Mimecast Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Mimecast Tools
mc_ · 374 tools · Free 194 · Pro 180
Email security, archiving, policy, human risk and DMARC over Mimecast API 2.0. Auth is OAuth2 client_credentials only: client_id + client_secret posted to POST /oauth/token for a 30-minute bearer, NO refresh token. No scope parameter - authority is bound when the Application is created, by its Product and Role, so a 401 app_forbidden is a key short one product; DMARC Analyzer is its own product the DMARC tools need. Three residency gateways (global, uk, us); DMARC is a base PATH on the same host, not a fourth gateway. An MSP holds ONE partner credential, naming a managed customer per call via x-mc-account, the accountCode argument. Paging has four shapes: legacy routes carry pageSize/pageToken in the REQUEST BODY under meta.pagination, ending by OMITTING next; REST routes use query parameters; DMARC pages by query, ending on meta.nextPage; some are unpaginated. Max page size 100. On legacy routes a 200 is not success - a non-empty fail[] is a failure. X-RateLimit-Reset is ms.
All connector tools · Mimecast setup guide
Mimecast tool groups
- Account — 8 tools
- Configuration snapshots — 4 tools
- Partner (MSP) — 2 tools
- Archive search — 5 tools
- Data retention — 5 tools
- Archive access logs — 3 tools
- Audit events — 2 tools
- Delivery monitoring — 2 tools
- Awareness scores — 6 tools
- Human risk — 7 tools
- Phishing campaigns — 2 tools
- Training queue and users — 2 tools
- Administrator roles — 1 tool
- Directory connections — 31 tools
- Groups — 13 tools
- Users — 19 tools
- DMARC DNS checks — 4 tools
- DMARC delegated domains — 18 tools
- DMARC detected domains — 3 tools
- DMARC domain groups — 7 tools
- DMARC domains — 8 tools
- DMARC policy presets — 4 tools
- DMARC compliance — 4 tools
- DMARC customer settings — 4 tools
- DMARC events and issues — 3 tools
- DMARC notifications — 5 tools
- DMARC reports — 4 tools
- DMARC sources — 8 tools
- DMARC tasks — 7 tools
- DMARC users — 6 tools
- Domain onboarding — 12 tools
- External domains — 2 tools
- Internal domains — 8 tools
- Protection mode — 1 tool
- Gateway configuration — 6 tools
- Held messages — 5 tools
- Journaling — 6 tools
- Managed senders — 4 tools
- Message tracking — 6 tools
- Outbound email — 2 tools
- Cloud Integrated policies — 7 tools
- Connectors — 5 tools
- Marketplace integrations — 8 tools
- Address alteration — 9 tools
- Anti-spoofing — 5 tools
- Anti-spoofing bypass — 9 tools
- Blocked senders — 7 tools
- DNS authentication — 11 tools
- Delivery routes — 11 tools
- Greylisting — 5 tools
- Managed URLs — 3 tools
- Web security — 4 tools
- Protection logs — 4 tools
- Remediation — 9 tools
- Reported emails — 8 tools
- SIEM feeds — 4 tools
- Threat events — 2 tools
- Threat intelligence — 5 tools
- Threat statistics — 9 tools
Account
mc_get_account details
mc_get_account details
[Mimecast] This endpoint returns the summary details for an account in Mimecast. POST /api/account/get-account. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dashboard_notifications details
mc_get_dashboard_notifications details
[Mimecast] This feed can be used to return dashboard notifications from the Administration Console Dashboard. POST /api/account/get-dashboard-notifications. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountCode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_emergency_contact details
mc_get_emergency_contact details
[Mimecast] Returns the Emergency Contact information for the account. GET /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_provisioning_packages details
mc_get_provisioning_packages details
[Mimecast] This endpoint returns products that are available to be provisioned by a partner. POST /api/provisioning/get-packages. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_support_info details
mc_get_support_info details
[Mimecast] This endpoint returns support information that is associated with a Mimecast tenant. POST /api/account/get-support-info. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_whoami details
mc_get_whoami details
[Mimecast] Returns details of a partner, including information such as Partner type, Mimecast account code in CI, CG and X1 platform. Refer to guideline tutorial page for more information on using this endpoint. GET /identity/whoami. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_emergency_contact details
mc_replace_emergency_contact details
[Mimecast] DESTRUCTIVE: creates an Emergency Contact for the account. Why this is destructive: wholesale replace - the body becomes the entire emergency-contact record and any field omitted from it is cleared. PUT /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: contactName, contactEmailAddress, mobilePhone, telephone, alternateEmailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_emergency_contact details
mc_update_emergency_contact details
[Mimecast] Updates the Emergency Contact information for the account. PATCH /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: contactName, contactEmailAddress, mobilePhone, telephone, alternateEmailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Configuration snapshots
mc_create_config_snapshot details
mc_create_config_snapshot details
[Mimecast] Create a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/create. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_export_config_snapshot details
mc_export_config_snapshot details
[Mimecast] Export a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/export. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_config_snapshots details
mc_list_config_snapshots details
[Mimecast] Get the comprehensive list of configuration snapshots for the customers Mimecast settings, including those for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/list. Email Security Cloud Gateway. Send the request body as JSON (required). Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_restore_config_snapshot details
mc_restore_config_snapshot details
[Mimecast] DESTRUCTIVE: restore a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. Why this is destructive: overwrites the account's LIVE configuration with the snapshot, replacing current policy and gateway settings. POST /config-snapshot/v1/restore. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Partner (MSP)
mc_get_partner_customer details
mc_get_partner_customer details
[Mimecast] Get one managed customer. GET /partner/v1/customers/. Email Security Cloud Gateway. Path parameters: customer_account_code. MSP discovery read for a single managed customer. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_partner_customers details
mc_list_partner_customers details
[Mimecast] List managed customers. GET /partner/v1/customers. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP discovery read. Returns each managed customer's accountCode, accountName, region, seatCount, industry, customerStatus and billingType. The accountCode is what every other tool's accountCode argument takes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Archive search
mc_get_archive_file details
mc_get_archive_file details
[Mimecast] Retrieves the file or attachment for given id. POST /api/archive/get-file. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_archive_message_detail details
mc_get_archive_message_detail details
[Mimecast] Retrieves archived message details. POST /api/archive/get-message-detail. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_archive_message_list details
mc_get_archive_message_list details
[Mimecast] Retrieves archive message list. POST /api/archive/get-message-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, includeAliases, includeDelegates, mailbox, start, view. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_archive_message_part details
mc_get_archive_message_part details
[Mimecast] Retrieves the message part - HTML, plain or RFC822. POST /api/archive/get-message-part. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: context, extractFromHtml, id, mailbox, stripDangerous, stripImg, stripStyles, transposeInlineCID, type. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_search_archive details
mc_search_archive details
[Mimecast] Retrieves archive search items. POST /api/archive/search. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, query. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Data retention
mc_add_smart_tag_messages details
mc_add_smart_tag_messages details
[Mimecast] Add messages to a smart tag. POST /dataretention/v1/smart-tags//messages. Email Security Cloud Gateway. Path parameters: smartTagId. Send the request body as JSON (required). Documented body fields: messageIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_smart_tags details
mc_list_smart_tags details
[Mimecast] Get all smart tags for account. GET /dataretention/v1/smart-tags. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_search_smart_tag_messages details
mc_search_smart_tag_messages details
[Mimecast] Search for messages in a smart tag. POST /dataretention/v1/smart-tags//messages/search. Email Security Cloud Gateway. Path parameters: smartTagId. Optional filters: pageSize, pageToken. Send the request body as JSON (required). Documented body fields: startDateTime, endDateTime. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_set_message_visibility details
mc_set_message_visibility details
[Mimecast] Set message visibility. POST /dataretention/v1/messages/visibility. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: visible, messageIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_retention_adjustment details
mc_update_retention_adjustment details
[Mimecast] DESTRUCTIVE: update retention adjustment for messages. Why this is destructive: it sets retainDays for the messages the body names, and retainDays: 0 purges them from the archive immediately - Mimecast keeps no copy and StackJack cannot recover them. POST /dataretention/v1/retention-adjustment. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: messageIds, retainDays. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Archive access logs
mc_get_archive_search_logs details
mc_get_archive_search_logs details
[Mimecast] Retrieves archive search logs. POST /api/archive/get-archive-search-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: query. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_search_logs details
mc_get_search_logs details
[Mimecast] Retrieves the search logs. POST /api/archive/get-search-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, query, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_view_logs details
mc_get_view_logs details
[Mimecast] Retrieves the email view logs. POST /api/archive/get-view-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, query, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Audit events
mc_get_audit_categories details
mc_get_audit_categories details
[Mimecast] Returns the list of audit categories available. POST /api/audit/get-categories. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_audit_events details
mc_get_audit_events details
[Mimecast] Returns the audit events matching the request. POST /api/audit/get-audit-events. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: categories, endDateTime, query, startDateTime. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Delivery monitoring
mc_get_held_release_logs details
mc_get_held_release_logs details
[Mimecast] This endpoint can be used to find messages that were either released to the recipient, with details about the user that processed the release. POST /api/gateway/get-held-release-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_rejections details
mc_get_rejections details
[Mimecast] This endpoint can be used to find rejected messages and the reasons for their rejection. POST /api/gateway/get-rejections. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, mailbox, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Awareness scores
mc_get_awareness_performance_details details
mc_get_awareness_performance_details details
[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Performance details by Department and Performance Type (data displayed on Performance > Achievements. POST /api/awareness-training/company/get-performance-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, includeUserDetails, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_awareness_performance_summary details
mc_get_awareness_performance_summary details
[Mimecast] This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Performance Summary by total user answer count. POST /api/awareness-training/company/get-performance-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_awareness_safe_score_details details
mc_get_awareness_safe_score_details details
[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS SAFE Score user level details and grades, including User Risk, Human Error, Sentiment, Engagement and Knowledge. POST /api/awareness-training/company/get-safe-score-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_awareness_safe_score_summary details
mc_get_awareness_safe_score_summary details
[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training SAFE Score company-level Summary by User Count per User Risk Grade. (Data displayed on Performance > User Risk Dashboard). POST /api/awareness-training/company/get-safe-score-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_awareness_watchlist_details details
mc_get_awareness_watchlist_details details
[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Watchlist details by Department and Watchlist Type. (Data displayed on Performance > Watchlist Details). POST /api/awareness-training/company/get-watchlist-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_awareness_watchlist_summary details
mc_get_awareness_watchlist_summary details
[Mimecast] This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Watchlist Summary by total user unwatched count. POST /api/awareness-training/company/get-watchlist-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Human risk
mc_get_individual_risk_profiles details
mc_get_individual_risk_profiles details
[Mimecast] Get individual risk profiles with scores. POST /human-risk/v1/individuals/risk-profiles. Email Security Cloud Gateway. Optional filters: pageToken, pageSize, monthsBack, fields. Send the request body as JSON (required). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_organization_attacks details
mc_get_organization_attacks details
[Mimecast] Get organizational attack data. GET /human-risk/v1/organization/attacks. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_organization_behaviors details
mc_get_organization_behaviors details
[Mimecast] Get organizational behavior data. GET /human-risk/v1/organization/behaviors. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_organization_risk details
mc_get_organization_risk details
[Mimecast] Get organization risk trends. GET /human-risk/v1/organization. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_risk_departments details
mc_list_risk_departments details
[Mimecast] List departments with aggregated risk data. GET /human-risk/v1/departments. Email Security Cloud Gateway. Optional filters: orderBy, pageSize, pageToken, count. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_risk_locations details
mc_list_risk_locations details
[Mimecast] List locations with aggregated risk data. GET /human-risk/v1/locations. Email Security Cloud Gateway. Optional filters: orderBy, pageSize, pageToken, count. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_search_individuals_risk details
mc_search_individuals_risk details
[Mimecast] Search individuals with risk data. POST /human-risk/v1/individuals/search. Email Security Cloud Gateway. Optional filters: pageSize, pageToken, count, fields. Send the request body as JSON (optional). Documented body fields: filters, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Phishing campaigns
mc_get_phishing_campaign details
mc_get_phishing_campaign details
[Mimecast] This API endpoint can be used to get all campaign-level information on Awareness Training Mime | OS Phishing Campaigns created, both pending and launched. (Data displayed on Phishing > Campaigns). POST /api/awareness-training/phishing/campaign/get-campaign. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_phishing_campaign_user_data details
mc_get_phishing_campaign_user_data details
[Mimecast] This API endpoint can be used to get an aggregated summary of Awareness Training Mime | OS Phishing Campaigns grouped by recipient email address. POST /api/awareness-training/phishing/campaign/get-user-data. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, id, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Training queue and users
mc_get_awareness_queue details
mc_get_awareness_queue details
[Mimecast] This API endpoint can be used to get all module-level information on Awareness Training Mime | OS Training Modules created, both pending and launched. POST /api/awareness-training/queue/get-queue. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_user_training_details details
mc_get_user_training_details details
[Mimecast] This API endpoint can be used to get user enrollment and completion information on Awareness Training Mime | OS Training Modules. POST /api/awareness-training/user/get-training-details. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Administrator roles
mc_list_admin_roles details
mc_list_admin_roles details
[Mimecast] Retrieves a list of roles for the account. Filterable by role Name. GET /role/cloud-gateway/v1/roles. Email Security Cloud Gateway. Optional filters: roleName, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Directory connections
mc_create_ad_integration details
mc_create_ad_integration details
[Mimecast] Creates a new directory integration for Active Directory. POST /directory/cloud-gateway/v1/integrations/active-directory. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, info, domains, hostname, alternateHostname, port, userDn, password, rootDn, encryptionMode, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_directory_sync_request details
mc_create_directory_sync_request details
[Mimecast] Requests a sync of all directory integrations for account. POST /directory/cloud-gateway/v1/integrations/sync-requests. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: action. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_google_integration details
mc_create_google_integration details
[Mimecast] Creates a new directory integration for Google. POST /directory/cloud-gateway/v1/integrations/google. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: enabled, description, info, domains, maxUnlink, deleteUsers, acknowledgeDisabledAccounts, user, key. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_m365_integration details
mc_create_m365_integration details
[Mimecast] Creates a new directory integration for M365. POST /directory/cloud-gateway/v1/integrations/m365. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, info, domains, connectorId, tenantDomain, serverSubtype, syncGuestUsers, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts, deleteUsers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_ad_integration details
mc_delete_ad_integration details
[Mimecast] DESTRUCTIVE: deletes an Active Directory directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_google_integration details
mc_delete_google_integration details
[Mimecast] DESTRUCTIVE: deletes a Google directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_m365_integration details
mc_delete_m365_integration details
[Mimecast] DESTRUCTIVE: deletes a M365 directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_execute_directory_sync details
mc_execute_directory_sync details
[Mimecast] This endpoint can be used to initiate directory synchronization. POST /api/directory/execute-sync. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ad_integration details
mc_get_ad_integration details
[Mimecast] Gets an Active Directory directory integration. GET /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_directory_connection details
mc_get_directory_connection details
[Mimecast] This endpoint can be used to retrieve directory connectors that are configured on the tenant. POST /api/directory/get-connection. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_google_integration details
mc_get_google_integration details
[Mimecast] Gets a Google directory integration. GET /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_m365_integration details
mc_get_m365_integration details
[Mimecast] Gets a M365 directory integration. GET /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_directory_integrations details
mc_list_directory_integrations details
[Mimecast] Gets all (m365, google, ldap) directory integrations for account. GET /directory/cloud-gateway/v1/integrations. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_authentication details
mc_test_ad_authentication details
[Mimecast] Tests if Active directory integration can authenticate. POST /directory/cloud-gateway/v1/integrations/active-directory//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_certificates details
mc_test_ad_certificates details
[Mimecast] Tests the certificates of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-certificates. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_connectivity details
mc_test_ad_connectivity details
[Mimecast] Tests the connectivity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_egress_connectivity details
mc_test_ad_egress_connectivity details
[Mimecast] Tests the Egress connectivity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-egress-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_email details
mc_test_ad_email details
[Mimecast] Tests if an Active Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/active-directory//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_ad_validation details
mc_test_ad_validation details
[Mimecast] Tests the validity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-validation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_google_authentication details
mc_test_google_authentication details
[Mimecast] Tests a Google directory authentication. POST /directory/cloud-gateway/v1/integrations/google//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_google_authorization details
mc_test_google_authorization details
[Mimecast] Tests a Google directory has the correct authorised permission set. POST /directory/cloud-gateway/v1/integrations/google//test-authorisation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_google_connectivity details
mc_test_google_connectivity details
[Mimecast] Tests the connectivity of a Google directory integration. POST /directory/cloud-gateway/v1/integrations/google//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_google_email details
mc_test_google_email details
[Mimecast] Tests if a Google Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/google//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_m365_authentication details
mc_test_m365_authentication details
[Mimecast] Tests a Microsoft 365 directory authentication. POST /directory/cloud-gateway/v1/integrations/m365//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_m365_authorization details
mc_test_m365_authorization details
[Mimecast] Tests a M365 directory has the correct authorised permission set. POST /directory/cloud-gateway/v1/integrations/m365//test-authorisation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_m365_connectivity details
mc_test_m365_connectivity details
[Mimecast] Tests the connectivity of a Microsoft 365 directory integration. POST /directory/cloud-gateway/v1/integrations/m365//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_m365_connector details
mc_test_m365_connector details
[Mimecast] Tests the connector associated to a M365 directory authorisation. POST /directory/cloud-gateway/v1/integrations/m365//test-connector. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_test_m365_email details
mc_test_m365_email details
[Mimecast] Tests if a Microsoft 365 Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/m365//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_ad_integration details
mc_update_ad_integration details
[Mimecast] Updates an Active Directory directory integration. PATCH /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: description, info, domains, hostname, alternateHostname, port, userDn, password, rootDn, encryptionMode, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_google_integration details
mc_update_google_integration details
[Mimecast] Updates a Google directory integration. PATCH /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: acknowledgeDisabledAccounts, enabled, description, info, domains, maxUnlink, deleteUsers, user, key. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_m365_integration details
mc_update_m365_integration details
[Mimecast] Updates an M365 directory integration. PATCH /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: description, info, domains, connectorId, tenantDomain, serverSubtype, syncGuestUsers, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts, deleteUsers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Groups
mc_add_group_member_mx details
mc_add_group_member_mx details
[Mimecast] This endpoint can be used to add user email addresses or domains to a profile group. POST /api/directory/add-group-member. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, emailAddress, id, notes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_add_group_members details
mc_add_group_members details
[Mimecast] This endpoint can be used to add user email addresses or domains to a profile group. POST /directory/cloud-gateway/v1/groups//members. Email Security Cloud Gateway. Path parameters: group_id. Send the request body as JSON (required). Documented body fields: groupMembers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_group details
mc_create_group details
[Mimecast] Creates a new Profile Groups at the root level, or as a child-group. POST /directory/cloud-gateway/v1/groups. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_group_mx details
mc_create_group_mx details
[Mimecast] This API endpoint can be used to create new Profile Groups at the root level, or as a child-group. Groups can be used to apply permissions and policies. POST /api/directory/create-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_group_mx details
mc_delete_group_mx details
[Mimecast] DESTRUCTIVE: this endpoint can be used to delete an exiting profile group. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/directory/delete-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_find_groups details
mc_find_groups details
[Mimecast] This endpoint can be used to find groups that exist on a tenant. POST /api/directory/find-groups. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: query, source. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_group details
mc_get_group details
[Mimecast] This endpoint can be used to get a profile group from a tenant. GET /directory/cloud-gateway/v1/groups/. Email Security Cloud Gateway. Path parameters: group_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_group_members_mx details
mc_get_group_members_mx details
[Mimecast] This endpoint can be used to retrieve group members from groups the exist on a tenant. POST /api/directory/get-group-members. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_group_members details
mc_list_group_members details
[Mimecast] This endpoint can be used to get group members from a tenant. GET /directory/cloud-gateway/v1/groups//members. Email Security Cloud Gateway. Path parameters: group_id. Optional filters: domain, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_groups details
mc_list_groups details
[Mimecast] This endpoint can be used to find groups that exist on a tenant. GET /directory/cloud-gateway/v1/groups. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remove_group_member_mx details
mc_remove_group_member_mx details
[Mimecast] DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/directory/remove-group-member. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, emailAddress, id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remove_group_members details
mc_remove_group_members details
[Mimecast] DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups. Why this is destructive: removes the member, alias or delegate named in the request. POST /directory/cloud-gateway/v1/groups//remove-members. Email Security Cloud Gateway. Path parameters: group_id. Send the request body as JSON (required). Documented body fields: groupMembers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_group_mx details
mc_update_group_mx details
[Mimecast] The update group endpoint can be used to update the description of Mimecast Profile groups. POST /api/directory/update-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, id, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Users
mc_add_delegate_user details
mc_add_delegate_user details
[Mimecast] This API endpoint provides the ability to create a new delegate permission for a user based on their primary address. More information about delegates is available in Mimecaster Central. POST /api/user/add-delegate-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: delegateAddress, primaryAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_add_user_to_purge_list details
mc_add_user_to_purge_list details
[Mimecast] DESTRUCTIVE: this endpoint can be used to add internal or external users to the Purge List. The Purge List gets examined each evening as part of the nightly housekeeping tasks. Why this is destructive: queues the mailbox for purge; Mimecast removes its retained mail. POST /api/user/add-to-purge-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_user details
mc_create_user details
[Mimecast] This endpoint allows the creation of a new user within the account. POST /user/cloud-gateway/v1/users. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: accountCode, emailAddress, name, password, forcePasswordChange. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_user_mx details
mc_create_user_mx details
[Mimecast] This endpoint can be used to create new cloud-users in Mimecast's Internal Directories. POST /api/user/create-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountCode, emailAddress, forcePasswordChange, name, password. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_find_attribute_types details
mc_find_attribute_types details
[Mimecast] This API endpoint can be used to find account attribute types. POST /api/attribute/find-attribute-types. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_find_delegate_users details
mc_find_delegate_users details
[Mimecast] This API endpoint provides the ability to return delegate permissions for a user based on their primary address. More information about delegates is availabile in Mimecaster Central. POST /api/user/find-delegate-users. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: primaryAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_internal_users details
mc_get_internal_users details
[Mimecast] This endpoint can be used to retrieve all internal users for a given domain. POST /api/user/get-internal-users. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_most_used_contacts details
mc_get_most_used_contacts details
[Mimecast] This endpoint returns the most used contacts synced from Azure Active Directory. POST /api/user/get-most-used-contacts. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_user_aliases details
mc_get_user_aliases details
[Mimecast] The get aliases endpoint can be used to retrieve aliases associated with a primary email address. POST /api/user/get-aliases. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_user_attributes details
mc_get_user_attributes details
[Mimecast] This endpoint can be used to retrieve attributes that are registered on the tenant, for a given user. POST /api/user/get-attributes. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_user_import_status details
mc_get_user_import_status details
[Mimecast] This endpoint can the used to get the current status of a user import request, using /api/user/import-users. POST /api/user/get-import-status. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_import_users details
mc_import_users details
[Mimecast] DESTRUCTIVE: the import users endpoint can be used to import users to an Internal Directory or a Profile Group. Why this is destructive: the x-mc-arg options include clearGroup, which EMPTIES the target Profile Group before the import runs - every member is taken out of the group and Mimecast keeps no copy, so a policy scoped to that group stops applying to anyone the import does not put back. POST /api/user/import-users. Email Security Cloud Gateway, MX-based deployments only. THE BODY IS THE FILE ITSELF, not a JSON payload: provide the import EITHER as CSV content in csvText OR as an XLS/XLSX workbook in contentBase64 or sourceUrl - exactly one of the two forms, never both and never neither. StackJack downloads an https URL server-side and refuses anything over 25 MB, a non-https URL, or a redirect to a different host. The import options travel in the x-mc-arg header, not in the body. This route is NOT one of Mimecast's legacy paginated routes despite its /api/ prefix: it takes no data array and no meta.pagination, and dataJson is refused for that reason. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_users details
mc_list_users details
[Mimecast] Get internal users for account. GET /user/cloud-gateway/v1/users. Email Security Cloud Gateway. Optional filters: emailAddress, domain, includeAliases, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remove_delegate_user details
mc_remove_delegate_user details
[Mimecast] DESTRUCTIVE: this API endpoint provides the ability to remove delegate permissions for a user based on their primary address. More information about delegates is availabile in Mimecaster Central. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/user/remove-delegate-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remove_user_alias details
mc_remove_user_alias details
[Mimecast] DESTRUCTIVE: the remove alias endpoint can be used to remove a alias that has been associated with a primary email address. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/user/remove-alias. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: alias, aliasFor. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remove_user_from_purge_list details
mc_remove_user_from_purge_list details
[Mimecast] DESTRUCTIVE: this endpoint can be used to remove internal or external users from the Purge List in case you added them by accident. Why this is destructive: changes retention for a mailbox already queued for purge. POST /api/user/remove-from-purge-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_user details
mc_update_user details
[Mimecast] The update user endpoint can be used to update users within an Internal Directory. POST /api/user/update-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountDisabled, accountLocked, allowPop, allowSmtp, archiveStartDate, emailAddress, forcePasswordChange, name, password, passwordNeverExpires. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_user_alias details
mc_update_user_alias details
[Mimecast] This API endpoint can be used to modify secondary email addresses for users. POST /api/user/update-alias. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: alias, aliasFor. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_user_attributes details
mc_update_user_attributes details
[Mimecast] This API endpoint can be used to update a non-directory synced user's attributes. POST /api/user/update-attributes. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributes, emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC DNS checks
mc_check_dmarc_dns_bimi details
mc_check_dmarc_dns_bimi details
[Mimecast] Get BIMI record check. GET /dmarc-analyzer/v1/dns/bimi. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_check_dmarc_dns_dkim details
mc_check_dmarc_dns_dkim details
[Mimecast] Get DKIM record check. GET /dmarc-analyzer/v1/dns/dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_check_dmarc_dns_dmarc details
mc_check_dmarc_dns_dmarc details
[Mimecast] Get DMARC record check. GET /dmarc-analyzer/v1/dns/dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_check_dmarc_dns_spf details
mc_check_dmarc_dns_spf details
[Mimecast] Get SPF record check. GET /dmarc-analyzer/v1/dns/spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: record. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC delegated domains
mc_create_dmarc_delegated_dkim_selector details
mc_create_dmarc_delegated_dkim_selector details
[Mimecast] Create a DKIM definition. POST /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: sourceId, version, selector, recordType, hostname, publicKey, serviceType, notes, flags. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_dmarc_delegated_dmarc_record details
mc_create_dmarc_delegated_dmarc_record details
[Mimecast] Create a DMARC definition. POST /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: dmarcPolicyPresetId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_dmarc_delegated_domain details
mc_create_dmarc_delegated_domain details
[Mimecast] Create a delegated domain entry. POST /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: items. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_delegated_dkim_all details
mc_delete_dmarc_delegated_dkim_all details
[Mimecast] DESTRUCTIVE: delete all DKIM delegation for a domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_delegated_dkim_selector details
mc_delete_dmarc_delegated_dkim_selector details
[Mimecast] DESTRUCTIVE: delete DKIM definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_delegated_dmarc_record details
mc_delete_dmarc_delegated_dmarc_record details
[Mimecast] DESTRUCTIVE: delete DMARC definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_delegated_domains_bulk details
mc_delete_dmarc_delegated_domains_bulk details
[Mimecast] DESTRUCTIVE: delete delegated domains. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_delegated_spf_record details
mc_delete_dmarc_delegated_spf_record details
[Mimecast] DESTRUCTIVE: delete SPF definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_dkim_details details
mc_get_dmarc_delegated_dkim_details details
[Mimecast] Get DKIM delegation details. GET /dmarc-analyzer/v1/delegated-domains//dkim/details. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_dkim_selector details
mc_get_dmarc_delegated_dkim_selector details
[Mimecast] Get a DKIM definition. GET /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_dmarc_record details
mc_get_dmarc_delegated_dmarc_record details
[Mimecast] Get DMARC definition. GET /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_domain_statistics details
mc_get_dmarc_delegated_domain_statistics details
[Mimecast] Get delegated domains statistics. GET /dmarc-analyzer/v1/delegated-domains/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_spf_details details
mc_get_dmarc_delegated_spf_details details
[Mimecast] Get SPF definition details. GET /dmarc-analyzer/v1/delegated-domains//spf/details. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_delegated_spf_record details
mc_get_dmarc_delegated_spf_record details
[Mimecast] Get SPF definition. GET /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_delegated_dkim_selectors details
mc_list_dmarc_delegated_dkim_selectors details
[Mimecast] List DKIM definitions. GET /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Optional filters: pageSize, pageToken, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_delegated_domains details
mc_list_dmarc_delegated_domains details
[Mimecast] Get delegated domains. GET /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, domain, domainDelegationStatus, dmarcDelegationStatus, dmarcPolicy, dkimDelegationStatus, spfDelegationStatus. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_dmarc_delegated_dkim_selector details
mc_replace_dmarc_delegated_dkim_selector details
[Mimecast] DESTRUCTIVE: update a DKIM definition. Why this is destructive: wholesale replace - the body becomes the whole DKIM definition for that selector, so a wrong or omitted public key stops mail signed with it authenticating. PUT /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. Send the request body as JSON (required). Documented body fields: sourceId, version, selector, recordType, hostname, publicKey, serviceType, notes, flags. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_dmarc_delegated_spf_record details
mc_replace_dmarc_delegated_spf_record details
[Mimecast] DESTRUCTIVE: update the SPF definition. Why this is destructive: wholesale replace - the body becomes the delegated domain's ENTIRE published SPF record and `terms` is optional, so a body without it publishes a record that authorizes no sending source at all and every legitimate sender starts failing SPF. PUT /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: version, terms, allQualifier. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC detected domains
mc_list_dmarc_detected_domains details
mc_list_dmarc_detected_domains details
[Mimecast] Get detected domains. GET /dmarc-analyzer/v1/detected-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, domain, acceptanceStatus, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_set_dmarc_detected_domain_status details
mc_set_dmarc_detected_domain_status details
[Mimecast] Update detected domain status. PUT /dmarc-analyzer/v1/detected-domains//status. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_detected_domains details
mc_update_dmarc_detected_domains details
[Mimecast] Batch update detected domains status. PATCH /dmarc-analyzer/v1/detected-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: ids, status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC domain groups
mc_create_dmarc_domain_group details
mc_create_dmarc_domain_group details
[Mimecast] Create a domain group. POST /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: name, type, doesAutoIncludeOrgSubdomains, includeDomainsWithStatus, includedDomains, includeDomainsRegex. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_dmarc_domain_group_association details
mc_create_dmarc_domain_group_association details
[Mimecast] Add domains to domain group. POST /dmarc-analyzer/v1/domain-groups//association. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_domain_group_association details
mc_delete_dmarc_domain_group_association details
[Mimecast] DESTRUCTIVE: remove domains from domain group. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domain-groups//association. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_domain_groups_bulk details
mc_delete_dmarc_domain_groups_bulk details
[Mimecast] DESTRUCTIVE: delete domain groups. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_domain_group details
mc_get_dmarc_domain_group details
[Mimecast] Get a domain group. GET /dmarc-analyzer/v1/domain-groups/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Optional filters: filterOnActivityStatus. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_domain_groups details
mc_list_dmarc_domain_groups details
[Mimecast] Get domain groups. GET /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, ids, orderBy, filterOnActivityStatus, includeDomainsCount. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_domain_group details
mc_update_dmarc_domain_group details
[Mimecast] DESTRUCTIVE: update a domain group. Why this is destructive: wholesale replace - includedDomains, includeDomainsWithStatus and includeDomainsRegex become exactly what the body carries, so a domain left out drops out of the group and every report, notification and policy scoped to that group stops covering it. PUT /dmarc-analyzer/v1/domain-groups/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: name, type, doesAutoIncludeOrgSubdomains, includeDomainsWithStatus, includedDomains, includeDomainsRegex. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC domains
mc_create_dmarc_domain details
mc_create_dmarc_domain details
[Mimecast] Create a managed domain entry. POST /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: items. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_domains_bulk details
mc_delete_dmarc_domains_bulk details
[Mimecast] DESTRUCTIVE: delete domains. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_domain details
mc_get_dmarc_domain details
[Mimecast] Get a managed domain. GET /dmarc-analyzer/v1/domains/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_domain_statistics details
mc_get_dmarc_domain_statistics details
[Mimecast] Get managed domain statistics. GET /dmarc-analyzer/v1/domains/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_domains details
mc_list_dmarc_domains details
[Mimecast] Get managed domains. GET /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, domain, domains, ids, group, filterOnActivityStatus, activityStatus, status, dmarcPolicy, dmarcStatus, dmarcDelegation, dkimStatus, dkimDelegation, spfStatus, spfDelegation, dnsDelegation, presetFilter, createdAt. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_vendor_configurations details
mc_list_dmarc_vendor_configurations details
[Mimecast] Get domain vendor configurations. GET /dmarc-analyzer/v1/domains/vendor-configurations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: domainIds, domains. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_refresh_dmarc_domain_dns details
mc_refresh_dmarc_domain_dns details
[Mimecast] Refresh managed domain DNS records. POST /dmarc-analyzer/v1/domains//refresh-dns. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_domain details
mc_update_dmarc_domain details
[Mimecast] Update managed domain activity status. PATCH /dmarc-analyzer/v1/domains/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Mimecast applies this body as an RFC 7386 merge patch (Content-Type application/merge-patch+json), so a field you omit is left unchanged and a field you set to null is REMOVED - null is not the same as omitting it. Documented body fields: activityStatus. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC policy presets
mc_create_dmarc_policy_preset details
mc_create_dmarc_policy_preset details
[Mimecast] DESTRUCTIVE: create a new DMARC policy preset. Why this is destructive: a DMARC policy preset is applied to managed domains, and a preset at p=reject tells receiving mail servers to DISCARD mail that fails authentication - misconfigured, it stops legitimate mail being delivered. POST /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: version, policy, subdomainPolicy, ruaAddresses, rufAddresses, dkimAlignment, spfAlignment, reportInterval, failureReportingOptions, failureReportFormat, percentage, name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_policy_presets_bulk details
mc_delete_dmarc_policy_presets_bulk details
[Mimecast] DESTRUCTIVE: delete a DMARC policy preset by ID. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_policy_presets details
mc_list_dmarc_policy_presets details
[Mimecast] Get DMARC policy presets. GET /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, id, name, policy, subdomainPolicy, dkimAlignment, spfAlignment, orderBy, isDefaultPolicy, failureReportingOptions, ruaEmails, rufEmails. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_policy_preset details
mc_update_dmarc_policy_preset details
[Mimecast] DESTRUCTIVE: update a DMARC policy preset by ID. Why this is destructive: wholesale replace of a DMARC policy preset already applied to managed domains - moving it to p=reject tells receiving mail servers to DISCARD mail that fails authentication, and anything omitted from the body is cleared. PUT /dmarc-analyzer/v1/dmarc-policy-preset/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: presetId. Send the request body as JSON (required). Documented body fields: version, policy, subdomainPolicy, ruaAddresses, rufAddresses, dkimAlignment, spfAlignment, reportInterval, failureReportingOptions, failureReportFormat, percentage, name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC compliance
mc_get_dmarc_compliance_statistics details
mc_get_dmarc_compliance_statistics details
[Mimecast] Get DMARC compliance statistics. GET /dmarc-analyzer/v1/compliance/dmarc/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: domainIds, groupIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_dns_suggestions details
mc_list_dmarc_dns_suggestions details
[Mimecast] Get DNS configuration suggestions for all domains. GET /dmarc-analyzer/v1/compliance/domains/dns-suggestions. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_enforcement details
mc_list_dmarc_enforcement details
[Mimecast] Get domains eligible for DMARC policy enforcement. GET /dmarc-analyzer/v1/compliance/domains/enforcement. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_policy_changes details
mc_list_dmarc_policy_changes details
[Mimecast] Get DMARC policy changes from data platform. GET /dmarc-analyzer/v1/compliance/domains/dmarc-policy-changes. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC customer settings
mc_delete_dmarc_encryption_key details
mc_delete_dmarc_encryption_key details
[Mimecast] DESTRUCTIVE: delete customer PGP key. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_customer details
mc_get_dmarc_customer details
[Mimecast] Get customer details. GET /dmarc-analyzer/v1/customers/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: identifier. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_encryption_key details
mc_get_dmarc_encryption_key details
[Mimecast] Get customer PGP key. GET /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_dmarc_encryption_key details
mc_replace_dmarc_encryption_key details
[Mimecast] DESTRUCTIVE: save customer PGP key. Why this is destructive: wholesale replace of the PGP key Mimecast encrypts this customer's forensic reports to - reports already delivered stay encrypted to the old key, so replacing it silently breaks decryption for everything that arrives afterwards unless the matching private key is in place. PUT /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: type, key, expiryTimestamp. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC events and issues
mc_delete_dmarc_issues_bulk details
mc_delete_dmarc_issues_bulk details
[Mimecast] DESTRUCTIVE: delete issues. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/issues. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_events details
mc_list_dmarc_events details
[Mimecast] Get events. GET /dmarc-analyzer/v1/events. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, startDate, endDate, domainId, group, eventType, recordType, handle. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_issues details
mc_list_dmarc_issues details
[Mimecast] Get issues. GET /dmarc-analyzer/v1/issues. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, ids, domainId, domain, group, recordType. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC notifications
mc_create_dmarc_notification details
mc_create_dmarc_notification details
[Mimecast] Create notification. POST /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: type. Send the request body as JSON (required). Documented body fields: email, frequency, domains, groups, triggerConfig. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_notifications_bulk details
mc_delete_dmarc_notifications_bulk details
[Mimecast] DESTRUCTIVE: delete a notification. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/notifications. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_notification details
mc_get_dmarc_notification details
[Mimecast] Get a notification. GET /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_notifications details
mc_list_dmarc_notifications details
[Mimecast] List notifications. GET /dmarc-analyzer/v1/notifications. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, type, ids, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_notification details
mc_update_dmarc_notification details
[Mimecast] DESTRUCTIVE: update a notification. Why this is destructive: wholesale replace - domains, groups and triggerConfig become exactly what the body carries, so a domain or group left out stops being notified and nobody is told that DMARC failures on it went unreported. PUT /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: email, frequency, domains, groups, triggerConfig. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC reports
mc_download_dmarc_forensic_report details
mc_download_dmarc_forensic_report details
[Mimecast] Download a DMARC forensic (failure) report. GET /dmarc-analyzer/v1/reports/forensic/download. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. This is the only Mimecast endpoint that answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a TEMPORARY read-only download link, valid for 30 minutes), contentType, suggestedFileName, sizeBytes and expiresAt; expiresAt is the link's real expiry, not a restated duration. Fetch the link before it expires - nothing else in StackJack keeps a copy. The report itself is ENCRYPTED to the PGP key stored for the customer (mc_get_dmarc_encryption_key reads it), so the downloaded file is ciphertext unless no key is configured; StackJack cannot decrypt it. Requires the DMARC Analyzer product with report read permission. MSP: pass accountCode to act on a managed customer; omit it to act on your own account.
mc_get_dmarc_report_results details
mc_get_dmarc_report_results details
[Mimecast] Get paginated report results. GET /dmarc-analyzer/v1/reports//results/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id, handle. Optional filters: pageToken, pageSize. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_report_metadata details
mc_list_dmarc_report_metadata details
[Mimecast] Get report metadata. GET /dmarc-analyzer/v1/report-metadata. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_query_dmarc_report details
mc_query_dmarc_report details
[Mimecast] Query report data. POST /dmarc-analyzer/v1/reports/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Optional filters: pageSize, domainGroupIds. Send the request body as JSON (required). Paging: pageSize (default 50) travels in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. This route takes no pageToken: it answers meta.handle and meta.nextPage, and mc_get_dmarc_report_results walks the pages from them. Documented body fields: timestampRangeStartsAt, timestampRangeEndsAt, projections, searchClause, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC sources
mc_create_dmarc_source_vendor_association details
mc_create_dmarc_source_vendor_association details
[Mimecast] Associate a vendor with a customer. POST /dmarc-analyzer/v1/sources/vendors/associations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_source_vendor_association details
mc_delete_dmarc_source_vendor_association details
[Mimecast] DESTRUCTIVE: delete vendor association. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/sources/vendors/associations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_source_compliance_statistics details
mc_get_dmarc_source_compliance_statistics details
[Mimecast] Get source compliance statistics. GET /dmarc-analyzer/v1/sources/compliance/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_source_vendor details
mc_get_dmarc_source_vendor details
[Mimecast] Get a single vendor. GET /dmarc-analyzer/v1/sources/vendors/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_source_compliance_actions details
mc_list_dmarc_source_compliance_actions details
[Mimecast] Get compliance actions. GET /dmarc-analyzer/v1/sources/compliance/actions. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_source_vendors details
mc_list_dmarc_source_vendors details
[Mimecast] Get vendors. GET /dmarc-analyzer/v1/sources/vendors. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, ids, category, includeArchived, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_sources details
mc_list_dmarc_sources details
[Mimecast] Get sources. GET /dmarc-analyzer/v1/sources. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, hostnames, category, includeArchived, ids, status, createdAt, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_source_vendor details
mc_update_dmarc_source_vendor details
[Mimecast] Update vendor status. PATCH /dmarc-analyzer/v1/sources/vendors/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Mimecast applies this body as an RFC 7386 merge patch (Content-Type application/merge-patch+json), so a field you omit is left unchanged and a field you set to null is REMOVED - null is not the same as omitting it. Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC tasks
mc_create_dmarc_task details
mc_create_dmarc_task details
[Mimecast] Create a new task. POST /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: title, type, status, description, entities. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_tasks_bulk details
mc_delete_dmarc_tasks_bulk details
[Mimecast] DESTRUCTIVE: delete or archive tasks. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_task details
mc_get_dmarc_task details
[Mimecast] Get a task by ID. GET /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_task_summary details
mc_get_dmarc_task_summary details
[Mimecast] Get task summary by status. GET /dmarc-analyzer/v1/tasks/summary. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: archived. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_tasks details
mc_list_dmarc_tasks details
[Mimecast] Get all tasks (paginated). GET /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, ids, title, type, status, archived. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_dmarc_task details
mc_replace_dmarc_task details
[Mimecast] DESTRUCTIVE: update a task. Why this is destructive: wholesale replace - Mimecast publishes a PATCH twin on this same path for partial edits, so the PUT body becomes the WHOLE task and a title, status, description, type or entity left out of it is gone. PUT /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: title, status, description, type, entities. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_task details
mc_update_dmarc_task details
[Mimecast] Partially update a task. PATCH /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DMARC users
mc_create_dmarc_user details
mc_create_dmarc_user details
[Mimecast] Add a new user. POST /dmarc-analyzer/v1/users. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: userName, userEmail, userPermission, allowedGroups, features. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dmarc_user details
mc_delete_dmarc_user details
[Mimecast] DESTRUCTIVE: delete a user. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_current_user details
mc_get_dmarc_current_user details
[Mimecast] Get current user. GET /dmarc-analyzer/v1/users/current-user. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dmarc_user details
mc_get_dmarc_user details
[Mimecast] Get user details. GET /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: idOrEmail. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dmarc_users details
mc_list_dmarc_users details
[Mimecast] Get all user details (paginated). GET /dmarc-analyzer/v1/users. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, email, name, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dmarc_user details
mc_update_dmarc_user details
[Mimecast] DESTRUCTIVE: update a user. Why this is destructive: a privilege change - userPermission, allowedGroups and features are replaced wholesale, so a permission omitted from the body is taken away from that DMARC Analyzer user. PUT /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: userPermission, allowedGroups, features. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Domain onboarding
mc_create_domain details
mc_create_domain details
[Mimecast] This endpoint can be used to add new domains to your Mimecast account. POST /api/domain/create-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_pending_domain details
mc_create_pending_domain details
[Mimecast] Creates one or more “pending” domains that must be verified. Multiple domains created will all share the same verification token. POST /domain/cloud-gateway/v1/pending-domains. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_pending_domain details
mc_delete_pending_domain details
[Mimecast] DESTRUCTIVE: deletes an unverified domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /domain/cloud-gateway/v1/pending-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_pending_domain_mx details
mc_delete_pending_domain_mx details
[Mimecast] DESTRUCTIVE: delete a pending domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/domain/delete-pending-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_generate_pending_domain_token details
mc_generate_pending_domain_token details
[Mimecast] Returns the code to be added to TXT records of the new domain and also extends the expiry of the code to 30 days from the time of the request. POST /domain/cloud-gateway/v1/pending-domains/generate-token. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_pending_domain details
mc_get_pending_domain details
[Mimecast] Gets a single pending domain. GET /domain/cloud-gateway/v1/pending-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_pending_domain_mx details
mc_get_pending_domain_mx details
[Mimecast] Retrieve pending domain information. POST /api/domain/get-pending-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_provision_status details
mc_get_provision_status details
[Mimecast] Retrieve provisioning status for a pending domain. POST /api/domain/get-provision-status. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_verification_code details
mc_get_verification_code details
[Mimecast] Retrieve verification code for a pending domain. POST /api/domain/get-verification-code. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_pending_domains details
mc_list_pending_domains details
[Mimecast] Gets all pending domains. Additional Information Pending domains will return the verification token in the response but it will NOT be updated. GET /domain/cloud-gateway/v1/pending-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_verify_domain details
mc_verify_domain details
[Mimecast] Verify a pending domain. POST /api/domain/verify-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_verify_pending_domain details
mc_verify_pending_domain details
[Mimecast] Verifies a pending domain via TXT record and moves it from pending to registered. POST /domain/cloud-gateway/v1/pending-domains/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
External domains
mc_get_external_domain details
mc_get_external_domain details
[Mimecast] Gets a single external domain. GET /domain/cloud-gateway/v1/external-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_external_domains details
mc_list_external_domains details
[Mimecast] Gets a list all external domains. GET /domain/cloud-gateway/v1/external-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Internal domains
mc_get_internal_domain details
mc_get_internal_domain details
[Mimecast] Gets a single internal domain. GET /domain/cloud-gateway/v1/internal-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_internal_domain_dns_records details
mc_get_internal_domain_dns_records details
[Mimecast] Returns the DNS record lookup for internal domain. GET /domain/cloud-gateway/v1/internal-domains//dns-records/. Email Security Cloud Gateway. Path parameters: domain_id, record_type. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_internal_domain_mx details
mc_get_internal_domain_mx details
[Mimecast] Retrieve internal domain information. POST /api/domain/get-internal-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_internal_domains details
mc_list_internal_domains details
[Mimecast] Gets a list all internal domains. GET /domain/cloud-gateway/v1/internal-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_lookup_m365_internal_domains details
mc_lookup_m365_internal_domains details
[Mimecast] Returns domains from the Microsoft 365 tenant linked to the specified M365 directory integration instance. GET /domain/cloud-gateway/v1/internal-domains/m365//lookup. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_register_m365_internal_domains details
mc_register_m365_internal_domains details
[Mimecast] Registers one or more internal domains from the Microsoft 365 tenant associated with the specified M365 directory integration instance. POST /domain/cloud-gateway/v1/internal-domains/m365//register. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_internal_domain details
mc_update_internal_domain details
[Mimecast] Updates an internal domain. PATCH /domain/cloud-gateway/v1/internal-domains/. Email Security Cloud Gateway. Path parameters: domain_id. Send the request body as JSON (required). Documented body fields: inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_verify_internal_domain details
mc_verify_internal_domain details
[Mimecast] The Api endpoint checks all the internal domains to ensure the customer has updated their MX records correctly. POST /domain/cloud-gateway/v1/internal-domains/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Protection mode
mc_update_protection_mode details
mc_update_protection_mode details
[Mimecast] Updates the account protection mode (gateway or gatewayless). PATCH /email/cloud-gateway/v1/protection-mode. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: mode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Gateway configuration
mc_delete_outbound_ip_addresses details
mc_delete_outbound_ip_addresses details
[Mimecast] DESTRUCTIVE: deletes all outbound IP Addresses for customer’s mail platform. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_email_statistics details
mc_get_email_statistics details
[Mimecast] This endpoint can be used to the email statistics for an account.This can used to check that mail delivery is working. GET /email/cloud-gateway/v1/statistics. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_gateway_details details
mc_get_gateway_details details
[Mimecast] Returns outbound config information such as hostnames, mail platform(s). Additionally, it also returns SPF record and inbound MX Record used by the customer. GET /email/cloud-gateway/v1/gateway-details. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_outbound_ip_addresses details
mc_list_outbound_ip_addresses details
[Mimecast] Gets list of all outbound IP Addresses for customer’s mail platform. GET /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_replace_outbound_ip_addresses details
mc_replace_outbound_ip_addresses details
[Mimecast] DESTRUCTIVE: replaces all outbound IP Addresses for customer’s mail platform. Why this is destructive: wholesale replace - the body becomes the entire outbound IP allow list, so any address omitted from it stops being able to send mail through Mimecast. PUT /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: outboundIpAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_gateway_details details
mc_update_gateway_details details
[Mimecast] Updates outbound config information such as Outbound enabled flag mail platform(s), updates umbrella accounts when mail platform is M365, GSuite or Google workspace. PATCH /email/cloud-gateway/v1/gateway-details. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: outboundEnabled, outboundIpAddresses, mailPlatform. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Held messages
mc_find_held_messages details
mc_find_held_messages details
[Mimecast] This API endpoint can be used to find messages currently held for review, including the hold reason, hold group, policy information, sender and recipients. POST /api/gateway/find-held-messages. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, filterBy, mailbox, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_hold_message_list details
mc_get_hold_message_list details
[Mimecast] This API endpoint can be used to get information about held messages, including the reason, hold level, sender and recipients. POST /api/gateway/get-hold-message-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_hold_summary_list details
mc_get_hold_summary_list details
[Mimecast] This API endpoint can be used to get counts of currently held messages for each hold reason. Hold reasons can reference policy actions or definition names. POST /api/gateway/get-hold-summary-list. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_reject_held_messages details
mc_reject_held_messages details
[Mimecast] DESTRUCTIVE: this API endpoint can be used to reject a currently held message based on the Find Held Messages API endpoint. Why this is destructive: the held message is discarded and the sender is notified that it was rejected. POST /api/gateway/hold-reject. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: ids, message, notify, reasonType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_release_held_messages details
mc_release_held_messages details
[Mimecast] DESTRUCTIVE: this API endpoint can be used to release a currently held message based on the Find Held Messages API endpoint. Why this is destructive: a released message is delivered to the recipient's mailbox immediately and cannot be recalled. POST /api/gateway/hold-release. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Journaling
mc_create_journaling_service details
mc_create_journaling_service details
[Mimecast] When the customer subscribes to Internal Email Protect, Continuity or Archiving we need to ensure that internal messages (that normally remain internal to the customers' email infrastructure) get. POST /journaling/cloud-gateway/v1/services. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, enabled, messageFormat, removeJournalHeaders, journalNonInternalAddresses, journalUnknownInternalAddresses, smtpJournalingConnection, pop3JournalingConnection. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_journaling_service details
mc_delete_journaling_service details
[Mimecast] DESTRUCTIVE: this endpoint deletes journaling connector specified with the journaling id in the endpoint. This endpoint is used to create journaling connector. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_journaling_service details
mc_get_journaling_service details
[Mimecast] This endpoint returns journaling connector, their configuration and current status specified with the journaling id in the endpoint. GET /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_journaling_service_mx details
mc_get_journaling_service_mx details
[Mimecast] This endpoint returns journaling connectors, their configuration and current status. POST /api/journaling/get-service. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_journaling_services details
mc_list_journaling_services details
[Mimecast] This endpoint returns all journaling connectors, their configuration and current status within the customer’s account. GET /journaling/cloud-gateway/v1/services. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_journaling_service details
mc_update_journaling_service details
[Mimecast] The endpoint updates journaling connector specified in the journaling id. PATCH /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. Send the request body as JSON (optional). Documented body fields: description, enabled, messageFormat, removeJournalHeaders, journalNonInternalAddresses, journalUnknownInternalAddresses, transferProtocol, smtpJournalingConnection, pop3JournalingConnection. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Managed senders
mc_bulk_delete_managed_internal_addresses details
mc_bulk_delete_managed_internal_addresses details
[Mimecast] DESTRUCTIVE: delete all Managed Senders entries that contain internal recipients as senders on the account. Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/internal-addresses/bulk-delete. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_bulk_delete_managed_recipient_senders details
mc_bulk_delete_managed_recipient_senders details
[Mimecast] DESTRUCTIVE: delete Managed Senders entries for a specific internal recipient. Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/recipients//bulk-delete. Email Security Cloud Gateway. Path parameters: recipient_email. Send the request body as JSON (optional). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_bulk_delete_managed_senders details
mc_bulk_delete_managed_senders details
[Mimecast] DESTRUCTIVE: delete Managed Senders entries based on sender email addresses or sender domains in addition to optional filtering criteria (Type, Action and Trusted). Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/senders/bulk-delete. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: ids, type, action, trusted. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_permit_or_block_sender details
mc_permit_or_block_sender details
[Mimecast] DESTRUCTIVE: permit or block a managed sender. Why this is destructive: changes whether that sender's mail reaches the recipient at all. POST /api/managedsender/permit-or-block-sender. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: action, sender, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Message tracking
mc_decode_ttp_url details
mc_decode_ttp_url details
[Mimecast] Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Account | Dashboard | Read. POST /api/ttp/url/decode-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_find_processing_messages details
mc_find_processing_messages details
[Mimecast] This API endpoint will return messages currently being processed by Mimecast. POST /api/gateway/find-processing-messages. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, sortBy, sortOrder, start, type. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_email_queues details
mc_get_email_queues details
[Mimecast] This endpoint can be used to get the count of the inbound and outbound email queues at specified times. POST /api/email/get-email-queues. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_gateway_message_file details
mc_get_gateway_message_file details
[Mimecast] This API endpoint can be used to retrieve the file or attachment for given id. POST /api/gateway/message/get-file. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_message_info details
mc_get_message_info details
[Mimecast] This API endpoint can be used to retrieve detailed information about a specific message. POST /api/message-finder/get-message-info. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_search_messages details
mc_search_messages details
[Mimecast] Search for messages. POST /api/message-finder/search. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: advancedTrackAndTraceOptions, attachments, end, messageId, route, searchReason, start, status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Outbound email
mc_send_email details
mc_send_email details
[Mimecast] DESTRUCTIVE: this API endpoint can be used to send an email. Why this is destructive: sends a real email from your Mimecast account; it lands in the recipients' mailboxes immediately and cannot be recalled. POST /api/email/send-email. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Documented body fields: attachments, bcc, cc, extraHeaders, from, htmlBody, inReplyTo, plainBody, subject, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_upload_email_file details
mc_upload_email_file details
[Mimecast] Upload a file so it can be attached to an outbound email. POST /api/file/file-upload. Email Security Cloud Gateway, MX-based deployments only. Provide the file EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl - exactly one of the two, never both. StackJack downloads an https URL server-side and refuses anything over 25 MB, a non-https URL, or a redirect to a different host. THIS DOES NOT SEND ANYTHING BY ITSELF and nothing reaches a recipient: the response is Mimecast's raw JSON, whose data[].urls carries the stored file's pre-signed URL, and the message is only sent when mc_send_email is called afterwards. Mimecast's own x-mc-arg header (the file's SHA-256 and byte length) is computed from the uploaded bytes, so there is nothing to pass for it. Requires an application with Account | Dashboard | Read permission. MSP: pass accountCode to act on a managed customer; omit it to act on your own account.
Cloud Integrated policies
mc_create_ci_policy details
mc_create_ci_policy details
[Mimecast] Add a policy. POST /email/cloud-integrated/v1/policies. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: name, description, protectionMode, targets, actions, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_ci_policy details
mc_delete_ci_policy details
[Mimecast] DESTRUCTIVE: delete a policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ci_default_policy details
mc_get_ci_default_policy details
[Mimecast] Get default policy. GET /email/cloud-integrated/v1/policies/default-policy. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ci_policy details
mc_get_ci_policy details
[Mimecast] Find policy by ID. GET /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_onboard_ci_account details
mc_onboard_ci_account details
[Mimecast] Onboard a customer account. POST /email/cloud-integrated/v1/onboarding. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: protectionMode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_ci_default_policy details
mc_update_ci_default_policy details
[Mimecast] Update default policy. PATCH /email/cloud-integrated/v1/policies/default-policy. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: protectionMode, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_ci_policy details
mc_update_ci_policy details
[Mimecast] Update a policy. PATCH /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. Send the request body as JSON (required). Documented body fields: name, description, protectionMode, targets, actions, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Connectors
mc_create_connector details
mc_create_connector details
[Mimecast] Initiate consent management request. This uses the consent workflow. POST /connector/cloud-gateway/v1/connectors. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: name, description, product, provider. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_connector details
mc_delete_connector details
[Mimecast] DESTRUCTIVE: deletes an existing Connector. Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_connector details
mc_get_connector details
[Mimecast] Fetches Connector information for an account by Connector ID Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. GET /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_connectors details
mc_list_connectors details
[Mimecast] Fetches all existing Connectors information for an account. Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. GET /connector/cloud-gateway/v1/connectors. Email Security Cloud Gateway. Optional filters: pageToken, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_connector details
mc_update_connector details
[Mimecast] Updates Connectors with following details - Connector Name, Connector description Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors. PATCH /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. Send the request body as JSON (required). Documented body fields: name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Marketplace integrations
mc_create_marketplace_integration details
mc_create_marketplace_integration details
[Mimecast] Start integration onboarding (consent request). POST /marketplace/v1/integrations. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: name, type, description, config, tags, consents, credentials. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_marketplace_consent_request details
mc_delete_marketplace_consent_request details
[Mimecast] DESTRUCTIVE: cancel consent request. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /marketplace/v1/consent-requests/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_marketplace_integration details
mc_delete_marketplace_integration details
[Mimecast] DESTRUCTIVE: delete an integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_marketplace_consent_request details
mc_get_marketplace_consent_request details
[Mimecast] Get consent request status. GET /marketplace/v1/consent-requests/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_marketplace_integration details
mc_get_marketplace_integration details
[Mimecast] Get integration details (includes enabled). GET /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_marketplace_consent_requests details
mc_list_marketplace_consent_requests details
[Mimecast] List consent requests. GET /marketplace/v1/consent-requests. Email Security Cloud Gateway. Optional filters: status. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_marketplace_integrations details
mc_list_marketplace_integrations details
[Mimecast] List integrations (includes enabled). GET /marketplace/v1/integrations. Email Security Cloud Gateway. Optional filters: view. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_marketplace_integration details
mc_update_marketplace_integration details
[Mimecast] Update an integration. PATCH /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. Send the request body as JSON (required). Documented body fields: name, description, config, tags, consents, credentials, enabled, role, products. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Address alteration
mc_create_address_alteration_definition details
mc_create_address_alteration_definition details
[Mimecast] This API endpoint can be used to create new Address Alteration definitions within an Address Alteration Set or at the root level for policy-less processing. POST /api/policy/address-alteration/create-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterations, folderId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_address_alteration_policy details
mc_create_address_alteration_policy details
[Mimecast] This API endpoint can be used to create new Address Alteration policy to apply an alteration definition based on sender and recipient values. POST /api/policy/address-alteration/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterationSetId, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_address_alteration_set details
mc_create_address_alteration_set details
[Mimecast] This API endpoint can be used to create new Address Alteration Set, to hold a number of alteration definitions. POST /api/policy/address-alteration/create-address-alteration-set. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_address_alteration_definition details
mc_delete_address_alteration_definition details
[Mimecast] DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration definitions within an Address Alteration Set. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/address-alteration/delete-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_address_alteration_policy details
mc_delete_address_alteration_policy details
[Mimecast] DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/address-alteration/delete-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_address_alteration_definition details
mc_get_address_alteration_definition details
[Mimecast] This API endpoint can be used to find an existing Address Alteration Definition. Each request field is optional, however at least one must be specified in the request body. POST /api/policy/address-alteration/get-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: folderId, newAddress, originalAddress, routing. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_address_alteration_policy details
mc_get_address_alteration_policy details
[Mimecast] This API endpoint can be used to find an existing Address Alteration policy. POST /api/policy/address-alteration/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_address_alteration_set details
mc_get_address_alteration_set details
[Mimecast] This API endpoint can be used to find an existing Address Alteration Set. POST /api/policy/address-alteration/get-address-alteration-set. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: depth, folderId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_address_alteration_policy details
mc_update_address_alteration_policy details
[Mimecast] This API endpoint can be used to update an existing Address Alteration policy. POST /api/policy/address-alteration/update-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterationSetId, id, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Anti-spoofing
mc_create_anti_spoofing_policy details
mc_create_anti_spoofing_policy details
[Mimecast] Creates a anti-spoofing policy for an account. POST /policy-management/cloud-gateway/v1/anti-spoofing/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_anti_spoofing_policy details
mc_delete_anti_spoofing_policy details
[Mimecast] DESTRUCTIVE: deletes a anti-spoofing policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_anti_spoofing_policy details
mc_get_anti_spoofing_policy details
[Mimecast] Gets an anti-spoofing policy for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_anti_spoofing_policies details
mc_list_anti_spoofing_policies details
[Mimecast] Gets all anti-spoofing policies for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_anti_spoofing_policy details
mc_update_anti_spoofing_policy details
[Mimecast] Updates a anti-spoofing policy for an account. PATCH /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs, hostnames. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Anti-spoofing bypass
mc_create_anti_spoofing_bypass_policy details
mc_create_anti_spoofing_bypass_policy details
[Mimecast] Creates a anti-spoofing bypass policy for an account. POST /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, spfDomains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_anti_spoofing_bypass_policy_mx details
mc_create_anti_spoofing_bypass_policy_mx details
[Mimecast] This endpoint can be used to create a new Anti-Spoofing SPF based Bypass policy. POST /api/policy/antispoofing-bypass/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_anti_spoofing_bypass_policy details
mc_delete_anti_spoofing_bypass_policy details
[Mimecast] DESTRUCTIVE: deletes a anti-spoofing bypass policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_anti_spoofing_bypass_policy_mx details
mc_delete_anti_spoofing_bypass_policy_mx details
[Mimecast] DESTRUCTIVE: this endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/antispoofing-bypass/delete-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_anti_spoofing_bypass_policy details
mc_get_anti_spoofing_bypass_policy details
[Mimecast] Gets a anti-spoofing bypass policy for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_anti_spoofing_bypass_policy_mx details
mc_get_anti_spoofing_bypass_policy_mx details
[Mimecast] This endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies. POST /api/policy/antispoofing-bypass/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_anti_spoofing_bypass_policies details
mc_list_anti_spoofing_bypass_policies details
[Mimecast] Gets all anti-spoofing bypass policies for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_anti_spoofing_bypass_policy details
mc_update_anti_spoofing_bypass_policy details
[Mimecast] Updates a anti-spoofing policy for an account. PATCH /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, spfDomains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_anti_spoofing_bypass_policy_mx details
mc_update_anti_spoofing_bypass_policy_mx details
[Mimecast] This endpoint can be used to update an existing Anti-Spoofing SPF based Bypass policy. POST /api/policy/antispoofing-bypass/update-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id, option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Blocked senders
mc_create_blocked_senders_policy details
mc_create_blocked_senders_policy details
[Mimecast] DESTRUCTIVE: creates a blocked senders policy for an account. Warning Warning: A sender and recipient policy set to Any will apply to all inbound email. A block action will prevent delivery of all messages. Why this is destructive: a blocked-senders policy stops mail from the addresses it names being delivered. POST /policy-management/cloud-gateway/v1/blocked-senders/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_blocked_senders_policy_mx details
mc_create_blocked_senders_policy_mx details
[Mimecast] DESTRUCTIVE: this endpoint creates new blocked sender policies, which can be used to manage a combination of sender and recipient restrictions. Why this is destructive: a blocked-senders policy stops mail from the addresses it names being delivered. POST /api/policy/blockedsenders/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_blocked_senders_policy details
mc_delete_blocked_senders_policy details
[Mimecast] DESTRUCTIVE: deletes a blocked senders policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_blocked_senders_policy details
mc_get_blocked_senders_policy details
[Mimecast] Gets an blocked senders policy for an account. GET /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_blocked_senders_policy_mx details
mc_get_blocked_senders_policy_mx details
[Mimecast] This endpoint retrieves blocked sender policies. POST /api/policy/blockedsenders/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_blocked_senders_policies details
mc_list_blocked_senders_policies details
[Mimecast] Gets all blocked senders policies for an account. GET /policy-management/cloud-gateway/v1/blocked-senders/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_blocked_senders_policy details
mc_update_blocked_senders_policy details
[Mimecast] DESTRUCTIVE: updates a blocked senders policy for an account. Why this is destructive: changes which senders are blocked, so mail that was being delivered can stop being delivered. PATCH /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
DNS authentication
mc_create_dns_auth_outbound_definition details
mc_create_dns_auth_outbound_definition details
[Mimecast] The Api endpoint can be used to create a DNS Authentication - Outbound definition, DKIM keys and the DNS entry. All these can be accessed when retrieving the definition. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, domain, selector, signDkim, keyLength. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_dns_auth_outbound_policy details
mc_create_dns_auth_outbound_policy details
[Mimecast] The Api endpoint can be used to create DNS Authentication - Outbound policy. The DKIM signature gets applied via a “DNS Authentication - Outbound” policy. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dns_auth_outbound_definition details
mc_delete_dns_auth_outbound_definition details
[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete a DNS Authentication - Outbound definition with definition id specified in the endpoint. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_dns_auth_outbound_policy details
mc_delete_dns_auth_outbound_policy details
[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete DNS Authentication - Outbound policies with policy id specified in the endpoint. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dns_auth_outbound_definition details
mc_get_dns_auth_outbound_definition details
[Mimecast] The Api endpoint can be used to get DNS Authentication - Outbound definition with definition id specified in the endpoint. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_dns_auth_outbound_policy details
mc_get_dns_auth_outbound_policy details
[Mimecast] The Api endpoint can be used to get DNS Authentication - Outbound policies with policy id specified in the endpoint. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dns_auth_outbound_definitions details
mc_list_dns_auth_outbound_definitions details
[Mimecast] The Api endpoint can be used to get all DNS Authentication - Outbound definitions. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_dns_auth_outbound_policies details
mc_list_dns_auth_outbound_policies details
[Mimecast] The Api endpoint can be used to get all DNS Authentication - Outbound policies within the customer’s account. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dns_auth_outbound_definition details
mc_update_dns_auth_outbound_definition details
[Mimecast] The Api endpoint can be used to update a DNS Authentication - Outbound definition with definition id specified in the endpoint. PATCH /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. Send the request body as JSON (required). Documented body fields: description, signDkim. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_dns_auth_outbound_policy details
mc_update_dns_auth_outbound_policy details
[Mimecast] The Api endpoint can be used to update DNS Authentication - Outbound policies with policy id specified in the endpoint. PATCH /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_verify_dns_auth_outbound_definition details
mc_verify_dns_auth_outbound_definition details
[Mimecast] The Api endpoint can be used to verify that DKIM within the DNS Authentication - Outbound policies with policy id specified in the endpoint is configured correctly. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions//verify. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Delivery routes
mc_create_delivery_route_definition details
mc_create_delivery_route_definition details
[Mimecast] The Api endpoint can be used to create a delivery route definition. POST /policy-management/cloud-gateway/v1/delivery-route/definitions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, hostname, port, smtpAuthentication, alternateRouteId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_delivery_route_policy details
mc_create_delivery_route_policy details
[Mimecast] The Api endpoint can be used to create a Delivery Route policy. POST /policy-management/cloud-gateway/v1/delivery-route/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, enforced, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_delivery_route_definition details
mc_delete_delivery_route_definition details
[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete a delivery route definition with definition id specified in the uri. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_delivery_route_policy details
mc_delete_delivery_route_policy details
[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete the delivery route with policy id specified in the uri. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_delivery_route_definition details
mc_get_delivery_route_definition details
[Mimecast] The Api endpoint can be used to get a delivery route definition with definition id specified in the uri. GET /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_delivery_route_policy details
mc_get_delivery_route_policy details
[Mimecast] The Api endpoint can be used to get a delivery route policy with policy id specified in the uri. GET /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_delivery_route_definitions details
mc_list_delivery_route_definitions details
[Mimecast] The Api endpoint can be used to get all existing delivery route definitions. GET /policy-management/cloud-gateway/v1/delivery-route/definitions. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_delivery_route_policies details
mc_list_delivery_route_policies details
[Mimecast] The Api endpoint can be used to get all existing delivery route policies. GET /policy-management/cloud-gateway/v1/delivery-route/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_delivery_route_definition details
mc_update_delivery_route_definition details
[Mimecast] The Api endpoint can be used to update a delivery route definition with definition id specified in the uri. PATCH /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. Send the request body as JSON (required). Documented body fields: description, hostname, port, smtpAuthentication, alternateRouteId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_delivery_route_policy details
mc_update_delivery_route_policy details
[Mimecast] The Api endpoint can be used to update the delivery route with policy id specified in the uri. PATCH /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, enforced, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_verify_delivery_route details
mc_verify_delivery_route details
[Mimecast] The Api endpoint can be used to verify that the delivery route policy is valid and that Mimecast can sucessfully communicate with the provided IP address or Hostname. POST /policy-management/cloud-gateway/v1/delivery-route/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: hostname, port, relaxedTls, checkExternalAccess, recipientEmailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Greylisting
mc_create_greylisting_policy details
mc_create_greylisting_policy details
[Mimecast] Creates a greylisting policy. POST /policy-management/cloud-gateway/v1/greylisting/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_greylisting_policy details
mc_delete_greylisting_policy details
[Mimecast] DESTRUCTIVE: deletes a greylisting policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_greylisting_policy details
mc_get_greylisting_policy details
[Mimecast] Get greylisting policy by an id. GET /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_greylisting_policies details
mc_list_greylisting_policies details
[Mimecast] Gets all greylisting policies for an account. GET /policy-management/cloud-gateway/v1/greylisting/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_greylisting_policy details
mc_update_greylisting_policy details
[Mimecast] Updates a greylisting policy. PATCH /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Managed URLs
mc_create_managed_url details
mc_create_managed_url details
[Mimecast] This endpoint can be used to add new managed URL entries for URL Protection. POST /api/ttp/url/create-managed-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: action, comment, disableLogClick, disableRewrite, disableUserAwareness, matchType, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_managed_url details
mc_delete_managed_url details
[Mimecast] DESTRUCTIVE: this API endpoint allows for the removal of an existing Managed URL entry. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/ttp/url/delete-managed-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_managed_urls details
mc_list_managed_urls details
[Mimecast] This endpoint can be used to return all entries currently in an accounts Managed URL list. Optional filtering fields can also be used to return a specific URL, or set of URLs. POST /api/ttp/url/get-all-managed-urls. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domainOrComment, domainOrUrl, exactMatch, filterBy, sortByUrl, sortOrder. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Web security
mc_create_web_white_url_policy details
mc_create_web_white_url_policy details
[Mimecast] This endpoint can be used to create a Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/create-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, policies, urls. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_web_white_url_policy details
mc_delete_web_white_url_policy details
[Mimecast] DESTRUCTIVE: this endpoint can be used to delete an existing Web Security Block or Allow List policy for domains or URLs. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/webwhiteurl/delete-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_web_white_url_policy details
mc_get_web_white_url_policy details
[Mimecast] This endpoint can be used to get information about an existing Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/get-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_web_white_url_policy details
mc_update_web_white_url_policy details
[Mimecast] This endpoint can be used to update an existing Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/update-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, id, policies, urls. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Protection logs
mc_get_dlp_logs details
mc_get_dlp_logs details
[Mimecast] This endpoint can be used to retrieve messages that triggered a DLP or Content Examination policy. POST /api/dlp/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: actions, from, oldestFirst, query, routes, searchField, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ttp_attachment_logs details
mc_get_ttp_attachment_logs details
[Mimecast] Pre-requisites In order to to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | Attachment Protection. POST /api/ttp/attachment/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: from, oldestFirst, result, route, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ttp_impersonation_logs details
mc_get_ttp_impersonation_logs details
[Mimecast] This endpoint can be used to get messages containing information flagged by an Impersonation Protection configuration. POST /api/ttp/impersonation/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: actions, from, identifiers, oldestFirst, query, searchField, taggedMalicious, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ttp_url_logs details
mc_get_ttp_url_logs details
[Mimecast] Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | URL Protection | Read. POST /api/ttp/url/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: from, oldestFirst, route, scanResult, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Remediation
mc_create_ttp_remediation details
mc_create_ttp_remediation details
[Mimecast] This endpoint can be used to create a remediation incident, by messageId, file hash or a url contained in an email. POST /api/ttp/remediation/create. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, hashOrMessageId, reason, searchBy, start, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_create_ttp_remediation_v2 details
mc_create_ttp_remediation_v2 details
[Mimecast] This endpoint can be used to create a remediation incident, by file hash or a url of by one or more messageId. POST /api/ttp/remediation/v2/create. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, messageIds, reason, searchBy, start, hash, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_find_ttp_remediation_incidents details
mc_find_ttp_remediation_incidents details
[Mimecast] This endpoint can be used to search for existing remediation incidents. While each request field is optional, at least one field must be supplied. POST /api/ttp/remediation/find-incidents. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_bulk_remediation_status details
mc_get_bulk_remediation_status details
[Mimecast] Get the bulk remediation status by batch ID. GET /security/remediation/v1/bulk/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: batchId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_event_remediation_status details
mc_get_event_remediation_status details
[Mimecast] Get remediation status by event ID. GET /security/remediation/v1/events/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: eventId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ttp_remediation_incident details
mc_get_ttp_remediation_incident details
[Mimecast] This endpoint can be used to get information about an existing incident. The information includes incident creation criteria, remediation status counts and information to restore a message, if needed. POST /api/ttp/remediation/get-incident. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remediate_security_event details
mc_remediate_security_event details
[Mimecast] DESTRUCTIVE: remediate a security event by event ID. Why this is destructive: pulls a delivered message out of the recipient's mailbox. POST /security/remediation/v1/events/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: eventId. Send the request body as JSON (required). Documented body fields: reason, actionType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_remediate_security_events_bulk details
mc_remediate_security_events_bulk details
[Mimecast] DESTRUCTIVE: remediate bulk security threat events. Why this is destructive: pulls delivered messages out of recipients' mailboxes in bulk. POST /security/remediation/v1/bulk. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: reason, actionType, processingIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_search_ttp_remediation_hash details
mc_search_ttp_remediation_hash details
[Mimecast] This endpoint can be used to identify if an account has seen a specific file hash within messages over the last year. POST /api/ttp/remediation/search-hash. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: hashes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Reported emails
mc_create_threat_report_subscription details
mc_create_threat_report_subscription details
[Mimecast] Create Subscriptions. POST /threat-reporting/v1/subscriptions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: clientState, notificationURL, resourceType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_threat_report_subscription details
mc_delete_threat_report_subscription details
[Mimecast] DESTRUCTIVE: delete Subscription. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /threat-reporting/v1/subscriptions/. Email Security Cloud Gateway. Path parameters: subscriptionId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_reported_email details
mc_get_reported_email details
[Mimecast] Retrieve reported email. GET /threat-reporting/v1/reported-emails/. Email Security Cloud Gateway. Path parameters: reportedMessageAggregateId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_threat_analysis details
mc_get_threat_analysis details
[Mimecast] Retrieve Threat Analysis by Id. GET /threat-reporting/v1/threat-analysis/. Email Security Cloud Gateway. Path parameters: threatAnalysisId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_reported_emails details
mc_list_reported_emails details
[Mimecast] List Reported Emails. GET /threat-reporting/v1/reported-emails. Email Security Cloud Gateway. Optional filters: dateRangeStartsAt, dateRangeEndsAt, pageSize, offset. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_threat_report_subscriptions details
mc_list_threat_report_subscriptions details
[Mimecast] List Subscriptions. GET /threat-reporting/v1/subscriptions. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_threat_reports details
mc_list_threat_reports details
[Mimecast] List Threat Reports. GET /threat-reporting/v1/threat-reports. Email Security Cloud Gateway. Optional filters: pageSize, offset. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_update_threat_report_subscription details
mc_update_threat_report_subscription details
[Mimecast] Renew Subscription. PATCH /threat-reporting/v1/subscriptions/. Email Security Cloud Gateway. Path parameters: subscriptionId. Send the request body as JSON (required). Documented body fields: oldClientState, clientState. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
SIEM feeds
mc_list_siem_batch_events_cg details
mc_list_siem_batch_events_cg details
[Mimecast] Retrieve CG Events. GET /siem/v1/batch/events/cg. Email Security Cloud Gateway. Optional filters: type, dateRangeStartsAt, dateRangeEndsAt, nextPage, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_siem_batch_events_ci details
mc_list_siem_batch_events_ci details
[Mimecast] Retrieve CI Events. GET /siem/v1/batch/events/ci. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Optional filters: type, dateRangeStartsAt, dateRangeEndsAt, nextPage, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_siem_events_cg details
mc_list_siem_events_cg details
[Mimecast] Retrieve CG Events. GET /siem/v1/events/cg. Email Security Cloud Gateway. Optional filters: types, dateRangeStartsAt, dateRangeEndsAt, pageSize, nextPage. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_siem_events_ci details
mc_list_siem_events_ci details
[Mimecast] Retrieve CI Events. GET /siem/v1/events/ci. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Optional filters: types, dateRangeStartsAt, dateRangeEndsAt, pageSize, nextPage. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Threat events
mc_get_threat_event_details details
mc_get_threat_event_details details
[Mimecast] Developer API to fetch threat details. GET /threats/v1/events//details. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_list_threat_events details
mc_list_threat_events details
[Mimecast] List Threat events. GET /threats/v1/events. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, analysis, status, direction, source, pageToken, pageSize, limit, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Threat intelligence
mc_create_byo_threat_intel_batch details
mc_create_byo_threat_intel_batch details
[Mimecast] DESTRUCTIVE: this endpoint can be used to import a single or batch of multiple indicators. These indicators can be used to perform a specific action based on their presence. Why this is destructive: the body's operationType decides what the batch DOES, and the vendor's own values are "Must be one of ALLOW, BLOCK or DELETE" - so this tool does not only add indicators, it can REMOVE the ones the batch names, and BLOCK stops mail carrying them being delivered. POST /api/byo-threat-intelligence/create-batch. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: hashList, operationType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_delete_byo_threat_intel_batch details
mc_delete_byo_threat_intel_batch details
[Mimecast] DESTRUCTIVE: this endpoint can be used to remove a batch of indicators. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/byo-threat-intelligence/delete-batch. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_byo_threat_intel_batches details
mc_get_byo_threat_intel_batches details
[Mimecast] This endpoint can be used to retrieve information about all existing batches. POST /api/byo-threat-intelligence/get-batches. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: order, sortBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_byo_threat_intel_quota details
mc_get_byo_threat_intel_quota details
[Mimecast] This endpoint can be used to retrieve the number of indicators in use and the number of remaining indicators that can be added. POST /api/byo-threat-intelligence/get-quota. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_ttp_threat_intel_feed details
mc_get_ttp_threat_intel_feed details
[Mimecast] This feed can be used to return identified malware threats at a customer or regional grid level. POST /api/ttp/threat-intel/get-feed. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: compress, end, feedType, fileType, start, token. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
Threat statistics
mc_get_attachment_scan_stats details
mc_get_attachment_scan_stats details
[Mimecast] Get Attachment Scan stats. GET /threats/v1/stats/attachment-scans. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_gateway_detection_stats details
mc_get_gateway_detection_stats details
[Mimecast] Get Gateway Detection stats by type. GET /threats/v1/stats/gateway-detections. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_impersonation_stats details
mc_get_impersonation_stats details
[Mimecast] Get Impersonation stats. GET /threats/v1/stats/impersonations. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_phishing_stats details
mc_get_phishing_stats details
[Mimecast] Get phishing stats. GET /threats/v1/stats/phishing. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_suspicious_stats details
mc_get_suspicious_stats details
[Mimecast] Get suspicious stats. GET /threats/v1/stats/suspicious. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_threats_by_recipient_stats details
mc_get_threats_by_recipient_stats details
[Mimecast] List Threat statistics by recipient. GET /threats/v1/stats/threats-by-recipient. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, pageToken, email, pageSize, orderBy, limit. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_threats_by_sender_stats details
mc_get_threats_by_sender_stats details
[Mimecast] List Threat statistics by sender. GET /threats/v1/stats/threats-by-sender. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, pageToken, email, pageSize, orderBy, limit. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_unwanted_stats details
mc_get_unwanted_stats details
[Mimecast] Get unwanted stats. GET /threats/v1/stats/unwanted. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
mc_get_url_click_stats details
mc_get_url_click_stats details
[Mimecast] Get URL Click stats. GET /threats/v1/stats/url-clicks. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team