sender bool
    Bypasses all detections and link following for messages from this sender.
    last_modified str
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    modified_at str
    pattern str
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    pattern_type str
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    verify_sender bool
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.
    comments String
    createdAt String
    id String
    Allow policy identifier.
    isAcceptableSender Boolean
    Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply.
    isExemptRecipient Boolean
    Bypasses all detections for messages to this recipient.
    isRecipient Boolean
    Deprecated as of July 1, 2025. Use isExemptRecipient instead. End of life: July 1, 2026.

    Deprecated: Use isExemptRecipient instead.

    isRegex Boolean
    isSender Boolean
    Deprecated as of July 1, 2025. Use isTrustedSender instead. End of life: July 1, 2026.

    Deprecated: Use isTrustedSender instead.

    isSpoof Boolean
    Deprecated as of July 1, 2025. Use isAcceptableSender instead. End of life: July 1, 2026.

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender Boolean
    Bypasses all detections and link following for messages from this sender.
    lastModified String
    Deprecated, use modifiedAt instead. End of life: November 1, 2026.

    Deprecated: Use modifiedAt instead.

    modifiedAt String
    pattern String
    The pattern value to match. The format depends on patternType: a valid email address for EMAIL (e.g. user@example.com), a valid domain name for DOMAIN (e.g. example.com), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. 1.2.3.4, 1.2.3.0/24, 2606:4700:4700::1111, or 2606:4700:4700::/48); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    patternType String
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    verifySender Boolean
    Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication.

    Package Details

    Repository
    Cloudflare pulumi/pulumi-cloudflare
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the cloudflare Terraform Provider.
    cloudflare logo cloudflare logo
    Viewing docs for Cloudflare v6.21.0
    published on Thursday, Sep 17, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial