1. Registry
  2. Packages
  3. Cloudflare Provider
  4. API Docs
  5. getEmailSecurityAllowPolicy
Viewing docs for Cloudflare v6.21.0
published on Thursday, Sep 17, 2026 by Pulumi
cloudflare logo cloudflare logo
Viewing docs for Cloudflare v6.21.0
published on Thursday, Sep 17, 2026 by Pulumi

    Accepted Permissions

    • Cloud Email Security: Read
    • Cloud Email Security: Write

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as cloudflare from "@pulumi/cloudflare";
    
    const exampleEmailSecurityAllowPolicy = cloudflare.getEmailSecurityAllowPolicy({
        accountId: "023e105f4ecef8ad9ca31a8372d0c353",
        policyId: "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
    });
    
    import pulumi
    import pulumi_cloudflare as cloudflare
    
    example_email_security_allow_policy = cloudflare.get_email_security_allow_policy(account_id="023e105f4ecef8ad9ca31a8372d0c353",
        policy_id="f174e90a-fafe-4643-bbbc-4a0ed4fc8415")
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-cloudflare/sdk/v6/go/cloudflare"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := cloudflare.GetEmailSecurityAllowPolicy(ctx, &cloudflare.LookupEmailSecurityAllowPolicyArgs{
    			AccountId: "023e105f4ecef8ad9ca31a8372d0c353",
    			PolicyId:  pulumi.StringRef("f174e90a-fafe-4643-bbbc-4a0ed4fc8415"),
    		}, nil)
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Cloudflare = Pulumi.Cloudflare;
    
    return await Deployment.RunAsync(() => 
    {
        var exampleEmailSecurityAllowPolicy = Cloudflare.GetEmailSecurityAllowPolicy.Invoke(new()
        {
            AccountId = "023e105f4ecef8ad9ca31a8372d0c353",
            PolicyId = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.cloudflare.CloudflareFunctions;
    import com.pulumi.cloudflare.inputs.GetEmailSecurityAllowPolicyArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            final var exampleEmailSecurityAllowPolicy = CloudflareFunctions.getEmailSecurityAllowPolicy(GetEmailSecurityAllowPolicyArgs.builder()
                .accountId("023e105f4ecef8ad9ca31a8372d0c353")
                .policyId("f174e90a-fafe-4643-bbbc-4a0ed4fc8415")
                .build());
    
        }
    }
    
    variables:
      exampleEmailSecurityAllowPolicy:
        fn::invoke:
          function: cloudflare:getEmailSecurityAllowPolicy
          arguments:
            accountId: 023e105f4ecef8ad9ca31a8372d0c353
            policyId: f174e90a-fafe-4643-bbbc-4a0ed4fc8415
    
    pulumi {
      required_providers {
        cloudflare = {
          source = "pulumi/cloudflare"
        }
      }
    }
    
    data "cloudflare_getemailsecurityallowpolicy" "exampleEmailSecurityAllowPolicy" {
      account_id = "023e105f4ecef8ad9ca31a8372d0c353"
      policy_id  = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
    }
    

    Using getEmailSecurityAllowPolicy

    Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.

    function getEmailSecurityAllowPolicy(args: GetEmailSecurityAllowPolicyArgs, opts?: InvokeOptions): Promise<GetEmailSecurityAllowPolicyResult>
    function getEmailSecurityAllowPolicyOutput(args: GetEmailSecurityAllowPolicyOutputArgs, opts?: InvokeOutputOptions): Output<GetEmailSecurityAllowPolicyResult>
    def get_email_security_allow_policy(account_id: Optional[str] = None,
                                        filter: Optional[GetEmailSecurityAllowPolicyFilter] = None,
                                        policy_id: Optional[str] = None,
                                        opts: Optional[InvokeOptions] = None) -> GetEmailSecurityAllowPolicyResult
    def get_email_security_allow_policy_output(account_id: pulumi.Input[Optional[str]] = None,
                                        filter: pulumi.Input[Optional[GetEmailSecurityAllowPolicyFilterArgs]] = None,
                                        policy_id: pulumi.Input[Optional[str]] = None,
                                        opts: Optional[InvokeOutputOptions] = None) -> Output[GetEmailSecurityAllowPolicyResult]
    func LookupEmailSecurityAllowPolicy(ctx *Context, args *LookupEmailSecurityAllowPolicyArgs, opts ...InvokeOption) (*LookupEmailSecurityAllowPolicyResult, error)
    func LookupEmailSecurityAllowPolicyOutput(ctx *Context, args *LookupEmailSecurityAllowPolicyOutputArgs, opts ...InvokeOption) LookupEmailSecurityAllowPolicyResultOutput

    > Note: This function is named LookupEmailSecurityAllowPolicy in the Go SDK.

    public static class GetEmailSecurityAllowPolicy 
    {
        public static Task<GetEmailSecurityAllowPolicyResult> InvokeAsync(GetEmailSecurityAllowPolicyArgs args, InvokeOptions? opts = null)
        public static Output<GetEmailSecurityAllowPolicyResult> Invoke(GetEmailSecurityAllowPolicyInvokeArgs args, InvokeOptions? opts = null)
        public static Output<GetEmailSecurityAllowPolicyResult> Invoke(GetEmailSecurityAllowPolicyInvokeArgs args, InvokeOutputOptions opts)
    }
    public static CompletableFuture<GetEmailSecurityAllowPolicyResult> getEmailSecurityAllowPolicy(GetEmailSecurityAllowPolicyArgs args, InvokeOptions options)
    public static Output<GetEmailSecurityAllowPolicyResult> getEmailSecurityAllowPolicy(GetEmailSecurityAllowPolicyArgs args, InvokeOptions options)
    public static Output<GetEmailSecurityAllowPolicyResult> getEmailSecurityAllowPolicy(GetEmailSecurityAllowPolicyArgs args, InvokeOutputOptions options)
    
    fn::invoke:
      function: cloudflare:index/getEmailSecurityAllowPolicy:getEmailSecurityAllowPolicy
      arguments:
        # arguments dictionary
    data "cloudflare_get_email_security_allow_policy" "name" {
        # arguments
    }

    The following arguments are supported:

    getEmailSecurityAllowPolicy Result

    The following output properties are available:

    AccountId string
    Comments string
    CreatedAt string
    Id string
    IsAcceptableSender bool
    IsExemptRecipient bool
    IsRecipient bool

    Deprecated: Use isExemptRecipient instead.

    IsRegex bool
    IsSender bool

    Deprecated: Use isTrustedSender instead.

    IsSpoof bool

    Deprecated: Use isAcceptableSender instead.

    IsTrustedSender bool
    LastModified string

    Deprecated: Use modifiedAt instead.

    ModifiedAt string
    Pattern string
    PatternType string
    VerifySender bool
    Filter GetEmailSecurityAllowPolicyFilter
    PolicyId string
    AccountId string
    Comments string
    CreatedAt string
    Id string
    IsAcceptableSender bool
    IsExemptRecipient bool
    IsRecipient bool

    Deprecated: Use isExemptRecipient instead.

    IsRegex bool
    IsSender bool

    Deprecated: Use isTrustedSender instead.

    IsSpoof bool

    Deprecated: Use isAcceptableSender instead.

    IsTrustedSender bool
    LastModified string

    Deprecated: Use modifiedAt instead.

    ModifiedAt string
    Pattern string
    PatternType string
    VerifySender bool
    Filter GetEmailSecurityAllowPolicyFilter
    PolicyId string
    account_id string
    comments string
    created_at string
    id string
    is_acceptable_sender bool
    is_exempt_recipient bool
    is_recipient bool

    Deprecated: Use isExemptRecipient instead.

    is_regex bool
    is_sender bool

    Deprecated: Use isTrustedSender instead.

    is_spoof bool

    Deprecated: Use isAcceptableSender instead.

    is_trusted_sender bool
    last_modified string

    Deprecated: Use modifiedAt instead.

    modified_at string
    pattern string
    pattern_type string
    verify_sender bool
    filter object
    policy_id string
    accountId String
    comments String
    createdAt String
    id String
    isAcceptableSender Boolean
    isExemptRecipient Boolean
    isRecipient Boolean

    Deprecated: Use isExemptRecipient instead.

    isRegex Boolean
    isSender Boolean

    Deprecated: Use isTrustedSender instead.

    isSpoof Boolean

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender Boolean
    lastModified String

    Deprecated: Use modifiedAt instead.

    modifiedAt String
    pattern String
    patternType String
    verifySender Boolean
    filter GetEmailSecurityAllowPolicyFilter
    policyId String
    accountId string
    comments string
    createdAt string
    id string
    isAcceptableSender boolean
    isExemptRecipient boolean
    isRecipient boolean

    Deprecated: Use isExemptRecipient instead.

    isRegex boolean
    isSender boolean

    Deprecated: Use isTrustedSender instead.

    isSpoof boolean

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender boolean
    lastModified string

    Deprecated: Use modifiedAt instead.

    modifiedAt string
    pattern string
    patternType string
    verifySender boolean
    filter GetEmailSecurityAllowPolicyFilter
    policyId string
    account_id str
    comments str
    created_at str
    id str
    is_acceptable_sender bool
    is_exempt_recipient bool
    is_recipient bool

    Deprecated: Use isExemptRecipient instead.

    is_regex bool
    is_sender bool

    Deprecated: Use isTrustedSender instead.

    is_spoof bool

    Deprecated: Use isAcceptableSender instead.

    is_trusted_sender bool
    last_modified str

    Deprecated: Use modifiedAt instead.

    modified_at str
    pattern str
    pattern_type str
    verify_sender bool
    filter GetEmailSecurityAllowPolicyFilter
    policy_id str
    accountId String
    comments String
    createdAt String
    id String
    isAcceptableSender Boolean
    isExemptRecipient Boolean
    isRecipient Boolean

    Deprecated: Use isExemptRecipient instead.

    isRegex Boolean
    isSender Boolean

    Deprecated: Use isTrustedSender instead.

    isSpoof Boolean

    Deprecated: Use isAcceptableSender instead.

    isTrustedSender Boolean
    lastModified String

    Deprecated: Use modifiedAt instead.

    modifiedAt String
    pattern String
    patternType String
    verifySender Boolean
    filter Property Map
    policyId String

    Supporting Types

    GetEmailSecurityAllowPolicyFilter

    Direction string
    The sorting direction. Available values: "asc", "desc".
    IsAcceptableSender bool
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    IsExemptRecipient bool
    Filter to show only policies where messages to the recipient bypass all detections.
    IsTrustedSender bool
    Filter to show only policies where messages from the sender bypass all detections and link following.
    Order string
    Field to sort by. Available values: "pattern", "createdAt".
    Pattern string
    PatternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    Search string
    Search term for filtering records. Behavior may change.
    VerifySender bool
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    Direction string
    The sorting direction. Available values: "asc", "desc".
    IsAcceptableSender bool
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    IsExemptRecipient bool
    Filter to show only policies where messages to the recipient bypass all detections.
    IsTrustedSender bool
    Filter to show only policies where messages from the sender bypass all detections and link following.
    Order string
    Field to sort by. Available values: "pattern", "createdAt".
    Pattern string
    PatternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    Search string
    Search term for filtering records. Behavior may change.
    VerifySender bool
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    direction string
    The sorting direction. Available values: "asc", "desc".
    is_acceptable_sender bool
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    is_exempt_recipient bool
    Filter to show only policies where messages to the recipient bypass all detections.
    is_trusted_sender bool
    Filter to show only policies where messages from the sender bypass all detections and link following.
    order string
    Field to sort by. Available values: "pattern", "createdAt".
    pattern string
    pattern_type string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    search string
    Search term for filtering records. Behavior may change.
    verify_sender bool
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    direction String
    The sorting direction. Available values: "asc", "desc".
    isAcceptableSender Boolean
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    isExemptRecipient Boolean
    Filter to show only policies where messages to the recipient bypass all detections.
    isTrustedSender Boolean
    Filter to show only policies where messages from the sender bypass all detections and link following.
    order String
    Field to sort by. Available values: "pattern", "createdAt".
    pattern String
    patternType String
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    search String
    Search term for filtering records. Behavior may change.
    verifySender Boolean
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    direction string
    The sorting direction. Available values: "asc", "desc".
    isAcceptableSender boolean
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    isExemptRecipient boolean
    Filter to show only policies where messages to the recipient bypass all detections.
    isTrustedSender boolean
    Filter to show only policies where messages from the sender bypass all detections and link following.
    order string
    Field to sort by. Available values: "pattern", "createdAt".
    pattern string
    patternType string
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    search string
    Search term for filtering records. Behavior may change.
    verifySender boolean
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    direction str
    The sorting direction. Available values: "asc", "desc".
    is_acceptable_sender bool
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    is_exempt_recipient bool
    Filter to show only policies where messages to the recipient bypass all detections.
    is_trusted_sender bool
    Filter to show only policies where messages from the sender bypass all detections and link following.
    order str
    Field to sort by. Available values: "pattern", "createdAt".
    pattern str
    pattern_type str
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    search str
    Search term for filtering records. Behavior may change.
    verify_sender bool
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.
    direction String
    The sorting direction. Available values: "asc", "desc".
    isAcceptableSender Boolean
    Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious).
    isExemptRecipient Boolean
    Filter to show only policies where messages to the recipient bypass all detections.
    isTrustedSender Boolean
    Filter to show only policies where messages from the sender bypass all detections and link following.
    order String
    Field to sort by. Available values: "pattern", "createdAt".
    pattern String
    patternType String
    Type of pattern matching.

    • EMAIL: matches a full email address (e.g. user@example.com)
    • DOMAIN: matches a domain name (e.g. example.com)
    • IP: matches a plain IPv4 or IPv6 address (e.g. 1.2.3.4 or 2606:4700:4700::1111) or CIDR block (e.g. 1.2.3.0/24 or 2606:4700:4700::/48). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.
    • UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries. Available values: "EMAIL", "DOMAIN", "IP", "UNKNOWN".
    search String
    Search term for filtering records. Behavior may change.
    verifySender Boolean
    Filter to show only policies that enforce DMARC, SPF, or DKIM authentication.

    Package Details

    Repository
    Cloudflare pulumi/pulumi-cloudflare
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the cloudflare Terraform Provider.
    cloudflare logo cloudflare logo
    Viewing docs for Cloudflare v6.21.0
    published on Thursday, Sep 17, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial