Skip to main content
Tools Reference

Mimecast Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Mimecast Tools

mc_ · 374 tools · Free 194 · Pro 180 Email security, archiving, policy, human risk and DMARC over Mimecast API 2.0. Auth is OAuth2 client_credentials only: client_id + client_secret posted to POST /oauth/token for a 30-minute bearer, NO refresh token. No scope parameter - authority is bound when the Application is created, by its Product and Role, so a 401 app_forbidden is a key short one product; DMARC Analyzer is its own product the DMARC tools need. Three residency gateways (global, uk, us); DMARC is a base PATH on the same host, not a fourth gateway. An MSP holds ONE partner credential, naming a managed customer per call via x-mc-account, the accountCode argument. Paging has four shapes: legacy routes carry pageSize/pageToken in the REQUEST BODY under meta.pagination, ending by OMITTING next; REST routes use query parameters; DMARC pages by query, ending on meta.nextPage; some are unpaginated. Max page size 100. On legacy routes a 200 is not success - a non-empty fail[] is a failure. X-RateLimit-Reset is ms.

All connector tools · Mimecast setup guide

Mimecast tool groups

Account

ToolPlanAccessSummary
mc_get_accountFreeRead-onlyThis endpoint returns the summary details for an account in Mimecast.
mc_get_dashboard_notificationsFreeRead-onlyThis feed can be used to return dashboard notifications from the Administration Console Dashboard.
mc_get_emergency_contactFreeRead-onlyReturns the Emergency Contact information for the account.
mc_get_provisioning_packagesFreeRead-onlyThis endpoint returns products that are available to be provisioned by a partner.
mc_get_support_infoFreeRead-onlyThis endpoint returns support information that is associated with a Mimecast tenant.
mc_get_whoamiFreeRead-onlyReturns details of a partner, including information such as Partner type, Mimecast account code in CI, CG and X1 platform.
mc_replace_emergency_contactProDestructiveDESTRUCTIVE: creates an Emergency Contact for the account.
mc_update_emergency_contactProWriteUpdates the Emergency Contact information for the account.

[Mimecast] This endpoint returns the summary details for an account in Mimecast. POST /api/account/get-account. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This feed can be used to return dashboard notifications from the Administration Console Dashboard. POST /api/account/get-dashboard-notifications. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountCode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Returns the Emergency Contact information for the account. GET /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This endpoint returns products that are available to be provisioned by a partner. POST /api/provisioning/get-packages. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This endpoint returns support information that is associated with a Mimecast tenant. POST /api/account/get-support-info. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Returns details of a partner, including information such as Partner type, Mimecast account code in CI, CG and X1 platform. Refer to guideline tutorial page for more information on using this endpoint. GET /identity/whoami. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] DESTRUCTIVE: creates an Emergency Contact for the account. Why this is destructive: wholesale replace - the body becomes the entire emergency-contact record and any field omitted from it is cleared. PUT /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: contactName, contactEmailAddress, mobilePhone, telephone, alternateEmailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Updates the Emergency Contact information for the account. PATCH /account/cloud-gateway/v1/emergency-contact. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: contactName, contactEmailAddress, mobilePhone, telephone, alternateEmailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Configuration snapshots

ToolPlanAccessSummary
mc_create_config_snapshotProWriteCreate a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.
mc_export_config_snapshotFreeRead-onlyExport a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.
mc_list_config_snapshotsFreeRead-onlyGet the comprehensive list of configuration snapshots for the customers Mimecast settings, including those for: Managed Senders, Managed URLs and Profile Groups.
mc_restore_config_snapshotProDestructiveDESTRUCTIVE: restore a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.

[Mimecast] Create a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/create. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Export a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/export. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Get the comprehensive list of configuration snapshots for the customers Mimecast settings, including those for: Managed Senders, Managed URLs and Profile Groups. POST /config-snapshot/v1/list. Email Security Cloud Gateway. Send the request body as JSON (required). Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: restore a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups. Why this is destructive: overwrites the account's LIVE configuration with the snapshot, replacing current policy and gateway settings. POST /config-snapshot/v1/restore. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: data. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Partner (MSP)

ToolPlanAccessSummary
mc_get_partner_customerFreeRead-onlyGet one managed customer.
mc_list_partner_customersFreeRead-onlyList managed customers.

[Mimecast] Get one managed customer. GET /partner/v1/customers/. Email Security Cloud Gateway. Path parameters: customer_account_code. MSP discovery read for a single managed customer. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
customerAccountCodestringyesRequired. The managed customer's Mimecast account code.

[Mimecast] List managed customers. GET /partner/v1/customers. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP discovery read. Returns each managed customer's accountCode, accountName, region, seatCount, industry, customerStatus and billingType. The accountCode is what every other tool's accountCode argument takes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
ToolPlanAccessSummary
mc_get_archive_fileFreeRead-onlyRetrieves the file or attachment for given id.
mc_get_archive_message_detailFreeRead-onlyRetrieves archived message details.
mc_get_archive_message_listFreeRead-onlyRetrieves archive message list.
mc_get_archive_message_partFreeRead-onlyRetrieves the message part - HTML, plain or RFC822. POST /api/archive/get-message-part.
mc_search_archiveFreeRead-onlyRetrieves archive search items.

[Mimecast] Retrieves the file or attachment for given id. POST /api/archive/get-file. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves archived message details. POST /api/archive/get-message-detail. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves archive message list. POST /api/archive/get-message-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, includeAliases, includeDelegates, mailbox, start, view. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves the message part - HTML, plain or RFC822. POST /api/archive/get-message-part. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: context, extractFromHtml, id, mailbox, stripDangerous, stripImg, stripStyles, transposeInlineCID, type. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves archive search items. POST /api/archive/search. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, query. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Data retention

ToolPlanAccessSummary
mc_add_smart_tag_messagesProWriteAdd messages to a smart tag.
mc_list_smart_tagsFreeRead-onlyGet all smart tags for account.
mc_search_smart_tag_messagesFreeRead-onlySearch for messages in a smart tag.
mc_set_message_visibilityProWriteSet message visibility.
mc_update_retention_adjustmentProDestructiveDESTRUCTIVE: update retention adjustment for messages.

[Mimecast] Add messages to a smart tag. POST /dataretention/v1/smart-tags//messages. Email Security Cloud Gateway. Path parameters: smartTagId. Send the request body as JSON (required). Documented body fields: messageIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
smartTagIdstringyesRequired. A valid Smart Tag identifier (obtainable via the Get List of Smart Tags endpoint)

[Mimecast] Get all smart tags for account. GET /dataretention/v1/smart-tags. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. Number of results per page. StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Token for the next page of results

[Mimecast] Search for messages in a smart tag. POST /dataretention/v1/smart-tags//messages/search. Email Security Cloud Gateway. Path parameters: smartTagId. Optional filters: pageSize, pageToken. Send the request body as JSON (required). Documented body fields: startDateTime, endDateTime. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
pageSizeintegernonullOptional. Number of results per page. StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Token for the next page of results
smartTagIdstringyesRequired. Encoded smart tag ID

[Mimecast] Set message visibility. POST /dataretention/v1/messages/visibility. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: visible, messageIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: update retention adjustment for messages. Why this is destructive: it sets retainDays for the messages the body names, and retainDays: 0 purges them from the archive immediately - Mimecast keeps no copy and StackJack cannot recover them. POST /dataretention/v1/retention-adjustment. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: messageIds, retainDays. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Archive access logs

ToolPlanAccessSummary
mc_get_archive_search_logsFreeRead-onlyRetrieves archive search logs.
mc_get_search_logsFreeRead-onlyRetrieves the search logs.
mc_get_view_logsFreeRead-onlyRetrieves the email view logs.

[Mimecast] Retrieves archive search logs. POST /api/archive/get-archive-search-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: query. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves the search logs. POST /api/archive/get-search-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, query, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieves the email view logs. POST /api/archive/get-view-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, query, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Audit events

ToolPlanAccessSummary
mc_get_audit_categoriesFreeRead-onlyReturns the list of audit categories available.
mc_get_audit_eventsFreeRead-onlyReturns the audit events matching the request.

[Mimecast] Returns the list of audit categories available. POST /api/audit/get-categories. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Returns the audit events matching the request. POST /api/audit/get-audit-events. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: categories, endDateTime, query, startDateTime. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Delivery monitoring

ToolPlanAccessSummary
mc_get_held_release_logsFreeRead-onlyThis endpoint can be used to find messages that were either released to the recipient, with details about the user that processed the release.
mc_get_rejectionsFreeRead-onlyThis endpoint can be used to find rejected messages and the reasons for their rejection.

[Mimecast] This endpoint can be used to find messages that were either released to the recipient, with details about the user that processed the release. POST /api/gateway/get-held-release-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to find rejected messages and the reasons for their rejection. POST /api/gateway/get-rejections. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, mailbox, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Awareness scores

ToolPlanAccessSummary
mc_get_awareness_performance_detailsFreeRead-onlyThis API endpoint can be used to get Awareness Training Mime | OS Training Module user level Performance details by Department and Performance Type (data displayed on Performance > Achievements.
mc_get_awareness_performance_summaryFreeRead-onlyThis API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Performance Summary by total user answer count.
mc_get_awareness_safe_score_detailsFreeRead-onlyThis API endpoint can be used to get Awareness Training Mime | OS SAFE Score user level details and grades, including User Risk, Human Error, Sentiment, Engagement and Knowledge.
mc_get_awareness_safe_score_summaryFreeRead-onlyThis API endpoint can be used to get Awareness Training Mime | OS Training SAFE Score company-level Summary by User Count per User Risk Grade.
mc_get_awareness_watchlist_detailsFreeRead-onlyThis API endpoint can be used to get Awareness Training Mime | OS Training Module user level Watchlist details by Department and Watchlist Type.
mc_get_awareness_watchlist_summaryFreeRead-onlyThis API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Watchlist Summary by total user unwatched count.

[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Performance details by Department and Performance Type (data displayed on Performance > Achievements. POST /api/awareness-training/company/get-performance-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, includeUserDetails, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Performance Summary by total user answer count. POST /api/awareness-training/company/get-performance-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS SAFE Score user level details and grades, including User Risk, Human Error, Sentiment, Engagement and Knowledge. POST /api/awareness-training/company/get-safe-score-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training SAFE Score company-level Summary by User Count per User Risk Grade. (Data displayed on Performance > User Risk Dashboard). POST /api/awareness-training/company/get-safe-score-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Watchlist details by Department and Watchlist Type. (Data displayed on Performance > Watchlist Details). POST /api/awareness-training/company/get-watchlist-details. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Watchlist Summary by total user unwatched count. POST /api/awareness-training/company/get-watchlist-summary. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

Human risk

ToolPlanAccessSummary
mc_get_individual_risk_profilesFreeRead-onlyGet individual risk profiles with scores.
mc_get_organization_attacksFreeRead-onlyGet organizational attack data.
mc_get_organization_behaviorsFreeRead-onlyGet organizational behavior data.
mc_get_organization_riskFreeRead-onlyGet organization risk trends.
mc_list_risk_departmentsFreeRead-onlyList departments with aggregated risk data.
mc_list_risk_locationsFreeRead-onlyList locations with aggregated risk data.
mc_search_individuals_riskFreeRead-onlySearch individuals with risk data.

[Mimecast] Get individual risk profiles with scores. POST /human-risk/v1/individuals/risk-profiles. Email Security Cloud Gateway. Optional filters: pageToken, pageSize, monthsBack, fields. Send the request body as JSON (required). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
fieldsstringnonullOptional. Comma-separated additional fields beyond defaults. Available - firstName, lastName, tenureMonths, tenureStatus, startDateTime, behaviors.eventCount, behaviors.events, attacks.eventCount, attacks.events. When monthsBack...
monthsBackintegernonullOptional. When provided, includes historical monthly behavior and attack data. The value is the number of months to include — 1 returns only the current month, 3 returns the current month plus the 2 previous months. When omitted...
pageSizeintegernonullOptional. Number of results to return per page Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Token for forward-only cursor-based pagination. Use the value from `meta.nextPage` in the previous response. Tokens are valid for 1 hour, if expired, restart pagination from the first page by omitting this parameter.

[Mimecast] Get organizational attack data. GET /human-risk/v1/organization/attacks. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
fieldsstringnonullOptional. Optional additional fields. Default fields (attackScore, attackFactor) are always included. Available optional field - attackTypes (per-type scores and event counts). Comma-separated values in ONE string - not a JSON array.
monthsBackintegernonullOptional. Number of months of historical data to include. Semantics depend on the endpoint (see each operation). For `GET /human-risk/v1/organization/attacks` and `GET /human-risk/v1/organization/behaviors`, this is calendar...

[Mimecast] Get organizational behavior data. GET /human-risk/v1/organization/behaviors. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
fieldsstringnonullOptional. Optional additional fields. Default fields (type, score, factor, eventCount, trend) are always included. Available optional field - events (behavior-specific event counts). Comma-separated values in ONE string - not a JSON array.
monthsBackintegernonullOptional. Number of months of historical data to include. Semantics depend on the endpoint (see each operation). For `GET /human-risk/v1/organization/attacks` and `GET /human-risk/v1/organization/behaviors`, this is calendar...

[Mimecast] Get organization risk trends. GET /human-risk/v1/organization. Email Security Cloud Gateway. Optional filters: monthsBack, fields. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
fieldsstringnonullOptional. Optional additional fields. Default fields (month, humanRiskScore, humanRiskFactor, humanRiskScoreTrend, attackScore, attackFactor, attackTrend) are always included. Available optional fields - attackTotal, riskResponses, totals.totalActions, totals.notifications, totals.outboundActions, totals.groupChanges. Comma-separated values in ONE string - not a JSON array.
monthsBackintegernonullOptional. Number of months of historical data to include. Semantics depend on the endpoint (see each operation). For `GET /human-risk/v1/organization/attacks` and `GET /human-risk/v1/organization/behaviors`, this is calendar...

[Mimecast] List departments with aggregated risk data. GET /human-risk/v1/departments. Email Security Cloud Gateway. Optional filters: orderBy, pageSize, pageToken, count. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
countbooleannonullOptional. When true, includes the total record count in meta on the first page only.
orderBystringnonullOptional. Sort field(s) with optional direction suffix (field -asc or field -desc), comma-separated for secondary sorting. Available fields - humanRiskScore, humanRiskFactor, displayName, emailAddress, department, location...
pageSizeintegernonullOptional. Number of items per page. Mimecast allows up to 1000 on this route, but StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Token for cursor-based pagination (from nextPage in response).

[Mimecast] List locations with aggregated risk data. GET /human-risk/v1/locations. Email Security Cloud Gateway. Optional filters: orderBy, pageSize, pageToken, count. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
countbooleannonullOptional. When true, includes the total record count in meta on the first page only.
orderBystringnonullOptional. Sort field(s) with optional direction suffix (field -asc or field -desc), comma-separated for secondary sorting. Available fields - humanRiskScore, humanRiskFactor, displayName, emailAddress, department, location...
pageSizeintegernonullOptional. Number of items per page. Mimecast allows up to 1000 on this route, but StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Token for cursor-based pagination (from nextPage in response).

[Mimecast] Search individuals with risk data. POST /human-risk/v1/individuals/search. Email Security Cloud Gateway. Optional filters: pageSize, pageToken, count, fields. Send the request body as JSON (optional). Documented body fields: filters, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringnonullOptional. The request body as JSON.
countbooleannonullOptional. When true, includes the total record count in meta on the first page only.
fieldsstringnonullOptional. Comma-separated additional fields beyond defaults. Available - firstName, lastName, tenureMonths, tenureStatus, startDateTime, behaviors.eventCount, behaviors.events, attacks.eventCount, attacks.events.
pageSizeintegernonullOptional. Number of results to return per page. Mimecast allows up to 1000 on this route, but StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Token for cursor-based pagination to request next page

Phishing campaigns

ToolPlanAccessSummary
mc_get_phishing_campaignFreeRead-onlyThis API endpoint can be used to get all campaign-level information on Awareness Training Mime | OS Phishing Campaigns created, both pending and launched.
mc_get_phishing_campaign_user_dataFreeRead-onlyThis API endpoint can be used to get an aggregated summary of Awareness Training Mime | OS Phishing Campaigns grouped by recipient email address.

[Mimecast] This API endpoint can be used to get all campaign-level information on Awareness Training Mime | OS Phishing Campaigns created, both pending and launched. (Data displayed on Phishing > Campaigns). POST /api/awareness-training/phishing/campaign/get-campaign. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get an aggregated summary of Awareness Training Mime | OS Phishing Campaigns grouped by recipient email address. POST /api/awareness-training/phishing/campaign/get-user-data. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributeIds, filterBy, id, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Training queue and users

ToolPlanAccessSummary
mc_get_awareness_queueFreeRead-onlyThis API endpoint can be used to get all module-level information on Awareness Training Mime | OS Training Modules created, both pending and launched.
mc_get_user_training_detailsFreeRead-onlyThis API endpoint can be used to get user enrollment and completion information on Awareness Training Mime | OS Training Modules.

[Mimecast] This API endpoint can be used to get all module-level information on Awareness Training Mime | OS Training Modules created, both pending and launched. POST /api/awareness-training/queue/get-queue. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This API endpoint can be used to get user enrollment and completion information on Awareness Training Mime | OS Training Modules. POST /api/awareness-training/user/get-training-details. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

Administrator roles

ToolPlanAccessSummary
mc_list_admin_rolesFreeRead-onlyRetrieves a list of roles for the account.

[Mimecast] Retrieves a list of roles for the account. Filterable by role Name. GET /role/cloud-gateway/v1/roles. Email Security Cloud Gateway. Optional filters: roleName, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token.
roleNamestringnonullOptional. Role name filter.

Directory connections

ToolPlanAccessSummary
mc_create_ad_integrationProWriteCreates a new directory integration for Active Directory.
mc_create_directory_sync_requestProWriteRequests a sync of all directory integrations for account.
mc_create_google_integrationProWriteCreates a new directory integration for Google.
mc_create_m365_integrationProWriteCreates a new directory integration for M365. POST /directory/cloud-gateway/v1/integrations/m365. Email Security Cloud Gateway.
mc_delete_ad_integrationProDestructiveDESTRUCTIVE: deletes an Active Directory directory integration.
mc_delete_google_integrationProDestructiveDESTRUCTIVE: deletes a Google directory integration.
mc_delete_m365_integrationProDestructiveDESTRUCTIVE: deletes a M365 directory integration.
mc_execute_directory_syncProWriteThis endpoint can be used to initiate directory synchronization.
mc_get_ad_integrationFreeRead-onlyGets an Active Directory directory integration.
mc_get_directory_connectionFreeRead-onlyThis endpoint can be used to retrieve directory connectors that are configured on the tenant.
mc_get_google_integrationFreeRead-onlyGets a Google directory integration.
mc_get_m365_integrationFreeRead-onlyGets a M365 directory integration.
mc_list_directory_integrationsFreeRead-onlyGets all (m365, google, ldap) directory integrations for account.
mc_test_ad_authenticationProWriteTests if Active directory integration can authenticate.
mc_test_ad_certificatesProWriteTests the certificates of an Active Directory integration.
mc_test_ad_connectivityProWriteTests the connectivity of an Active Directory integration.
mc_test_ad_egress_connectivityProWriteTests the Egress connectivity of an Active Directory integration.
mc_test_ad_emailProWriteTests if an Active Directory integration can retrieve directory samples.
mc_test_ad_validationProWriteTests the validity of an Active Directory integration.
mc_test_google_authenticationProWriteTests a Google directory authentication.
mc_test_google_authorizationProWriteTests a Google directory has the correct authorised permission set.
mc_test_google_connectivityProWriteTests the connectivity of a Google directory integration.
mc_test_google_emailProWriteTests if a Google Directory integration can retrieve directory samples.
mc_test_m365_authenticationProWriteTests a Microsoft 365 directory authentication.
mc_test_m365_authorizationProWriteTests a M365 directory has the correct authorised permission set.
mc_test_m365_connectivityProWriteTests the connectivity of a Microsoft 365 directory integration.
mc_test_m365_connectorProWriteTests the connector associated to a M365 directory authorisation.
mc_test_m365_emailProWriteTests if a Microsoft 365 Directory integration can retrieve directory samples.
mc_update_ad_integrationProWriteUpdates an Active Directory directory integration.
mc_update_google_integrationProWriteUpdates a Google directory integration.
mc_update_m365_integrationProWriteUpdates an M365 directory integration.

[Mimecast] Creates a new directory integration for Active Directory. POST /directory/cloud-gateway/v1/integrations/active-directory. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, info, domains, hostname, alternateHostname, port, userDn, password, rootDn, encryptionMode, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Requests a sync of all directory integrations for account. POST /directory/cloud-gateway/v1/integrations/sync-requests. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: action. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Creates a new directory integration for Google. POST /directory/cloud-gateway/v1/integrations/google. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: enabled, description, info, domains, maxUnlink, deleteUsers, acknowledgeDisabledAccounts, user, key. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Creates a new directory integration for M365. POST /directory/cloud-gateway/v1/integrations/m365. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, info, domains, connectorId, tenantDomain, serverSubtype, syncGuestUsers, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts, deleteUsers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: deletes an Active Directory directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active Directory integration to delete

[Mimecast] DESTRUCTIVE: deletes a Google directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to delete

[Mimecast] DESTRUCTIVE: deletes a M365 directory integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the M365 directory integration to delete

[Mimecast] This endpoint can be used to initiate directory synchronization. POST /api/directory/execute-sync. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Gets an Active Directory directory integration. GET /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active Directory integration to get

[Mimecast] This endpoint can be used to retrieve directory connectors that are configured on the tenant. POST /api/directory/get-connection. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Gets a Google directory integration. GET /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to get

[Mimecast] Gets a M365 directory integration. GET /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to get

[Mimecast] Gets all (m365, google, ldap) directory integrations for account. GET /directory/cloud-gateway/v1/integrations. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Tests if Active directory integration can authenticate. POST /directory/cloud-gateway/v1/integrations/active-directory//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests the certificates of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-certificates. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests the connectivity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests the Egress connectivity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-egress-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests if an Active Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/active-directory//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests the validity of an Active Directory integration. POST /directory/cloud-gateway/v1/integrations/active-directory//test-validation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Active directory integration to test

[Mimecast] Tests a Google directory authentication. POST /directory/cloud-gateway/v1/integrations/google//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to test

[Mimecast] Tests a Google directory has the correct authorised permission set. POST /directory/cloud-gateway/v1/integrations/google//test-authorisation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to test

[Mimecast] Tests the connectivity of a Google directory integration. POST /directory/cloud-gateway/v1/integrations/google//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to test

[Mimecast] Tests if a Google Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/google//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Google directory integration to test

[Mimecast] Tests a Microsoft 365 directory authentication. POST /directory/cloud-gateway/v1/integrations/m365//test-authentication. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to test

[Mimecast] Tests a M365 directory has the correct authorised permission set. POST /directory/cloud-gateway/v1/integrations/m365//test-authorisation. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to test

[Mimecast] Tests the connectivity of a Microsoft 365 directory integration. POST /directory/cloud-gateway/v1/integrations/m365//test-connectivity. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to test

[Mimecast] Tests the connector associated to a M365 directory authorisation. POST /directory/cloud-gateway/v1/integrations/m365//test-connector. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 integration to test

[Mimecast] Tests if a Microsoft 365 Directory integration can retrieve directory samples. POST /directory/cloud-gateway/v1/integrations/m365//test-email. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to test

[Mimecast] Updates an Active Directory directory integration. PATCH /directory/cloud-gateway/v1/integrations/active-directory/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: description, info, domains, hostname, alternateHostname, port, userDn, password, rootDn, encryptionMode, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
integrationIdstringyesRequired. ID of the Active Directory integration to get

[Mimecast] Updates a Google directory integration. PATCH /directory/cloud-gateway/v1/integrations/google/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: acknowledgeDisabledAccounts, enabled, description, info, domains, maxUnlink, deleteUsers, user, key. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
integrationIdstringyesRequired. ID of the Google directory integration to get

[Mimecast] Updates an M365 directory integration. PATCH /directory/cloud-gateway/v1/integrations/m365/. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: description, info, domains, connectorId, tenantDomain, serverSubtype, syncGuestUsers, acknowledgeDisabledAccounts, enabled, maxUnlink, syncContacts, deleteUsers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
integrationIdstringyesRequired. ID of the Microsoft 365 directory integration to get

Groups

ToolPlanAccessSummary
mc_add_group_member_mxProWriteThis endpoint can be used to add user email addresses or domains to a profile group.
mc_add_group_membersProWriteThis endpoint can be used to add user email addresses or domains to a profile group.
mc_create_groupProWriteCreates a new Profile Groups at the root level, or as a child-group.
mc_create_group_mxProWriteThis API endpoint can be used to create new Profile Groups at the root level, or as a child-group.
mc_delete_group_mxProDestructiveDESTRUCTIVE: this endpoint can be used to delete an exiting profile group.
mc_find_groupsFreeRead-onlyThis endpoint can be used to find groups that exist on a tenant.
mc_get_groupFreeRead-onlyThis endpoint can be used to get a profile group from a tenant.
mc_get_group_members_mxFreeRead-onlyThis endpoint can be used to retrieve group members from groups the exist on a tenant.
mc_list_group_membersFreeRead-onlyThis endpoint can be used to get group members from a tenant.
mc_list_groupsFreeRead-onlyThis endpoint can be used to find groups that exist on a tenant.
mc_remove_group_member_mxProDestructiveDESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups.
mc_remove_group_membersProDestructiveDESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups.
mc_update_group_mxProWriteThe update group endpoint can be used to update the description of Mimecast Profile groups.

[Mimecast] This endpoint can be used to add user email addresses or domains to a profile group. POST /api/directory/add-group-member. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, emailAddress, id, notes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to add user email addresses or domains to a profile group. POST /directory/cloud-gateway/v1/groups//members. Email Security Cloud Gateway. Path parameters: group_id. Send the request body as JSON (required). Documented body fields: groupMembers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
groupIdstringyesRequired. Group ID

[Mimecast] Creates a new Profile Groups at the root level, or as a child-group. POST /directory/cloud-gateway/v1/groups. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] This API endpoint can be used to create new Profile Groups at the root level, or as a child-group. Groups can be used to apply permissions and policies. POST /api/directory/create-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to delete an exiting profile group. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/directory/delete-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to find groups that exist on a tenant. POST /api/directory/find-groups. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: query, source. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to get a profile group from a tenant. GET /directory/cloud-gateway/v1/groups/. Email Security Cloud Gateway. Path parameters: group_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
groupIdstringyesRequired. Group ID

[Mimecast] This endpoint can be used to retrieve group members from groups the exist on a tenant. POST /api/directory/get-group-members. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to get group members from a tenant. GET /directory/cloud-gateway/v1/groups//members. Email Security Cloud Gateway. Path parameters: group_id. Optional filters: domain, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringnonullOptional. Limit results to a specific domain
groupIdstringyesRequired. Group ID
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] This endpoint can be used to find groups that exist on a tenant. GET /directory/cloud-gateway/v1/groups. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/directory/remove-group-member. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, emailAddress, id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups. Why this is destructive: removes the member, alias or delegate named in the request. POST /directory/cloud-gateway/v1/groups//remove-members. Email Security Cloud Gateway. Path parameters: group_id. Send the request body as JSON (required). Documented body fields: groupMembers. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
groupIdstringyesRequired. Group ID

[Mimecast] The update group endpoint can be used to update the description of Mimecast Profile groups. POST /api/directory/update-group. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, id, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Users

ToolPlanAccessSummary
mc_add_delegate_userProWriteThis API endpoint provides the ability to create a new delegate permission for a user based on their primary address.
mc_add_user_to_purge_listProDestructiveDESTRUCTIVE: this endpoint can be used to add internal or external users to the Purge List.
mc_create_userProWriteThis endpoint allows the creation of a new user within the account.
mc_create_user_mxProWriteThis endpoint can be used to create new cloud-users in Mimecast's Internal Directories.
mc_find_attribute_typesFreeRead-onlyThis API endpoint can be used to find account attribute types.
mc_find_delegate_usersFreeRead-onlyThis API endpoint provides the ability to return delegate permissions for a user based on their primary address.
mc_get_internal_usersFreeRead-onlyThis endpoint can be used to retrieve all internal users for a given domain.
mc_get_most_used_contactsFreeRead-onlyThis endpoint returns the most used contacts synced from Azure Active Directory.
mc_get_user_aliasesFreeRead-onlyThe get aliases endpoint can be used to retrieve aliases associated with a primary email address.
mc_get_user_attributesFreeRead-onlyThis endpoint can be used to retrieve attributes that are registered on the tenant, for a given user.
mc_get_user_import_statusFreeRead-onlyThis endpoint can the used to get the current status of a user import request, using /api/user/import-users.
mc_import_usersProDestructiveDESTRUCTIVE: the import users endpoint can be used to import users to an Internal Directory or a Profile Group.
mc_list_usersFreeRead-onlyGet internal users for account.
mc_remove_delegate_userProDestructiveDESTRUCTIVE: this API endpoint provides the ability to remove delegate permissions for a user based on their primary address.
mc_remove_user_aliasProDestructiveDESTRUCTIVE: the remove alias endpoint can be used to remove a alias that has been associated with a primary email address.
mc_remove_user_from_purge_listProDestructiveDESTRUCTIVE: this endpoint can be used to remove internal or external users from the Purge List in case you added them by accident.
mc_update_userProWriteThe update user endpoint can be used to update users within an Internal Directory.
mc_update_user_aliasProWriteThis API endpoint can be used to modify secondary email addresses for users.
mc_update_user_attributesProWriteThis API endpoint can be used to update a non-directory synced user's attributes.

[Mimecast] This API endpoint provides the ability to create a new delegate permission for a user based on their primary address. More information about delegates is available in Mimecaster Central. POST /api/user/add-delegate-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: delegateAddress, primaryAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to add internal or external users to the Purge List. The Purge List gets examined each evening as part of the nightly housekeeping tasks. Why this is destructive: queues the mailbox for purge; Mimecast removes its retained mail. POST /api/user/add-to-purge-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint allows the creation of a new user within the account. POST /user/cloud-gateway/v1/users. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: accountCode, emailAddress, name, password, forcePasswordChange. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] This endpoint can be used to create new cloud-users in Mimecast's Internal Directories. POST /api/user/create-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountCode, emailAddress, forcePasswordChange, name, password. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to find account attribute types. POST /api/attribute/find-attribute-types. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: filterBy, searchBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint provides the ability to return delegate permissions for a user based on their primary address. More information about delegates is availabile in Mimecaster Central. POST /api/user/find-delegate-users. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: primaryAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to retrieve all internal users for a given domain. POST /api/user/get-internal-users. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint returns the most used contacts synced from Azure Active Directory. POST /api/user/get-most-used-contacts. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] The get aliases endpoint can be used to retrieve aliases associated with a primary email address. POST /api/user/get-aliases. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to retrieve attributes that are registered on the tenant, for a given user. POST /api/user/get-attributes. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can the used to get the current status of a user import request, using /api/user/import-users. POST /api/user/get-import-status. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: the import users endpoint can be used to import users to an Internal Directory or a Profile Group. Why this is destructive: the x-mc-arg options include clearGroup, which EMPTIES the target Profile Group before the import runs - every member is taken out of the group and Mimecast keeps no copy, so a policy scoped to that group stops applying to anyone the import does not put back. POST /api/user/import-users. Email Security Cloud Gateway, MX-based deployments only. THE BODY IS THE FILE ITSELF, not a JSON payload: provide the import EITHER as CSV content in csvText OR as an XLS/XLSX workbook in contentBase64 or sourceUrl - exactly one of the two forms, never both and never neither. StackJack downloads an https URL server-side and refuses anything over 25 MB, a non-https URL, or a redirect to a different host. The import options travel in the x-mc-arg header, not in the body. This route is NOT one of Mimecast's legacy paginated routes despite its /api/ prefix: it takes no data array and no meta.pagination, and dataJson is refused for that reason. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
contentBase64stringnonullAn XLS/XLSX workbook's bytes as base64. Provide this OR sourceUrl OR csvText. Maximum 25 MB decoded.
csvTextstringnonullCSV content, sent verbatim as the request body. The first line is the header, e.g. "email,name,mobile" followed by one line per user. Provide this OR a file (contentBase64 / sourceUrl), never both.
dataJsonstringnonullNot used on this route. Mimecast takes the file content as the request body here, so there is no data array to put a payload in; supply csvText or a file instead. Passing it is refused rather than ignored.
fileNamestringnonullFile name of the workbook being imported, including its extension (e.g. users.xlsx). Required when you supply contentBase64 or sourceUrl; it is what decides the media type the bytes are sent as.
pageSizeintegernonullNot used on this route: an import is one call and returns one result, so there is nothing to page. Accepted only so a caller written against the previous shape does not break.
pageTokenstringnonullNot used on this route: an import is one call and returns one result, so there is nothing to page. Accepted only so a caller written against the previous shape does not break.
sourceUrlstringnonullPublic https URL StackJack downloads the workbook from. Provide this OR contentBase64 OR csvText. Maximum 25 MB.
xMcArgstringnonullOptional. A header carrying a JSON OBJECT, sent verbatim. Real JSON, exactly this shape: {"data":[{"notifyEmailAddress":"admin@example.com","allowAddressMigration":true,"groupId":"grp-123","clearGroup":false,"fileType":"csv"}]}. notifyEmailAddress is where Mimecast sends the import report, and fileType is csv or xlsx. clearGroup EMPTIES the named group before the import runs. Mimecast rejects the import when this header is not parseable JSON.

[Mimecast] Get internal users for account. GET /user/cloud-gateway/v1/users. Email Security Cloud Gateway. Optional filters: emailAddress, domain, includeAliases, pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringnonullOptional. Domain to filter by.
emailAddressstringnonullOptional. Email address to filter by.
includeAliasesbooleannonullOptional. Whether to include aliases in the result.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] DESTRUCTIVE: this API endpoint provides the ability to remove delegate permissions for a user based on their primary address. More information about delegates is availabile in Mimecaster Central. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/user/remove-delegate-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: the remove alias endpoint can be used to remove a alias that has been associated with a primary email address. Why this is destructive: removes the member, alias or delegate named in the request. POST /api/user/remove-alias. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: alias, aliasFor. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to remove internal or external users from the Purge List in case you added them by accident. Why this is destructive: changes retention for a mailbox already queued for purge. POST /api/user/remove-from-purge-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: emailAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] The update user endpoint can be used to update users within an Internal Directory. POST /api/user/update-user. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: accountDisabled, accountLocked, allowPop, allowSmtp, archiveStartDate, emailAddress, forcePasswordChange, name, password, passwordNeverExpires. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to modify secondary email addresses for users. POST /api/user/update-alias. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: alias, aliasFor. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to update a non-directory synced user's attributes. POST /api/user/update-attributes. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: attributes, emailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

DMARC DNS checks

ToolPlanAccessSummary
mc_check_dmarc_dns_bimiFreeRead-onlyGet BIMI record check.
mc_check_dmarc_dns_dkimFreeRead-onlyGet DKIM record check.
mc_check_dmarc_dns_dmarcFreeRead-onlyGet DMARC record check.
mc_check_dmarc_dns_spfFreeRead-onlyGet SPF record check.

[Mimecast] Get BIMI record check. GET /dmarc-analyzer/v1/dns/bimi. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringyesRequired. Domain for which the BIMI record is checked.

[Mimecast] Get DKIM record check. GET /dmarc-analyzer/v1/dns/dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringyesRequired. Domain for which the DKIM record is checked.
selectorstringyesRequired. DKIM selector to check.

[Mimecast] Get DMARC record check. GET /dmarc-analyzer/v1/dns/dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringyesRequired. Domain for which the DMARC record is checked.

[Mimecast] Get SPF record check. GET /dmarc-analyzer/v1/dns/spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: record. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringyesRequired. Domain for which the SPF record is checked.
recordstringnonullOptional. Optional SPF record to validate.

DMARC delegated domains

ToolPlanAccessSummary
mc_create_dmarc_delegated_dkim_selectorProWriteCreate a DKIM definition.
mc_create_dmarc_delegated_dmarc_recordProWriteCreate a DMARC definition.
mc_create_dmarc_delegated_domainProWriteCreate a delegated domain entry.
mc_delete_dmarc_delegated_dkim_allProDestructiveDESTRUCTIVE: delete all DKIM delegation for a domain.
mc_delete_dmarc_delegated_dkim_selectorProDestructiveDESTRUCTIVE: delete DKIM definition.
mc_delete_dmarc_delegated_dmarc_recordProDestructiveDESTRUCTIVE: delete DMARC definition.
mc_delete_dmarc_delegated_domains_bulkProDestructiveDESTRUCTIVE: delete delegated domains.
mc_delete_dmarc_delegated_spf_recordProDestructiveDESTRUCTIVE: delete SPF definition.
mc_get_dmarc_delegated_dkim_detailsFreeRead-onlyGet DKIM delegation details.
mc_get_dmarc_delegated_dkim_selectorFreeRead-onlyGet a DKIM definition.
mc_get_dmarc_delegated_dmarc_recordFreeRead-onlyGet DMARC definition.
mc_get_dmarc_delegated_domain_statisticsFreeRead-onlyGet delegated domains statistics.
mc_get_dmarc_delegated_spf_detailsFreeRead-onlyGet SPF definition details.
mc_get_dmarc_delegated_spf_recordFreeRead-onlyGet SPF definition.
mc_list_dmarc_delegated_dkim_selectorsFreeRead-onlyList DKIM definitions.
mc_list_dmarc_delegated_domainsFreeRead-onlyGet delegated domains.
mc_replace_dmarc_delegated_dkim_selectorProDestructiveDESTRUCTIVE: update a DKIM definition.
mc_replace_dmarc_delegated_spf_recordProDestructiveDESTRUCTIVE: update the SPF definition.

[Mimecast] Create a DKIM definition. POST /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: sourceId, version, selector, recordType, hostname, publicKey, serviceType, notes, flags. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Create a DMARC definition. POST /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: dmarcPolicyPresetId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Create a delegated domain entry. POST /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: items. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete all DKIM delegation for a domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] DESTRUCTIVE: delete DKIM definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.
selectorstringyesRequired. DKIM selector.

[Mimecast] DESTRUCTIVE: delete DMARC definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] DESTRUCTIVE: delete delegated domains. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated domain IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] DESTRUCTIVE: delete SPF definition. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Get DKIM delegation details. GET /dmarc-analyzer/v1/delegated-domains//dkim/details. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Get a DKIM definition. GET /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.
selectorstringyesRequired. DKIM selector.

[Mimecast] Get DMARC definition. GET /dmarc-analyzer/v1/delegated-domains//dmarc. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Get delegated domains statistics. GET /dmarc-analyzer/v1/delegated-domains/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get SPF definition details. GET /dmarc-analyzer/v1/delegated-domains//spf/details. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] Get SPF definition. GET /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.

[Mimecast] List DKIM definitions. GET /dmarc-analyzer/v1/delegated-domains//dkim. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Optional filters: pageSize, pageToken, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Unique identifier for the domain.
orderBystringnonullOptional. Sorting order for the result collection. Format is '\ -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] Get delegated domains. GET /dmarc-analyzer/v1/delegated-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, domain, domainDelegationStatus, dmarcDelegationStatus, dmarcPolicy, dkimDelegationStatus, spfDelegationStatus. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dkimDelegationStatusstringnonullOptional. DKIM delegation status to filter on. Comma-separated values in ONE string - not a JSON array.
dmarcDelegationStatusstringnonullOptional. DMARC delegation status to filter on. Comma-separated values in ONE string - not a JSON array.
dmarcPolicystringnonullOptional. DMARC policy value to filter on. Comma-separated values in ONE string - not a JSON array.
domainstringnonullOptional. Domain values to filter on.
domainDelegationStatusstringnonullOptional. Delegation status to filter on. Comma-separated values in ONE string - not a JSON array.
orderBystringnonullOptional. Sorting order for the result collection. Format is '\ -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
spfDelegationStatusstringnonullOptional. SPF delegation status to filter on. Comma-separated values in ONE string - not a JSON array.

[Mimecast] DESTRUCTIVE: update a DKIM definition. Why this is destructive: wholesale replace - the body becomes the whole DKIM definition for that selector, so a wrong or omitted public key stops mail signed with it authenticating. PUT /dmarc-analyzer/v1/delegated-domains//dkim/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId, selector. Send the request body as JSON (required). Documented body fields: sourceId, version, selector, recordType, hostname, publicKey, serviceType, notes, flags. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainIdstringyesRequired. Unique identifier for the domain.
selectorstringyesRequired. DKIM selector.

[Mimecast] DESTRUCTIVE: update the SPF definition. Why this is destructive: wholesale replace - the body becomes the delegated domain's ENTIRE published SPF record and `terms` is optional, so a body without it publishes a record that authorizes no sending source at all and every legitimate sender starts failing SPF. PUT /dmarc-analyzer/v1/delegated-domains//spf. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: domainId. Send the request body as JSON (required). Documented body fields: version, terms, allQualifier. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainIdstringyesRequired. Unique identifier for the domain.

DMARC detected domains

ToolPlanAccessSummary
mc_list_dmarc_detected_domainsFreeRead-onlyGet detected domains.
mc_set_dmarc_detected_domain_statusProWriteUpdate detected domain status.
mc_update_dmarc_detected_domainsProWriteBatch update detected domains status.

[Mimecast] Get detected domains. GET /dmarc-analyzer/v1/detected-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, domain, acceptanceStatus, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
acceptanceStatusstringnonullOptional. Filter detected domains by acceptance status.
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringnonullOptional. Domain values to filter on.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'. Supported columns - acceptanceStatus, createdAt, domain.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] Update detected domain status. PUT /dmarc-analyzer/v1/detected-domains//status. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Detected domain ID to update.

[Mimecast] Batch update detected domains status. PATCH /dmarc-analyzer/v1/detected-domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: ids, status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

DMARC domain groups

ToolPlanAccessSummary
mc_create_dmarc_domain_groupProWriteCreate a domain group.
mc_create_dmarc_domain_group_associationProWriteAdd domains to domain group.
mc_delete_dmarc_domain_group_associationProDestructiveDESTRUCTIVE: remove domains from domain group.
mc_delete_dmarc_domain_groups_bulkProDestructiveDESTRUCTIVE: delete domain groups.
mc_get_dmarc_domain_groupFreeRead-onlyGet a domain group.
mc_list_dmarc_domain_groupsFreeRead-onlyGet domain groups.
mc_update_dmarc_domain_groupProDestructiveDESTRUCTIVE: update a domain group.

[Mimecast] Create a domain group. POST /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: name, type, doesAutoIncludeOrgSubdomains, includeDomainsWithStatus, includedDomains, includeDomainsRegex. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Add domains to domain group. POST /dmarc-analyzer/v1/domain-groups//association. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Comma-separated domain IDs to add to the domain group. Comma-separated values in ONE string - not a JSON array.
idstringyesRequired. Domain group ID.

[Mimecast] DESTRUCTIVE: remove domains from domain group. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domain-groups//association. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Comma-separated domain IDs to remove from the domain group. Comma-separated values in ONE string - not a JSON array.
idstringyesRequired. Domain group ID.

[Mimecast] DESTRUCTIVE: delete domain groups. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated domain group IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get a domain group. GET /dmarc-analyzer/v1/domain-groups/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Optional filters: filterOnActivityStatus. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
filterOnActivityStatusbooleannonullOptional. When true (default), filter domains by the group's includeDomainsWithStatus. When false, return all domains in the group regardless of activity status.
idstringyesRequired. Unique identifier for the domain group.

[Mimecast] Get domain groups. GET /dmarc-analyzer/v1/domain-groups. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, ids, orderBy, filterOnActivityStatus, includeDomainsCount. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
filterOnActivityStatusbooleannonullOptional. When true (default), domain counts and listing respect the group's includeDomainsWithStatus. When false, counts and lists include all domains in the group regardless of activity status.
idsstringnonullOptional. Comma-separated domain group IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
includeDomainsCountbooleannonullOptional. Whether to include the domain count for each domain group.
namestringnonullOptional. Domain group name to filter on.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] DESTRUCTIVE: update a domain group. Why this is destructive: wholesale replace - includedDomains, includeDomainsWithStatus and includeDomainsRegex become exactly what the body carries, so a domain left out drops out of the group and every report, notification and policy scoped to that group stops covering it. PUT /dmarc-analyzer/v1/domain-groups/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: name, type, doesAutoIncludeOrgSubdomains, includeDomainsWithStatus, includedDomains, includeDomainsRegex. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Unique identifier for the domain group.

DMARC domains

ToolPlanAccessSummary
mc_create_dmarc_domainProWriteCreate a managed domain entry.
mc_delete_dmarc_domains_bulkProDestructiveDESTRUCTIVE: delete domains.
mc_get_dmarc_domainFreeRead-onlyGet a managed domain.
mc_get_dmarc_domain_statisticsFreeRead-onlyGet managed domain statistics.
mc_list_dmarc_domainsFreeRead-onlyGet managed domains.
mc_list_dmarc_vendor_configurationsFreeRead-onlyGet domain vendor configurations.
mc_refresh_dmarc_domain_dnsProWriteRefresh managed domain DNS records.
mc_update_dmarc_domainProWriteUpdate managed domain activity status.

[Mimecast] Create a managed domain entry. POST /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: items. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete domains. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated domain IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get a managed domain. GET /dmarc-analyzer/v1/domains/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Unique identifier for the domain.

[Mimecast] Get managed domain statistics. GET /dmarc-analyzer/v1/domains/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get managed domains. GET /dmarc-analyzer/v1/domains. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, domain, domains, ids, group, filterOnActivityStatus, activityStatus, status, dmarcPolicy, dmarcStatus, dmarcDelegation, dkimStatus, dkimDelegation, spfStatus, spfDelegation, dnsDelegation, presetFilter, createdAt. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
activityStatusstringnonullOptional. Activity status to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.
createdAtstringnonullOptional. Date range to filter domains by creation date. Must provide exactly 2 values - start and end dates. Supports formats - 2025-01-01T00 -00 -00. Comma-separated values in ONE string - not a JSON array.
dkimDelegationbooleannonullOptional. DKIM Delegation to filter on.
dkimStatusstringnonullOptional. DKIM Status to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.
dmarcDelegationbooleannonullOptional. DMARC Delegation to filter on.
dmarcPolicystringnonullOptional. DMARC Policy to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.
dmarcStatusstringnonullOptional. DMARC Status to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.
dnsDelegationstringnonullOptional. DNS Delegation status to filter on.
domainstringnonullOptional. Domain values to filter on.
domainsstringnonullOptional. Domain names to filter on (exact match). Multiple domains can be specified. Comma-separated values in ONE string - not a JSON array.
filterOnActivityStatusbooleannonullOptional. When true (default), filter domains by the group's includeDomainsWithStatus when filtering by group. When false, return all domains in the group regardless of activity status. Only applies when group is specified.
groupstringnonullOptional. Domain group ID to filter on.
idsstringnonullOptional. Comma-separated domain IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
presetFilterstringnonullOptional. Filter to apply for widget display.
spfDelegationbooleannonullOptional. SPF Delegation to filter on.
spfStatusstringnonullOptional. SPF Status to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.
statusstringnonullOptional. Status to filter on (multi-selection supported). Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get domain vendor configurations. GET /dmarc-analyzer/v1/domains/vendor-configurations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: domainIds, domains. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdsstringnonullOptional. List of domain IDs to filter on. Either domainIds or domains must be provided. Comma-separated values in ONE string - not a JSON array.
domainsstringnonullOptional. List of domain names to filter on. Either domainIds or domains must be provided. Comma-separated values in ONE string - not a JSON array.
sourceIdstringyesRequired. Source ID (required).

[Mimecast] Refresh managed domain DNS records. POST /dmarc-analyzer/v1/domains//refresh-dns. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Unique identifier for the domain.

[Mimecast] Update managed domain activity status. PATCH /dmarc-analyzer/v1/domains/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Mimecast applies this body as an RFC 7386 merge patch (Content-Type application/merge-patch+json), so a field you omit is left unchanged and a field you set to null is REMOVED - null is not the same as omitting it. Documented body fields: activityStatus. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON, applied as an RFC 7386 merge patch - a field set to null is REMOVED.
idstringyesRequired. Unique identifier for the domain.

DMARC policy presets

ToolPlanAccessSummary
mc_create_dmarc_policy_presetProDestructiveDESTRUCTIVE: create a new DMARC policy preset.
mc_delete_dmarc_policy_presets_bulkProDestructiveDESTRUCTIVE: delete a DMARC policy preset by ID.
mc_list_dmarc_policy_presetsFreeRead-onlyGet DMARC policy presets.
mc_update_dmarc_policy_presetProDestructiveDESTRUCTIVE: update a DMARC policy preset by ID.

[Mimecast] DESTRUCTIVE: create a new DMARC policy preset. Why this is destructive: a DMARC policy preset is applied to managed domains, and a preset at p=reject tells receiving mail servers to DISCARD mail that fails authentication - misconfigured, it stops legitimate mail being delivered. POST /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: version, policy, subdomainPolicy, ruaAddresses, rufAddresses, dkimAlignment, spfAlignment, reportInterval, failureReportingOptions, failureReportFormat, percentage, name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete a DMARC policy preset by ID. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated preset IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get DMARC policy presets. GET /dmarc-analyzer/v1/dmarc-policy-preset. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, id, name, policy, subdomainPolicy, dkimAlignment, spfAlignment, orderBy, isDefaultPolicy, failureReportingOptions, ruaEmails, rufEmails. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dkimAlignmentstringnonullOptional. Comma-separated values in ONE string - not a JSON array.
failureReportingOptionsstringnonullOptional. Filter by failure reporting options. Comma-separated values in ONE string - not a JSON array.
idstringnonullOptional. ID of the preset. Comma-separated values in ONE string - not a JSON array.
isDefaultPolicybooleannonullOptional. Filter by default policy.
namestringnonullOptional. Name of the preset.
orderBystringnonullOptional. Sorting order for the result collection. Format is '\ -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
policystringnonullOptional. DMARC policy to filter on. Comma-separated values in ONE string - not a JSON array.
ruaEmailsstringnonullOptional. Filter by rua emails. Comma-separated values in ONE string - not a JSON array.
rufEmailsstringnonullOptional. Filter by ruf emails. Comma-separated values in ONE string - not a JSON array.
spfAlignmentstringnonullOptional. Comma-separated values in ONE string - not a JSON array.
subdomainPolicystringnonullOptional. DMARC subdomain policy to filter on. Comma-separated values in ONE string - not a JSON array.

[Mimecast] DESTRUCTIVE: update a DMARC policy preset by ID. Why this is destructive: wholesale replace of a DMARC policy preset already applied to managed domains - moving it to p=reject tells receiving mail servers to DISCARD mail that fails authentication, and anything omitted from the body is cleared. PUT /dmarc-analyzer/v1/dmarc-policy-preset/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: presetId. Send the request body as JSON (required). Documented body fields: version, policy, subdomainPolicy, ruaAddresses, rufAddresses, dkimAlignment, spfAlignment, reportInterval, failureReportingOptions, failureReportFormat, percentage, name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
presetIdstringyesRequired. ID of the DMARC policy preset.

DMARC compliance

ToolPlanAccessSummary
mc_get_dmarc_compliance_statisticsFreeRead-onlyGet DMARC compliance statistics.
mc_list_dmarc_dns_suggestionsFreeRead-onlyGet DNS configuration suggestions for all domains.
mc_list_dmarc_enforcementFreeRead-onlyGet domains eligible for DMARC policy enforcement.
mc_list_dmarc_policy_changesFreeRead-onlyGet DMARC policy changes from data platform.

[Mimecast] Get DMARC compliance statistics. GET /dmarc-analyzer/v1/compliance/dmarc/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: domainIds, groupIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdsstringnonullOptional. Comma-separated domain IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
groupIdsstringnonullOptional. Comma-separated domain group IDs to retrieve. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get DNS configuration suggestions for all domains. GET /dmarc-analyzer/v1/compliance/domains/dns-suggestions. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] Get domains eligible for DMARC policy enforcement. GET /dmarc-analyzer/v1/compliance/domains/enforcement. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get DMARC policy changes from data platform. GET /dmarc-analyzer/v1/compliance/domains/dmarc-policy-changes. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

DMARC customer settings

ToolPlanAccessSummary
mc_delete_dmarc_encryption_keyProDestructiveDESTRUCTIVE: delete customer PGP key.
mc_get_dmarc_customerFreeRead-onlyGet customer details.
mc_get_dmarc_encryption_keyFreeRead-onlyGet customer PGP key.
mc_replace_dmarc_encryption_keyProDestructiveDESTRUCTIVE: save customer PGP key.

[Mimecast] DESTRUCTIVE: delete customer PGP key. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get customer details. GET /dmarc-analyzer/v1/customers/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: identifier. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
identifierstringyesRequired. Unique customer account code, customer UUID, or report code.

[Mimecast] Get customer PGP key. GET /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] DESTRUCTIVE: save customer PGP key. Why this is destructive: wholesale replace of the PGP key Mimecast encrypts this customer's forensic reports to - reports already delivered stay encrypted to the old key, so replacing it silently breaks decryption for everything that arrives afterwards unless the matching private key is in place. PUT /dmarc-analyzer/v1/customers/encryption-key. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: type, key, expiryTimestamp. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

DMARC events and issues

ToolPlanAccessSummary
mc_delete_dmarc_issues_bulkProDestructiveDESTRUCTIVE: delete issues.
mc_list_dmarc_eventsFreeRead-onlyGet events.
mc_list_dmarc_issuesFreeRead-onlyGet issues.

[Mimecast] DESTRUCTIVE: delete issues. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/issues. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idsstringyesRequired. Issue IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get events. GET /dmarc-analyzer/v1/events. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, startDate, endDate, domainId, group, eventType, recordType, handle. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringnonullOptional. Domain ID to filter on.
endDatestringnonullOptional. End date (exclusive) to retrieve data up to. Required for initial query, not needed when using handle for pagination.
eventTypestringnonullOptional. DNS event type to filter on.
groupstringnonullOptional. Domain group ID to filter on.
handlestringnonullOptional. Data Platform query handle for pagination continuation.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
recordTypestringnonullOptional. DNS record type to filter on. Comma-separated values in ONE string - not a JSON array.
startDatestringnonullOptional. Start date (inclusive) to retrieve data from. Required for initial query, not needed when using handle for pagination.

[Mimecast] Get issues. GET /dmarc-analyzer/v1/issues. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, ids, domainId, domain, group, recordType. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainstringnonullOptional. Domain values to filter on.
domainIdstringnonullOptional. Domain ID to filter on.
groupstringnonullOptional. Domain group ID to filter on.
idsstringnonullOptional. Issue IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
recordTypestringnonullOptional. DNS record type to filter on. Comma-separated values in ONE string - not a JSON array.

DMARC notifications

ToolPlanAccessSummary
mc_create_dmarc_notificationProWriteCreate notification.
mc_delete_dmarc_notifications_bulkProDestructiveDESTRUCTIVE: delete a notification.
mc_get_dmarc_notificationFreeRead-onlyGet a notification.
mc_list_dmarc_notificationsFreeRead-onlyList notifications.
mc_update_dmarc_notificationProDestructiveDESTRUCTIVE: update a notification.

[Mimecast] Create notification. POST /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: type. Send the request body as JSON (required). Documented body fields: email, frequency, domains, groups, triggerConfig. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
typestringyesRequired. Type of notification.

[Mimecast] DESTRUCTIVE: delete a notification. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/notifications. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idsstringyesRequired. Comma-separated notification IDs to delete. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get a notification. GET /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Unique identifier for the notification.

[Mimecast] List notifications. GET /dmarc-analyzer/v1/notifications. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, type, ids, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idsstringnonullOptional. Comma-separated notification IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
typestringnonullOptional. Type of notification.

[Mimecast] DESTRUCTIVE: update a notification. Why this is destructive: wholesale replace - domains, groups and triggerConfig become exactly what the body carries, so a domain or group left out stops being notified and nobody is told that DMARC failures on it went unreported. PUT /dmarc-analyzer/v1/notifications/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: email, frequency, domains, groups, triggerConfig. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Unique identifier for the notification.

DMARC reports

ToolPlanAccessSummary
mc_download_dmarc_forensic_reportProRead-onlyDownload a DMARC forensic (failure) report.
mc_get_dmarc_report_resultsFreeRead-onlyGet paginated report results.
mc_list_dmarc_report_metadataFreeRead-onlyGet report metadata.
mc_query_dmarc_reportFreeRead-onlyQuery report data.

[Mimecast] Download a DMARC forensic (failure) report. GET /dmarc-analyzer/v1/reports/forensic/download. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. This is the only Mimecast endpoint that answers a file rather than JSON, so instead of the bytes you get a JSON envelope with sasUrl (a TEMPORARY read-only download link, valid for 30 minutes), contentType, suggestedFileName, sizeBytes and expiresAt; expiresAt is the link's real expiry, not a restated duration. Fetch the link before it expires - nothing else in StackJack keeps a copy. The report itself is ENCRYPTED to the PGP key stored for the customer (mc_get_dmarc_encryption_key reads it), so the downloaded file is ciphertext unless no key is configured; StackJack cannot decrypt it. Requires the DMARC Analyzer product with report read permission. MSP: pass accountCode to act on a managed customer; omit it to act on your own account.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pathstringyesRequired. The report's storage path, exactly as a DMARC report listing supplied it. Sent as the vendor's path query parameter.

[Mimecast] Get paginated report results. GET /dmarc-analyzer/v1/reports//results/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id, handle. Optional filters: pageToken, pageSize. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
handlestringyesRequired. Unique handle that was returned by the original request's response.
idstringyesRequired. Unique identifier for the report.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 500. For chart endpoints, use higher values to get complete time-series data. Mimecast allows up to 500 on this route, but StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] Get report metadata. GET /dmarc-analyzer/v1/report-metadata. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated report IDs for which metadata is requested. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Query report data. POST /dmarc-analyzer/v1/reports/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Optional filters: pageSize, domainGroupIds. Send the request body as JSON (required). Paging: pageSize (default 50) travels in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. This route takes no pageToken: it answers meta.handle and meta.nextPage, and mc_get_dmarc_report_results walks the pages from them. Documented body fields: timestampRangeStartsAt, timestampRangeEndsAt, projections, searchClause, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainGroupIdsstringnonullOptional. List of domain group IDs. Comma-separated values in ONE string - not a JSON array.
idstringyesRequired. Unique identifier for the report.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 500. For chart endpoints, use higher values to get complete time-series data. Mimecast allows up to 500 on this route, but StackJack sends at most 100 per request.

DMARC sources

ToolPlanAccessSummary
mc_create_dmarc_source_vendor_associationProWriteAssociate a vendor with a customer.
mc_delete_dmarc_source_vendor_associationProDestructiveDESTRUCTIVE: delete vendor association.
mc_get_dmarc_source_compliance_statisticsFreeRead-onlyGet source compliance statistics.
mc_get_dmarc_source_vendorFreeRead-onlyGet a single vendor.
mc_list_dmarc_source_compliance_actionsFreeRead-onlyGet compliance actions.
mc_list_dmarc_source_vendorsFreeRead-onlyGet vendors.
mc_list_dmarc_sourcesFreeRead-onlyGet sources.
mc_update_dmarc_source_vendorProWriteUpdate vendor status.

[Mimecast] Associate a vendor with a customer. POST /dmarc-analyzer/v1/sources/vendors/associations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete vendor association. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/sources/vendors/associations. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Comma-separated vendor IDs to disassociate. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get source compliance statistics. GET /dmarc-analyzer/v1/sources/compliance/statistics. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get a single vendor. GET /dmarc-analyzer/v1/sources/vendors/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Unique identifier of the vendor.

[Mimecast] Get compliance actions. GET /dmarc-analyzer/v1/sources/compliance/actions. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get vendors. GET /dmarc-analyzer/v1/sources/vendors. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, ids, category, includeArchived, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
categorystringnonullOptional. Vendor category to filter on.
idsstringnonullOptional. Comma-separated vendor IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
includeArchivedbooleannonullOptional. Include archived sources in the result.
namestringnonullOptional. Vendor name to filter on.
orderBystringnonullOptional. Sorting order for the result collection. Format is '\ -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] Get sources. GET /dmarc-analyzer/v1/sources. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, name, hostnames, category, includeArchived, ids, status, createdAt, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
categorystringnonullOptional. Source category to filter on.
createdAtstringnonullOptional. Date range to filter sources by creation date. Must provide exactly 2 values - start and end dates. Format - 2025-01-01T00 -00 -00. Comma-separated values in ONE string - not a JSON array.
hostnamesstringnonullOptional. Source hostname to filter on. Comma-separated values in ONE string - not a JSON array.
idsstringnonullOptional. Comma-separated source IDs to retrieve. Comma-separated values in ONE string - not a JSON array.
includeArchivedbooleannonullOptional. Include archived sources in the result.
namestringnonullOptional. Source name to filter on.
orderBystringnonullOptional. Sorting order for the result collection. Format is '\ -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
statusstringnonullOptional. Comma-separated source statuses to filter on. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Update vendor status. PATCH /dmarc-analyzer/v1/sources/vendors/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Mimecast applies this body as an RFC 7386 merge patch (Content-Type application/merge-patch+json), so a field you omit is left unchanged and a field you set to null is REMOVED - null is not the same as omitting it. Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON, applied as an RFC 7386 merge patch - a field set to null is REMOVED.
idstringyesRequired. Unique identifier for the vendor.

DMARC tasks

ToolPlanAccessSummary
mc_create_dmarc_taskProWriteCreate a new task.
mc_delete_dmarc_tasks_bulkProDestructiveDESTRUCTIVE: delete or archive tasks.
mc_get_dmarc_taskFreeRead-onlyGet a task by ID.
mc_get_dmarc_task_summaryFreeRead-onlyGet task summary by status.
mc_list_dmarc_tasksFreeRead-onlyGet all tasks (paginated).
mc_replace_dmarc_taskProDestructiveDESTRUCTIVE: update a task.
mc_update_dmarc_taskProWritePartially update a task.

[Mimecast] Create a new task. POST /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: title, type, status, description, entities. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete or archive tasks. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idsstringyesRequired. Comma-separated task IDs to delete or archive. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Get a task by ID. GET /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Task ID.

[Mimecast] Get task summary by status. GET /dmarc-analyzer/v1/tasks/summary. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: archived. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
archivedbooleannonullOptional. Filter archived tasks.

[Mimecast] Get all tasks (paginated). GET /dmarc-analyzer/v1/tasks. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, orderBy, ids, title, type, status, archived. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
archivedbooleannonullOptional. Filter archived tasks.
idsstringnonullOptional. Filter by task IDs. Comma-separated values in ONE string - not a JSON array.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.
statusstringnonullOptional. Filter by task statuses. Comma-separated values in ONE string - not a JSON array.
titlestringnonullOptional. Filter by task title.
typestringnonullOptional. Filter by task types. Comma-separated values in ONE string - not a JSON array.

[Mimecast] DESTRUCTIVE: update a task. Why this is destructive: wholesale replace - Mimecast publishes a PATCH twin on this same path for partial edits, so the PUT body becomes the WHOLE task and a title, status, description, type or entity left out of it is gone. PUT /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: title, status, description, type, entities. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Task ID.

[Mimecast] Partially update a task. PATCH /dmarc-analyzer/v1/tasks/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. The unique identifier of the task.

DMARC users

ToolPlanAccessSummary
mc_create_dmarc_userProWriteAdd a new user.
mc_delete_dmarc_userProDestructiveDESTRUCTIVE: delete a user.
mc_get_dmarc_current_userFreeRead-onlyGet current user.
mc_get_dmarc_userFreeRead-onlyGet user details.
mc_list_dmarc_usersFreeRead-onlyGet all user details (paginated).
mc_update_dmarc_userProDestructiveDESTRUCTIVE: update a user.

[Mimecast] Add a new user. POST /dmarc-analyzer/v1/users. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Send the request body as JSON (required). Documented body fields: userName, userEmail, userPermission, allowedGroups, features. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete a user. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Unique identifier for the user.

[Mimecast] Get current user. GET /dmarc-analyzer/v1/users/current-user. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Get user details. GET /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: idOrEmail. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idOrEmailstringyesRequired. User ID or email address.

[Mimecast] Get all user details (paginated). GET /dmarc-analyzer/v1/users. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Optional filters: pageSize, pageToken, email, name, orderBy. Paging: pageSize (default 50) and pageToken travel in the QUERY STRING on DMARC Analyzer, not in the request body - the pageSize parameter names this route's own maximum, which is not the same on every route. The response carries meta.nextPage; stop when it is absent. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
emailstringnonullOptional. Filter by user email addresses. Comma-separated values in ONE string - not a JSON array.
namestringnonullOptional. Filter by user name.
orderBystringnonullOptional. Sorting order for the result collection. Format is ' -[asc|desc]'.
pageSizeintegernonullOptional. Requested page size. Min - 1, Max - 100. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination token of the requested page.

[Mimecast] DESTRUCTIVE: update a user. Why this is destructive: a privilege change - userPermission, allowedGroups and features are replaced wholesale, so a permission omitted from the body is taken away from that DMARC Analyzer user. PUT /dmarc-analyzer/v1/users/. Mimecast DMARC Analyzer - requires the DMARC Analyzer product on the Mimecast API application; a 401 or 403 app_forbidden here means the application is missing that product, not that the credential is wrong. Path parameters: id. Send the request body as JSON (required). Documented body fields: userPermission, allowedGroups, features. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Unique identifier for the user.

Domain onboarding

ToolPlanAccessSummary
mc_create_domainProWriteThis endpoint can be used to add new domains to your Mimecast account.
mc_create_pending_domainProWriteCreates one or more “pending” domains that must be verified.
mc_delete_pending_domainProDestructiveDESTRUCTIVE: deletes an unverified domain.
mc_delete_pending_domain_mxProDestructiveDESTRUCTIVE: delete a pending domain.
mc_generate_pending_domain_tokenProWriteReturns the code to be added to TXT records of the new domain and also extends the expiry of the code to 30 days from the time of the request.
mc_get_pending_domainFreeRead-onlyGets a single pending domain.
mc_get_pending_domain_mxFreeRead-onlyRetrieve pending domain information.
mc_get_provision_statusFreeRead-onlyRetrieve provisioning status for a pending domain.
mc_get_verification_codeFreeRead-onlyRetrieve verification code for a pending domain.
mc_list_pending_domainsFreeRead-onlyGets all pending domains.
mc_verify_domainProWriteVerify a pending domain.
mc_verify_pending_domainProWriteVerifies a pending domain via TXT record and moves it from pending to registered.

[Mimecast] This endpoint can be used to add new domains to your Mimecast account. POST /api/domain/create-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Creates one or more “pending” domains that must be verified. Multiple domains created will all share the same verification token. POST /domain/cloud-gateway/v1/pending-domains. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: deletes an unverified domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /domain/cloud-gateway/v1/pending-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Pending domain id.

[Mimecast] DESTRUCTIVE: delete a pending domain. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/domain/delete-pending-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Returns the code to be added to TXT records of the new domain and also extends the expiry of the code to 30 days from the time of the request. POST /domain/cloud-gateway/v1/pending-domains/generate-token. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Gets a single pending domain. GET /domain/cloud-gateway/v1/pending-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Pending domain id.

[Mimecast] Retrieve pending domain information. POST /api/domain/get-pending-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieve provisioning status for a pending domain. POST /api/domain/get-provision-status. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Retrieve verification code for a pending domain. POST /api/domain/get-verification-code. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Gets all pending domains. Additional Information Pending domains will return the verification token in the response but it will NOT be updated. GET /domain/cloud-gateway/v1/pending-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Verify a pending domain. POST /api/domain/verify-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain, inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Verifies a pending domain via TXT record and moves it from pending to registered. POST /domain/cloud-gateway/v1/pending-domains/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

External domains

ToolPlanAccessSummary
mc_get_external_domainFreeRead-onlyGets a single external domain.
mc_list_external_domainsFreeRead-onlyGets a list all external domains.

[Mimecast] Gets a single external domain. GET /domain/cloud-gateway/v1/external-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. External domain id.

[Mimecast] Gets a list all external domains. GET /domain/cloud-gateway/v1/external-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

Internal domains

ToolPlanAccessSummary
mc_get_internal_domainFreeRead-onlyGets a single internal domain.
mc_get_internal_domain_dns_recordsFreeRead-onlyReturns the DNS record lookup for internal domain.
mc_get_internal_domain_mxFreeRead-onlyRetrieve internal domain information.
mc_list_internal_domainsFreeRead-onlyGets a list all internal domains.
mc_lookup_m365_internal_domainsFreeRead-onlyReturns domains from the Microsoft 365 tenant linked to the specified M365 directory integration instance.
mc_register_m365_internal_domainsProWriteRegisters one or more internal domains from the Microsoft 365 tenant associated with the specified M365 directory integration instance.
mc_update_internal_domainProWriteUpdates an internal domain.
mc_verify_internal_domainProWriteThe Api endpoint checks all the internal domains to ensure the customer has updated their MX records correctly.

[Mimecast] Gets a single internal domain. GET /domain/cloud-gateway/v1/internal-domains/. Email Security Cloud Gateway. Path parameters: domain_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Domain id.

[Mimecast] Returns the DNS record lookup for internal domain. GET /domain/cloud-gateway/v1/internal-domains//dns-records/. Email Security Cloud Gateway. Path parameters: domain_id, record_type. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
domainIdstringyesRequired. Domain id.
recordTypestringyesRequired. Record type to lookup.

[Mimecast] Retrieve internal domain information. POST /api/domain/get-internal-domain. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domain. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Gets a list all internal domains. GET /domain/cloud-gateway/v1/internal-domains. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Returns domains from the Microsoft 365 tenant linked to the specified M365 directory integration instance. GET /domain/cloud-gateway/v1/internal-domains/m365//lookup. Email Security Cloud Gateway. Path parameters: integration_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
integrationIdstringyesRequired. UUID of the M365 directory integration instance.

[Mimecast] Registers one or more internal domains from the Microsoft 365 tenant associated with the specified M365 directory integration instance. POST /domain/cloud-gateway/v1/internal-domains/m365//register. Email Security Cloud Gateway. Path parameters: integration_id. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
integrationIdstringyesRequired. UUID of the M365 directory integration instance.

[Mimecast] Updates an internal domain. PATCH /domain/cloud-gateway/v1/internal-domains/. Email Security Cloud Gateway. Path parameters: domain_id. Send the request body as JSON (required). Documented body fields: inboundType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
domainIdstringyesRequired. Domain id.

[Mimecast] The Api endpoint checks all the internal domains to ensure the customer has updated their MX records correctly. POST /domain/cloud-gateway/v1/internal-domains/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: domains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Protection mode

ToolPlanAccessSummary
mc_update_protection_modeProWriteUpdates the account protection mode (gateway or gatewayless).

[Mimecast] Updates the account protection mode (gateway or gatewayless). PATCH /email/cloud-gateway/v1/protection-mode. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: mode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Gateway configuration

ToolPlanAccessSummary
mc_delete_outbound_ip_addressesProDestructiveDESTRUCTIVE: deletes all outbound IP Addresses for customer’s mail platform.
mc_get_email_statisticsFreeRead-onlyThis endpoint can be used to the email statistics for an account.This can used to check that mail delivery is working.
mc_get_gateway_detailsFreeRead-onlyReturns outbound config information such as hostnames, mail platform(s).
mc_list_outbound_ip_addressesFreeRead-onlyGets list of all outbound IP Addresses for customer’s mail platform.
mc_replace_outbound_ip_addressesProDestructiveDESTRUCTIVE: replaces all outbound IP Addresses for customer’s mail platform.
mc_update_gateway_detailsProWriteUpdates outbound config information such as Outbound enabled flag mail platform(s), updates umbrella accounts when mail platform is M365, GSuite or Google workspace.

[Mimecast] DESTRUCTIVE: deletes all outbound IP Addresses for customer’s mail platform. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This endpoint can be used to the email statistics for an account.This can used to check that mail delivery is working. GET /email/cloud-gateway/v1/statistics. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Returns outbound config information such as hostnames, mail platform(s). Additionally, it also returns SPF record and inbound MX Record used by the customer. GET /email/cloud-gateway/v1/gateway-details. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Gets list of all outbound IP Addresses for customer’s mail platform. GET /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] DESTRUCTIVE: replaces all outbound IP Addresses for customer’s mail platform. Why this is destructive: wholesale replace - the body becomes the entire outbound IP allow list, so any address omitted from it stops being able to send mail through Mimecast. PUT /email/cloud-gateway/v1/outbound-ip-addresses. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: outboundIpAddresses. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Updates outbound config information such as Outbound enabled flag mail platform(s), updates umbrella accounts when mail platform is M365, GSuite or Google workspace. PATCH /email/cloud-gateway/v1/gateway-details. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: outboundEnabled, outboundIpAddresses, mailPlatform. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Held messages

ToolPlanAccessSummary
mc_find_held_messagesFreeRead-onlyThis API endpoint can be used to find messages currently held for review, including the hold reason, hold group, policy information, sender and recipients.
mc_get_hold_message_listFreeRead-onlyThis API endpoint can be used to get information about held messages, including the reason, hold level, sender and recipients.
mc_get_hold_summary_listFreeRead-onlyThis API endpoint can be used to get counts of currently held messages for each hold reason.
mc_reject_held_messagesProDestructiveDESTRUCTIVE: this API endpoint can be used to reject a currently held message based on the Find Held Messages API endpoint.
mc_release_held_messagesProDestructiveDESTRUCTIVE: this API endpoint can be used to release a currently held message based on the Find Held Messages API endpoint.

[Mimecast] This API endpoint can be used to find messages currently held for review, including the hold reason, hold group, policy information, sender and recipients. POST /api/gateway/find-held-messages. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, filterBy, mailbox, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get information about held messages, including the reason, hold level, sender and recipients. POST /api/gateway/get-hold-message-list. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: admin, end, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to get counts of currently held messages for each hold reason. Hold reasons can reference policy actions or definition names. POST /api/gateway/get-hold-summary-list. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] DESTRUCTIVE: this API endpoint can be used to reject a currently held message based on the Find Held Messages API endpoint. Why this is destructive: the held message is discarded and the sender is notified that it was rejected. POST /api/gateway/hold-reject. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: ids, message, notify, reasonType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this API endpoint can be used to release a currently held message based on the Find Held Messages API endpoint. Why this is destructive: a released message is delivered to the recipient's mailbox immediately and cannot be recalled. POST /api/gateway/hold-release. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Journaling

ToolPlanAccessSummary
mc_create_journaling_serviceProWriteWhen the customer subscribes to Internal Email Protect, Continuity or Archiving we need to ensure that internal messages (that normally remain internal to the customers' email infrastructure) get.
mc_delete_journaling_serviceProDestructiveDESTRUCTIVE: this endpoint deletes journaling connector specified with the journaling id in the endpoint.
mc_get_journaling_serviceFreeRead-onlyThis endpoint returns journaling connector, their configuration and current status specified with the journaling id in the endpoint.
mc_get_journaling_service_mxFreeRead-onlyThis endpoint returns journaling connectors, their configuration and current status.
mc_list_journaling_servicesFreeRead-onlyThis endpoint returns all journaling connectors, their configuration and current status within the customer’s account.
mc_update_journaling_serviceProWriteThe endpoint updates journaling connector specified in the journaling id.

[Mimecast] When the customer subscribes to Internal Email Protect, Continuity or Archiving we need to ensure that internal messages (that normally remain internal to the customers' email infrastructure) get. POST /journaling/cloud-gateway/v1/services. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, enabled, messageFormat, removeJournalHeaders, journalNonInternalAddresses, journalUnknownInternalAddresses, smtpJournalingConnection, pop3JournalingConnection. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: this endpoint deletes journaling connector specified with the journaling id in the endpoint. This endpoint is used to create journaling connector. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
journalingIdintegeryesRequired. ID of the journaling service.

[Mimecast] This endpoint returns journaling connector, their configuration and current status specified with the journaling id in the endpoint. GET /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
journalingIdintegeryesRequired. ID of the journaling service.

[Mimecast] This endpoint returns journaling connectors, their configuration and current status. POST /api/journaling/get-service. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint returns all journaling connectors, their configuration and current status within the customer’s account. GET /journaling/cloud-gateway/v1/services. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] The endpoint updates journaling connector specified in the journaling id. PATCH /journaling/cloud-gateway/v1/services/. Email Security Cloud Gateway. Path parameters: journaling_id. Send the request body as JSON (optional). Documented body fields: description, enabled, messageFormat, removeJournalHeaders, journalNonInternalAddresses, journalUnknownInternalAddresses, transferProtocol, smtpJournalingConnection, pop3JournalingConnection. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringnonullOptional. The request body as JSON.
journalingIdintegeryesRequired. ID of the journaling service.

Managed senders

ToolPlanAccessSummary
mc_bulk_delete_managed_internal_addressesProDestructiveDESTRUCTIVE: delete all Managed Senders entries that contain internal recipients as senders on the account.
mc_bulk_delete_managed_recipient_sendersProDestructiveDESTRUCTIVE: delete Managed Senders entries for a specific internal recipient.
mc_bulk_delete_managed_sendersProDestructiveDESTRUCTIVE: delete Managed Senders entries based on sender email addresses or sender domains in addition to optional filtering criteria (Type, Action and Trusted).
mc_permit_or_block_senderProDestructiveDESTRUCTIVE: permit or block a managed sender.

[Mimecast] DESTRUCTIVE: delete all Managed Senders entries that contain internal recipients as senders on the account. Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/internal-addresses/bulk-delete. Email Security Cloud Gateway. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] DESTRUCTIVE: delete Managed Senders entries for a specific internal recipient. Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/recipients//bulk-delete. Email Security Cloud Gateway. Path parameters: recipient_email. Send the request body as JSON (optional). Documented body fields: ids. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringnonullOptional. The request body as JSON.
recipientEmailstringyesRequired. Recipient Email

[Mimecast] DESTRUCTIVE: delete Managed Senders entries based on sender email addresses or sender domains in addition to optional filtering criteria (Type, Action and Trusted). Why this is destructive: deletes every entry the request names in one call. POST /email/cloud-gateway/v1/managed-senders/senders/bulk-delete. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: ids, type, action, trusted. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: permit or block a managed sender. Why this is destructive: changes whether that sender's mail reaches the recipient at all. POST /api/managedsender/permit-or-block-sender. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: action, sender, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Message tracking

ToolPlanAccessSummary
mc_decode_ttp_urlFreeRead-onlyPre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Account | Dashboard | Read.
mc_find_processing_messagesFreeRead-onlyThis API endpoint will return messages currently being processed by Mimecast.
mc_get_email_queuesFreeRead-onlyThis endpoint can be used to get the count of the inbound and outbound email queues at specified times.
mc_get_gateway_message_fileFreeRead-onlyThis API endpoint can be used to retrieve the file or attachment for given id.
mc_get_message_infoFreeRead-onlyThis API endpoint can be used to retrieve detailed information about a specific message.
mc_search_messagesFreeRead-onlySearch for messages.

[Mimecast] Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Account | Dashboard | Read. POST /api/ttp/url/decode-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint will return messages currently being processed by Mimecast. POST /api/gateway/find-processing-messages. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, sortBy, sortOrder, start, type. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to get the count of the inbound and outbound email queues at specified times. POST /api/email/get-email-queues. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to retrieve the file or attachment for given id. POST /api/gateway/message/get-file. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. This answers a JSON envelope, NOT the file itself: data[].urls carries short-lived pre-signed download URLs on Mimecast's own storage host. Fetch a URL yourself and promptly - StackJack proxies none of those bytes and cannot refresh an expired link. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to retrieve detailed information about a specific message. POST /api/message-finder/get-message-info. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Search for messages. POST /api/message-finder/search. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: advancedTrackAndTraceOptions, attachments, end, messageId, route, searchReason, start, status. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Outbound email

ToolPlanAccessSummary
mc_send_emailProDestructiveDESTRUCTIVE: this API endpoint can be used to send an email.
mc_upload_email_fileProWriteUpload a file so it can be attached to an outbound email.

[Mimecast] DESTRUCTIVE: this API endpoint can be used to send an email. Why this is destructive: sends a real email from your Mimecast account; it lands in the recipients' mailboxes immediately and cannot be recalled. POST /api/email/send-email. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Documented body fields: attachments, bcc, cc, extraHeaders, from, htmlBody, inReplyTo, plainBody, subject, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.

[Mimecast] Upload a file so it can be attached to an outbound email. POST /api/file/file-upload. Email Security Cloud Gateway, MX-based deployments only. Provide the file EITHER as base64 in contentBase64 OR as a public https URL in sourceUrl - exactly one of the two, never both. StackJack downloads an https URL server-side and refuses anything over 25 MB, a non-https URL, or a redirect to a different host. THIS DOES NOT SEND ANYTHING BY ITSELF and nothing reaches a recipient: the response is Mimecast's raw JSON, whose data[].urls carries the stored file's pre-signed URL, and the message is only sent when mc_send_email is called afterwards. Mimecast's own x-mc-arg header (the file's SHA-256 and byte length) is computed from the uploaded bytes, so there is nothing to pass for it. Requires an application with Account | Dashboard | Read permission. MSP: pass accountCode to act on a managed customer; omit it to act on your own account.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
contentBase64stringnonullThe file's bytes as base64. Provide this OR sourceUrl, not both. Maximum 25 MB decoded.
fileNamestringyesRequired. File name to store the upload under, including its extension (e.g. report.pdf).
sourceUrlstringnonullPublic https URL StackJack downloads the file from. Provide this OR contentBase64, not both. Maximum 25 MB.

Cloud Integrated policies

ToolPlanAccessSummary
mc_create_ci_policyProWriteAdd a policy.
mc_delete_ci_policyProDestructiveDESTRUCTIVE: delete a policy.
mc_get_ci_default_policyFreeRead-onlyGet default policy.
mc_get_ci_policyFreeRead-onlyFind policy by ID.
mc_onboard_ci_accountProWriteOnboard a customer account.
mc_update_ci_default_policyProWriteUpdate default policy.
mc_update_ci_policyProWriteUpdate a policy.

[Mimecast] Add a policy. POST /email/cloud-integrated/v1/policies. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: name, description, protectionMode, targets, actions, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete a policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. ID of a policy

[Mimecast] Get default policy. GET /email/cloud-integrated/v1/policies/default-policy. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] Find policy by ID. GET /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. ID of a policy

[Mimecast] Onboard a customer account. POST /email/cloud-integrated/v1/onboarding. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: protectionMode. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Update default policy. PATCH /email/cloud-integrated/v1/policies/default-policy. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: protectionMode, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] Update a policy. PATCH /email/cloud-integrated/v1/policies/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: policyId. Send the request body as JSON (required). Documented body fields: name, description, protectionMode, targets, actions, alerts, securityEngines. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. ID of a policy.

Connectors

ToolPlanAccessSummary
mc_create_connectorProWriteInitiate consent management request.
mc_delete_connectorProDestructiveDESTRUCTIVE: deletes an existing Connector.
mc_get_connectorFreeRead-onlyFetches Connector information for an account by Connector ID Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation.
mc_list_connectorsFreeRead-onlyFetches all existing Connectors information for an account.
mc_update_connectorProWriteUpdates Connectors with following details - Connector Name, Connector description Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors.

[Mimecast] Initiate consent management request. This uses the consent workflow. POST /connector/cloud-gateway/v1/connectors. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: name, description, product, provider. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: deletes an existing Connector. Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
connectorIdstringyesRequired. Connector ID.

[Mimecast] Fetches Connector information for an account by Connector ID Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. GET /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
connectorIdstringyesRequired. ID of connector.

[Mimecast] Fetches all existing Connectors information for an account. Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation. GET /connector/cloud-gateway/v1/connectors. Email Security Cloud Gateway. Optional filters: pageToken, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. Pagination page size. StackJack sends at most 100 per request.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Updates Connectors with following details - Connector Name, Connector description Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors. PATCH /connector/cloud-gateway/v1/connectors/. Email Security Cloud Gateway. Path parameters: connector_id. Send the request body as JSON (required). Documented body fields: name, description. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
connectorIdstringyesRequired. ID of connector.

Marketplace integrations

ToolPlanAccessSummary
mc_create_marketplace_integrationProWriteStart integration onboarding (consent request).
mc_delete_marketplace_consent_requestProDestructiveDESTRUCTIVE: cancel consent request.
mc_delete_marketplace_integrationProDestructiveDESTRUCTIVE: delete an integration.
mc_get_marketplace_consent_requestFreeRead-onlyGet consent request status.
mc_get_marketplace_integrationFreeRead-onlyGet integration details (includes enabled).
mc_list_marketplace_consent_requestsFreeRead-onlyList consent requests.
mc_list_marketplace_integrationsFreeRead-onlyList integrations (includes enabled).
mc_update_marketplace_integrationProWriteUpdate an integration.

[Mimecast] Start integration onboarding (consent request). POST /marketplace/v1/integrations. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: name, type, description, config, tags, consents, credentials. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete an integration. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Integration ID

[Mimecast] Get integration details (includes enabled). GET /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Integration ID

[Mimecast] List integrations (includes enabled). GET /marketplace/v1/integrations. Email Security Cloud Gateway. Optional filters: view. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
viewstringnonullOptional. Optional view projection for response fields. Comma-separated values in ONE string - not a JSON array.

[Mimecast] Update an integration. PATCH /marketplace/v1/integrations/. Email Security Cloud Gateway. Path parameters: id. Send the request body as JSON (required). Documented body fields: name, description, config, tags, consents, credentials, enabled, role, products. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
idstringyesRequired. Integration ID

Address alteration

ToolPlanAccessSummary
mc_create_address_alteration_definitionProWriteThis API endpoint can be used to create new Address Alteration definitions within an Address Alteration Set or at the root level for policy-less processing.
mc_create_address_alteration_policyProWriteThis API endpoint can be used to create new Address Alteration policy to apply an alteration definition based on sender and recipient values.
mc_create_address_alteration_setProWriteThis API endpoint can be used to create new Address Alteration Set, to hold a number of alteration definitions.
mc_delete_address_alteration_definitionProDestructiveDESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration definitions within an Address Alteration Set.
mc_delete_address_alteration_policyProDestructiveDESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration policy.
mc_get_address_alteration_definitionFreeRead-onlyThis API endpoint can be used to find an existing Address Alteration Definition.
mc_get_address_alteration_policyFreeRead-onlyThis API endpoint can be used to find an existing Address Alteration policy.
mc_get_address_alteration_setFreeRead-onlyThis API endpoint can be used to find an existing Address Alteration Set.
mc_update_address_alteration_policyProWriteThis API endpoint can be used to update an existing Address Alteration policy.

[Mimecast] This API endpoint can be used to create new Address Alteration definitions within an Address Alteration Set or at the root level for policy-less processing. POST /api/policy/address-alteration/create-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterations, folderId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to create new Address Alteration policy to apply an alteration definition based on sender and recipient values. POST /api/policy/address-alteration/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterationSetId, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to create new Address Alteration Set, to hold a number of alteration definitions. POST /api/policy/address-alteration/create-address-alteration-set. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, parentId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration definitions within an Address Alteration Set. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/address-alteration/delete-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/address-alteration/delete-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to find an existing Address Alteration Definition. Each request field is optional, however at least one must be specified in the request body. POST /api/policy/address-alteration/get-definition. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: folderId, newAddress, originalAddress, routing. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to find an existing Address Alteration policy. POST /api/policy/address-alteration/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to find an existing Address Alteration Set. POST /api/policy/address-alteration/get-address-alteration-set. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: depth, folderId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This API endpoint can be used to update an existing Address Alteration policy. POST /api/policy/address-alteration/update-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: addressAlterationSetId, id, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Anti-spoofing

ToolPlanAccessSummary
mc_create_anti_spoofing_policyProWriteCreates a anti-spoofing policy for an account.
mc_delete_anti_spoofing_policyProDestructiveDESTRUCTIVE: deletes a anti-spoofing policy.
mc_get_anti_spoofing_policyFreeRead-onlyGets an anti-spoofing policy for an account.
mc_list_anti_spoofing_policiesFreeRead-onlyGets all anti-spoofing policies for an account.
mc_update_anti_spoofing_policyProWriteUpdates a anti-spoofing policy for an account.

[Mimecast] Creates a anti-spoofing policy for an account. POST /policy-management/cloud-gateway/v1/anti-spoofing/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: deletes a anti-spoofing policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] Gets an anti-spoofing policy for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] Gets all anti-spoofing policies for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Updates a anti-spoofing policy for an account. PATCH /policy-management/cloud-gateway/v1/anti-spoofing/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs, hostnames. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Policy ID.

Anti-spoofing bypass

ToolPlanAccessSummary
mc_create_anti_spoofing_bypass_policyProWriteCreates a anti-spoofing bypass policy for an account.
mc_create_anti_spoofing_bypass_policy_mxProWriteThis endpoint can be used to create a new Anti-Spoofing SPF based Bypass policy.
mc_delete_anti_spoofing_bypass_policyProDestructiveDESTRUCTIVE: deletes a anti-spoofing bypass policy.
mc_delete_anti_spoofing_bypass_policy_mxProDestructiveDESTRUCTIVE: this endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies.
mc_get_anti_spoofing_bypass_policyFreeRead-onlyGets a anti-spoofing bypass policy for an account.
mc_get_anti_spoofing_bypass_policy_mxFreeRead-onlyThis endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies.
mc_list_anti_spoofing_bypass_policiesFreeRead-onlyGets all anti-spoofing bypass policies for an account.
mc_update_anti_spoofing_bypass_policyProWriteUpdates a anti-spoofing policy for an account.
mc_update_anti_spoofing_bypass_policy_mxProWriteThis endpoint can be used to update an existing Anti-Spoofing SPF based Bypass policy.

[Mimecast] Creates a anti-spoofing bypass policy for an account. POST /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, spfDomains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] This endpoint can be used to create a new Anti-Spoofing SPF based Bypass policy. POST /api/policy/antispoofing-bypass/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: deletes a anti-spoofing bypass policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] DESTRUCTIVE: this endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/antispoofing-bypass/delete-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Gets a anti-spoofing bypass policy for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] This endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies. POST /api/policy/antispoofing-bypass/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Gets all anti-spoofing bypass policies for an account. GET /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Updates a anti-spoofing policy for an account. PATCH /policy-management/cloud-gateway/v1/anti-spoofing-bypass/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, spfDomains. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Policy ID.

[Mimecast] This endpoint can be used to update an existing Anti-Spoofing SPF based Bypass policy. POST /api/policy/antispoofing-bypass/update-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id, option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Blocked senders

ToolPlanAccessSummary
mc_create_blocked_senders_policyProDestructiveDESTRUCTIVE: creates a blocked senders policy for an account.
mc_create_blocked_senders_policy_mxProDestructiveDESTRUCTIVE: this endpoint creates new blocked sender policies, which can be used to manage a combination of sender and recipient restrictions.
mc_delete_blocked_senders_policyProDestructiveDESTRUCTIVE: deletes a blocked senders policy.
mc_get_blocked_senders_policyFreeRead-onlyGets an blocked senders policy for an account.
mc_get_blocked_senders_policy_mxFreeRead-onlyThis endpoint retrieves blocked sender policies.
mc_list_blocked_senders_policiesFreeRead-onlyGets all blocked senders policies for an account.
mc_update_blocked_senders_policyProDestructiveDESTRUCTIVE: updates a blocked senders policy for an account.

[Mimecast] DESTRUCTIVE: creates a blocked senders policy for an account. Warning Warning: A sender and recipient policy set to Any will apply to all inbound email. A block action will prevent delivery of all messages. Why this is destructive: a blocked-senders policy stops mail from the addresses it names being delivered. POST /policy-management/cloud-gateway/v1/blocked-senders/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, enforced, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: this endpoint creates new blocked sender policies, which can be used to manage a combination of sender and recipient restrictions. Why this is destructive: a blocked-senders policy stops mail from the addresses it names being delivered. POST /api/policy/blockedsenders/create-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: option, policy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: deletes a blocked senders policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] Gets an blocked senders policy for an account. GET /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] This endpoint retrieves blocked sender policies. POST /api/policy/blockedsenders/get-policy. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Gets all blocked senders policies for an account. GET /policy-management/cloud-gateway/v1/blocked-senders/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] DESTRUCTIVE: updates a blocked senders policy for an account. Why this is destructive: changes which senders are blocked, so mail that was being delivered can stop being delivered. PATCH /policy-management/cloud-gateway/v1/blocked-senders/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Policy ID.

DNS authentication

ToolPlanAccessSummary
mc_create_dns_auth_outbound_definitionProWriteThe Api endpoint can be used to create a DNS Authentication - Outbound definition, DKIM keys and the DNS entry.
mc_create_dns_auth_outbound_policyProWriteThe Api endpoint can be used to create DNS Authentication - Outbound policy.
mc_delete_dns_auth_outbound_definitionProDestructiveDESTRUCTIVE: the Api endpoint can be used to delete a DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_delete_dns_auth_outbound_policyProDestructiveDESTRUCTIVE: the Api endpoint can be used to delete DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_get_dns_auth_outbound_definitionFreeRead-onlyThe Api endpoint can be used to get DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_get_dns_auth_outbound_policyFreeRead-onlyThe Api endpoint can be used to get DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_list_dns_auth_outbound_definitionsFreeRead-onlyThe Api endpoint can be used to get all DNS Authentication - Outbound definitions.
mc_list_dns_auth_outbound_policiesFreeRead-onlyThe Api endpoint can be used to get all DNS Authentication - Outbound policies within the customer’s account.
mc_update_dns_auth_outbound_definitionProWriteThe Api endpoint can be used to update a DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_update_dns_auth_outbound_policyProWriteThe Api endpoint can be used to update DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_verify_dns_auth_outbound_definitionProWriteThe Api endpoint can be used to verify that DKIM within the DNS Authentication - Outbound policies with policy id specified in the endpoint is configured correctly.

[Mimecast] The Api endpoint can be used to create a DNS Authentication - Outbound definition, DKIM keys and the DNS entry. All these can be accessed when retrieving the definition. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, domain, selector, signDkim, keyLength. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] The Api endpoint can be used to create DNS Authentication - Outbound policy. The DKIM signature gets applied via a “DNS Authentication - Outbound” policy. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete a DNS Authentication - Outbound definition with definition id specified in the endpoint. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
definitionIdstringyesRequired. Definition ID.

[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete DNS Authentication - Outbound policies with policy id specified in the endpoint. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Secure ID of the DNS authentication outbound policy.

[Mimecast] The Api endpoint can be used to get DNS Authentication - Outbound definition with definition id specified in the endpoint. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
definitionIdstringyesRequired. Secure ID of outbound definition for DNS authentication.

[Mimecast] The Api endpoint can be used to get DNS Authentication - Outbound policies with policy id specified in the endpoint. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Secure ID of the DNS authentication outbound policy.

[Mimecast] The Api endpoint can be used to get all DNS Authentication - Outbound definitions. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] The Api endpoint can be used to get all DNS Authentication - Outbound policies within the customer’s account. GET /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] The Api endpoint can be used to update a DNS Authentication - Outbound definition with definition id specified in the endpoint. PATCH /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. Send the request body as JSON (required). Documented body fields: description, signDkim. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
definitionIdstringyesRequired. Secure ID of outbound definition for DNS authentication.

[Mimecast] The Api endpoint can be used to update DNS Authentication - Outbound policies with policy id specified in the endpoint. PATCH /policy-management/cloud-gateway/v1/dns-authentication-outbound/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, fromDateTime, toDateTime, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Secure ID of the DNS authentication outbound policy.

[Mimecast] The Api endpoint can be used to verify that DKIM within the DNS Authentication - Outbound policies with policy id specified in the endpoint is configured correctly. POST /policy-management/cloud-gateway/v1/dns-authentication-outbound/definitions//verify. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
definitionIdstringyesRequired. Secure ID of outbound definition for DNS authentication.

Delivery routes

ToolPlanAccessSummary
mc_create_delivery_route_definitionProWriteThe Api endpoint can be used to create a delivery route definition.
mc_create_delivery_route_policyProWriteThe Api endpoint can be used to create a Delivery Route policy.
mc_delete_delivery_route_definitionProDestructiveDESTRUCTIVE: the Api endpoint can be used to delete a delivery route definition with definition id specified in the uri.
mc_delete_delivery_route_policyProDestructiveDESTRUCTIVE: the Api endpoint can be used to delete the delivery route with policy id specified in the uri.
mc_get_delivery_route_definitionFreeRead-onlyThe Api endpoint can be used to get a delivery route definition with definition id specified in the uri.
mc_get_delivery_route_policyFreeRead-onlyThe Api endpoint can be used to get a delivery route policy with policy id specified in the uri.
mc_list_delivery_route_definitionsFreeRead-onlyThe Api endpoint can be used to get all existing delivery route definitions.
mc_list_delivery_route_policiesFreeRead-onlyThe Api endpoint can be used to get all existing delivery route policies.
mc_update_delivery_route_definitionProWriteThe Api endpoint can be used to update a delivery route definition with definition id specified in the uri.
mc_update_delivery_route_policyProWriteThe Api endpoint can be used to update the delivery route with policy id specified in the uri.
mc_verify_delivery_routeProWriteThe Api endpoint can be used to verify that the delivery route policy is valid and that Mimecast can sucessfully communicate with the provided IP address or Hostname.

[Mimecast] The Api endpoint can be used to create a delivery route definition. POST /policy-management/cloud-gateway/v1/delivery-route/definitions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, hostname, port, smtpAuthentication, alternateRouteId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] The Api endpoint can be used to create a Delivery Route policy. POST /policy-management/cloud-gateway/v1/delivery-route/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, enforced, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete a delivery route definition with definition id specified in the uri. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
definitionIdstringyesRequired. Secure ID of delivery route definition.

[Mimecast] DESTRUCTIVE: the Api endpoint can be used to delete the delivery route with policy id specified in the uri. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] The Api endpoint can be used to get a delivery route definition with definition id specified in the uri. GET /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
definitionIdstringyesRequired. Secure ID of delivery route definition.

[Mimecast] The Api endpoint can be used to get a delivery route policy with policy id specified in the uri. GET /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Secure ID of delivery route policy.

[Mimecast] The Api endpoint can be used to get all existing delivery route definitions. GET /policy-management/cloud-gateway/v1/delivery-route/definitions. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] The Api endpoint can be used to get all existing delivery route policies. GET /policy-management/cloud-gateway/v1/delivery-route/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] The Api endpoint can be used to update a delivery route definition with definition id specified in the uri. PATCH /policy-management/cloud-gateway/v1/delivery-route/definitions/. Email Security Cloud Gateway. Path parameters: definition_id. Send the request body as JSON (required). Documented body fields: description, hostname, port, smtpAuthentication, alternateRouteId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
definitionIdstringyesRequired. Secure ID of delivery route definition.

[Mimecast] The Api endpoint can be used to update the delivery route with policy id specified in the uri. PATCH /policy-management/cloud-gateway/v1/delivery-route/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, definitionId, fromPart, from, to, enabled, enforced, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Secure ID of delivery route policy.

[Mimecast] The Api endpoint can be used to verify that the delivery route policy is valid and that Mimecast can sucessfully communicate with the provided IP address or Hostname. POST /policy-management/cloud-gateway/v1/delivery-route/verify. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: hostname, port, relaxedTls, checkExternalAccess, recipientEmailAddress. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

Greylisting

ToolPlanAccessSummary
mc_create_greylisting_policyProWriteCreates a greylisting policy.
mc_delete_greylisting_policyProDestructiveDESTRUCTIVE: deletes a greylisting policy.
mc_get_greylisting_policyFreeRead-onlyGet greylisting policy by an id.
mc_list_greylisting_policiesFreeRead-onlyGets all greylisting policies for an account.
mc_update_greylisting_policyProWriteUpdates a greylisting policy.

[Mimecast] Creates a greylisting policy. POST /policy-management/cloud-gateway/v1/greylisting/policies. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: deletes a greylisting policy. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] Get greylisting policy by an id. GET /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
policyIdstringyesRequired. Policy ID.

[Mimecast] Gets all greylisting policies for an account. GET /policy-management/cloud-gateway/v1/greylisting/policies. Email Security Cloud Gateway. Optional filters: pageSize, pageToken. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. Pagination page token

[Mimecast] Updates a greylisting policy. PATCH /policy-management/cloud-gateway/v1/greylisting/policies/. Email Security Cloud Gateway. Path parameters: policy_id. Send the request body as JSON (required). Documented body fields: description, option, from, to, enabled, fromDate, toDate, fromEternal, toEternal, override, bidirectional, sourceIPs. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
policyIdstringyesRequired. Policy ID.

Managed URLs

ToolPlanAccessSummary
mc_create_managed_urlProWriteThis endpoint can be used to add new managed URL entries for URL Protection.
mc_delete_managed_urlProDestructiveDESTRUCTIVE: this API endpoint allows for the removal of an existing Managed URL entry.
mc_list_managed_urlsFreeRead-onlyThis endpoint can be used to return all entries currently in an accounts Managed URL list.

[Mimecast] This endpoint can be used to add new managed URL entries for URL Protection. POST /api/ttp/url/create-managed-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: action, comment, disableLogClick, disableRewrite, disableUserAwareness, matchType, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this API endpoint allows for the removal of an existing Managed URL entry. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/ttp/url/delete-managed-url. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to return all entries currently in an accounts Managed URL list. Optional filtering fields can also be used to return a specific URL, or set of URLs. POST /api/ttp/url/get-all-managed-urls. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: domainOrComment, domainOrUrl, exactMatch, filterBy, sortByUrl, sortOrder. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Web security

ToolPlanAccessSummary
mc_create_web_white_url_policyProWriteThis endpoint can be used to create a Web Security Block or Allow List policy for domains or URLs.
mc_delete_web_white_url_policyProDestructiveDESTRUCTIVE: this endpoint can be used to delete an existing Web Security Block or Allow List policy for domains or URLs.
mc_get_web_white_url_policyFreeRead-onlyThis endpoint can be used to get information about an existing Web Security Block or Allow List policy for domains or URLs.
mc_update_web_white_url_policyProWriteThis endpoint can be used to update an existing Web Security Block or Allow List policy for domains or URLs.

[Mimecast] This endpoint can be used to create a Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/create-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, policies, urls. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to delete an existing Web Security Block or Allow List policy for domains or URLs. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/policy/webwhiteurl/delete-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to get information about an existing Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/get-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to update an existing Web Security Block or Allow List policy for domains or URLs. POST /api/policy/webwhiteurl/update-policy-with-targets. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: description, id, policies, urls. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Protection logs

ToolPlanAccessSummary
mc_get_dlp_logsFreeRead-onlyThis endpoint can be used to retrieve messages that triggered a DLP or Content Examination policy.
mc_get_ttp_attachment_logsFreeRead-onlyPre-requisites In order to to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | Attachment Protection.
mc_get_ttp_impersonation_logsFreeRead-onlyThis endpoint can be used to get messages containing information flagged by an Impersonation Protection configuration.
mc_get_ttp_url_logsFreeRead-onlyPre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | URL Protection | Read.

[Mimecast] This endpoint can be used to retrieve messages that triggered a DLP or Content Examination policy. POST /api/dlp/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: actions, from, oldestFirst, query, routes, searchField, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Pre-requisites In order to to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | Attachment Protection. POST /api/ttp/attachment/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: from, oldestFirst, result, route, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to get messages containing information flagged by an Impersonation Protection configuration. POST /api/ttp/impersonation/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: actions, from, identifiers, oldestFirst, query, searchField, taggedMalicious, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | URL Protection | Read. POST /api/ttp/url/get-logs. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: from, oldestFirst, route, scanResult, to. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Remediation

ToolPlanAccessSummary
mc_create_ttp_remediationProWriteThis endpoint can be used to create a remediation incident, by messageId, file hash or a url contained in an email.
mc_create_ttp_remediation_v2ProWriteThis endpoint can be used to create a remediation incident, by file hash or a url of by one or more messageId.
mc_find_ttp_remediation_incidentsFreeRead-onlyThis endpoint can be used to search for existing remediation incidents.
mc_get_bulk_remediation_statusFreeRead-onlyGet the bulk remediation status by batch ID.
mc_get_event_remediation_statusFreeRead-onlyGet remediation status by event ID.
mc_get_ttp_remediation_incidentFreeRead-onlyThis endpoint can be used to get information about an existing incident.
mc_remediate_security_eventProDestructiveDESTRUCTIVE: remediate a security event by event ID.
mc_remediate_security_events_bulkProDestructiveDESTRUCTIVE: remediate bulk security threat events.
mc_search_ttp_remediation_hashFreeRead-onlyThis endpoint can be used to identify if an account has seen a specific file hash within messages over the last year.

[Mimecast] This endpoint can be used to create a remediation incident, by messageId, file hash or a url contained in an email. POST /api/ttp/remediation/create. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, hashOrMessageId, reason, searchBy, start, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to create a remediation incident, by file hash or a url of by one or more messageId. POST /api/ttp/remediation/v2/create. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, messageIds, reason, searchBy, start, hash, url. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to search for existing remediation incidents. While each request field is optional, at least one field must be supplied. POST /api/ttp/remediation/find-incidents. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: end, filterBy, searchBy, start. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] Get the bulk remediation status by batch ID. GET /security/remediation/v1/bulk/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: batchId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
batchIdstringyesRequired. ID of a security event.

[Mimecast] Get remediation status by event ID. GET /security/remediation/v1/events/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: eventId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
eventIdstringyesRequired. ID of a security event.

[Mimecast] This endpoint can be used to get information about an existing incident. The information includes incident creation criteria, remediation status counts and information to restore a message, if needed. POST /api/ttp/remediation/get-incident. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: remediate a security event by event ID. Why this is destructive: pulls a delivered message out of the recipient's mailbox. POST /security/remediation/v1/events/. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Path parameters: eventId. Send the request body as JSON (required). Documented body fields: reason, actionType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
eventIdstringyesRequired. ID of a security event.

[Mimecast] DESTRUCTIVE: remediate bulk security threat events. Why this is destructive: pulls delivered messages out of recipients' mailboxes in bulk. POST /security/remediation/v1/bulk. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Send the request body as JSON (required). Documented body fields: reason, actionType, processingIds. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] This endpoint can be used to identify if an account has seen a specific file hash within messages over the last year. POST /api/ttp/remediation/search-hash. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: hashes. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Reported emails

ToolPlanAccessSummary
mc_create_threat_report_subscriptionProWriteCreate Subscriptions.
mc_delete_threat_report_subscriptionProDestructiveDESTRUCTIVE: delete Subscription.
mc_get_reported_emailFreeRead-onlyRetrieve reported email.
mc_get_threat_analysisFreeRead-onlyRetrieve Threat Analysis by Id.
mc_list_reported_emailsFreeRead-onlyList Reported Emails.
mc_list_threat_report_subscriptionsFreeRead-onlyList Subscriptions.
mc_list_threat_reportsFreeRead-onlyList Threat Reports.
mc_update_threat_report_subscriptionProWriteRenew Subscription.

[Mimecast] Create Subscriptions. POST /threat-reporting/v1/subscriptions. Email Security Cloud Gateway. Send the request body as JSON (required). Documented body fields: clientState, notificationURL, resourceType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.

[Mimecast] DESTRUCTIVE: delete Subscription. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. DELETE /threat-reporting/v1/subscriptions/. Email Security Cloud Gateway. Path parameters: subscriptionId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
subscriptionIdstringyesRequired.

[Mimecast] Retrieve reported email. GET /threat-reporting/v1/reported-emails/. Email Security Cloud Gateway. Path parameters: reportedMessageAggregateId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
reportedMessageAggregateIdstringyesRequired. The the reported message aggregateId

[Mimecast] Retrieve Threat Analysis by Id. GET /threat-reporting/v1/threat-analysis/. Email Security Cloud Gateway. Path parameters: threatAnalysisId. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
threatAnalysisIdstringyesRequired. The threat analysis id

[Mimecast] List Reported Emails. GET /threat-reporting/v1/reported-emails. Email Security Cloud Gateway. Optional filters: dateRangeStartsAt, dateRangeEndsAt, pageSize, offset. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dateRangeEndsAtstringnonullOptional. The date in ISO-8601 format from which to end, default to the current time.
dateRangeStartsAtstringnonullOptional. The date in ISO-8601 format from which to start, default a week from the current time.
offsetintegernonullOptional. The number of pages to offset before returning results, starting from 0
pageSizeintegernonullOptional. The number of results to return per page. Page size of 25,50,100,250,500, if missing default value is 50. StackJack sends at most 100 per request.

[Mimecast] List Subscriptions. GET /threat-reporting/v1/subscriptions. Email Security Cloud Gateway. Not paginated: Mimecast documents no page parameters here, so expect the whole collection in one response - on a large tenant it can exceed the result-size cap. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] List Threat Reports. GET /threat-reporting/v1/threat-reports. Email Security Cloud Gateway. Optional filters: pageSize, offset. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
offsetintegernonullOptional. The number of pages to offset before returning results
pageSizeintegernonullOptional. The number of results to return per page. Valid values of 25, 50, 100, 250, 500. If missing, the default value is 50. StackJack sends at most 100 per request.
reportedMessageAggregateIdstringyesRequired. The the reported message aggregateId

[Mimecast] Renew Subscription. PATCH /threat-reporting/v1/subscriptions/. Email Security Cloud Gateway. Path parameters: subscriptionId. Send the request body as JSON (required). Documented body fields: oldClientState, clientState. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
bodyJsonstringyesRequired. The request body as JSON.
subscriptionIdstringyesRequired.

SIEM feeds

ToolPlanAccessSummary
mc_list_siem_batch_events_cgFreeRead-onlyRetrieve CG Events.
mc_list_siem_batch_events_ciFreeRead-onlyRetrieve CI Events.
mc_list_siem_events_cgFreeRead-onlyRetrieve CG Events.
mc_list_siem_events_ciFreeRead-onlyRetrieve CI Events.

[Mimecast] Retrieve CG Events. GET /siem/v1/batch/events/cg. Email Security Cloud Gateway. Optional filters: type, dateRangeStartsAt, dateRangeEndsAt, nextPage, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dateRangeEndsAtstringnonullOptional. The date key in ISO-8601 full-date format from which to end.
dateRangeStartsAtstringnonullOptional. The date key in ISO-8601 full-date format from which to start.
nextPagestringnonullOptional. The pagination key provided by the previous request.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
typestringnonullOptional. A single key-value pair of event type and subtype delimited by a colon (` -`). Type is optional , unless the `Accept` header is `application/cim`. Subtype is entirely optional. Simply append ` -{{your_subtype}}`

[Mimecast] Retrieve CI Events. GET /siem/v1/batch/events/ci. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Optional filters: type, dateRangeStartsAt, dateRangeEndsAt, nextPage, pageSize. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dateRangeEndsAtstringnonullOptional. The date key in ISO-8601 full-date format from which to end.
dateRangeStartsAtstringnonullOptional. The date key in ISO-8601 full-date format from which to start.
nextPagestringnonullOptional. The pagination key provided by the previous request.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
typestringnonullOptional. A single key-value pair of event type and subtype delimited by a colon (` -`). Type is optional , unless the `Accept` header is `application/cim`. Subtype is entirely optional. Simply append ` -{{your_subtype}}`

[Mimecast] Retrieve CG Events. GET /siem/v1/events/cg. Email Security Cloud Gateway. Optional filters: types, dateRangeStartsAt, dateRangeEndsAt, pageSize, nextPage. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dateRangeEndsAtstringnonullOptional. The date in ISO-8601 format from which to end.
dateRangeStartsAtstringnonullOptional. The date in ISO-8601 format from which to start.
nextPagestringnonullOptional. The pagination key provided by the previous request.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
typesstringnonullOptional. A single key-value pair of event type and subtype delimited by a colon (` -`). Type is optional , unless the `Accept` header is `application/cim`. Subtype is entirely optional. Simply append ` -{{your_subtype}}`

[Mimecast] Retrieve CI Events. GET /siem/v1/events/ci. Email Security Cloud Integrated - a Cloud Gateway account answers Not Found here. Optional filters: types, dateRangeStartsAt, dateRangeEndsAt, pageSize, nextPage. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dateRangeEndsAtstringnonullOptional. The date in ISO-8601 format from which to end.
dateRangeStartsAtstringnonullOptional. The date in ISO-8601 format from which to start.
nextPagestringnonullOptional. The pagination key provided by the previous request.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
typesstringnonullOptional. A single key-value pair of event type and subtype delimited by a colon (` -`). Type is optional , unless the `Accept` header is `application/cim`. Subtype is entirely optional. Simply append ` -{{your_subtype}}`

Threat events

ToolPlanAccessSummary
mc_get_threat_event_detailsFreeRead-onlyDeveloper API to fetch threat details.
mc_list_threat_eventsFreeRead-onlyList Threat events.

[Mimecast] Developer API to fetch threat details. GET /threats/v1/events//details. Email Security Cloud Gateway. Path parameters: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
idstringyesRequired. Detection Id.
pageSizeintegeryesRequired. Max pageSize to fetch sub-collections(attachments, urls, recipients) Capped at 100 by Mimecast.
sourcestringyesRequired. Filter parameter to get the threat details statistics for the relevant service(s)

[Mimecast] List Threat events. GET /threats/v1/events. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, analysis, status, direction, source, pageToken, pageSize, limit, orderBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
analysisstringnonullOptional. Comma-separated list of analysis values to filter on. Comma-separated values in ONE string - not a JSON array.
directionstringnonullOptional. Comma-separated list of direction values to filter on, currently only inbound (in future will include all directions) Comma-separated values in ONE string - not a JSON array.
limitintegernonullOptional. Maximum number of records to return, in total. Min - 1, Max - 1000.
orderBystringnonullOptional. Sorting order for the result collection. Format is 'column -[asc|desc]'. Supported columns are - spamCount, malwareCount, phishingCount, suspiciousCount, unwantedCount, totalCount.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. The pagination key provided by the previous request.
sourcestringnonullOptional. Comma-separated list of source values to filter on. Comma-separated values in ONE string - not a JSON array.
statusstringnonullOptional. Comma-separated list of status values to filter on. Comma-separated values in ONE string - not a JSON array.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

Threat intelligence

ToolPlanAccessSummary
mc_create_byo_threat_intel_batchProDestructiveDESTRUCTIVE: this endpoint can be used to import a single or batch of multiple indicators.
mc_delete_byo_threat_intel_batchProDestructiveDESTRUCTIVE: this endpoint can be used to remove a batch of indicators.
mc_get_byo_threat_intel_batchesFreeRead-onlyThis endpoint can be used to retrieve information about all existing batches.
mc_get_byo_threat_intel_quotaFreeRead-onlyThis endpoint can be used to retrieve the number of indicators in use and the number of remaining indicators that can be added.
mc_get_ttp_threat_intel_feedFreeRead-onlyThis feed can be used to return identified malware threats at a customer or regional grid level.

[Mimecast] DESTRUCTIVE: this endpoint can be used to import a single or batch of multiple indicators. These indicators can be used to perform a specific action based on their presence. Why this is destructive: the body's operationType decides what the batch DOES, and the vendor's own values are "Must be one of ALLOW, BLOCK or DELETE" - so this tool does not only add indicators, it can REMOVE the ones the batch names, and BLOCK stops mail carrying them being delivered. POST /api/byo-threat-intelligence/create-batch. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: hashList, operationType. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] DESTRUCTIVE: this endpoint can be used to remove a batch of indicators. Why this is destructive: delete semantics - the record is removed and StackJack cannot recover it. POST /api/byo-threat-intelligence/delete-batch. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: id. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to retrieve information about all existing batches. POST /api/byo-threat-intelligence/get-batches. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (optional). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: order, sortBy. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringnonullOptional. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

[Mimecast] This endpoint can be used to retrieve the number of indicators in use and the number of remaining indicators that can be added. POST /api/byo-threat-intelligence/get-quota. Email Security Cloud Gateway, MX-based deployments only. Mimecast documents no request payload for this route. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.

[Mimecast] This feed can be used to return identified malware threats at a customer or regional grid level. POST /api/ttp/threat-intel/get-feed. Email Security Cloud Gateway, MX-based deployments only. Send the payload as JSON; Mimecast wraps it in its data array for you (required). Paging: pageSize (max 100) and pageToken travel in the request body under meta.pagination. The response omits meta.pagination.next on the last page, so stop when it is absent rather than when a page comes back empty. Documented body fields: compress, end, feedType, fileType, start, token. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
dataJsonstringyesRequired. The payload object as JSON. Mimecast wraps it in its data array.
pageSizeintegernonullOptional. Results per page, 1-100. Travels in the request body under meta.pagination.
pageTokenstringnonullOptional. The opaque page token from a previous response's meta.pagination.next. Travels in the request body, not the query string.

Threat statistics

ToolPlanAccessSummary
mc_get_attachment_scan_statsFreeRead-onlyGet Attachment Scan stats.
mc_get_gateway_detection_statsFreeRead-onlyGet Gateway Detection stats by type.
mc_get_impersonation_statsFreeRead-onlyGet Impersonation stats.
mc_get_phishing_statsFreeRead-onlyGet phishing stats.
mc_get_suspicious_statsFreeRead-onlyGet suspicious stats.
mc_get_threats_by_recipient_statsFreeRead-onlyList Threat statistics by recipient.
mc_get_threats_by_sender_statsFreeRead-onlyList Threat statistics by sender.
mc_get_unwanted_statsFreeRead-onlyGet unwanted stats.
mc_get_url_click_statsFreeRead-onlyGet URL Click stats.

[Mimecast] Get Attachment Scan stats. GET /threats/v1/stats/attachment-scans. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] Get Gateway Detection stats by type. GET /threats/v1/stats/gateway-detections. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.
typestringyesRequired. Type of Gateway Detection threat.

[Mimecast] Get Impersonation stats. GET /threats/v1/stats/impersonations. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] Get phishing stats. GET /threats/v1/stats/phishing. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] Get suspicious stats. GET /threats/v1/stats/suspicious. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] List Threat statistics by recipient. GET /threats/v1/stats/threats-by-recipient. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, pageToken, email, pageSize, orderBy, limit. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
emailstringnonullOptional. Email address to filter records on.
limitintegernonullOptional. Maximum number of records to return, in total. Min - 1, Max - 1000.
orderBystringnonullOptional. Sorting order for the result collection. Format is 'column -[asc|desc]'. Supported columns are - spamCount, malwareCount, phishingCount, suspiciousCount, unwantedCount, totalCount.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. The pagination key provided by the previous request.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] List Threat statistics by sender. GET /threats/v1/stats/threats-by-sender. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt, pageToken, email, pageSize, orderBy, limit. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
emailstringnonullOptional. Email address to filter records on.
limitintegernonullOptional. Maximum number of records to return, in total. Min - 1, Max - 1000.
orderBystringnonullOptional. Sorting order for the result collection. Format is 'column -[asc|desc]'. Supported columns are - spamCount, malwareCount, phishingCount, suspiciousCount, unwantedCount, totalCount.
pageSizeintegernonullOptional. The maximum number of rows to return per page. Capped at 100 by Mimecast.
pageTokenstringnonullOptional. The pagination key provided by the previous request.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] Get unwanted stats. GET /threats/v1/stats/unwanted. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.

[Mimecast] Get URL Click stats. GET /threats/v1/stats/url-clicks. Email Security Cloud Gateway. Optional filters: timestampRangeEndsAt. MSP: pass accountCode to act on a managed customer; omit it to act on your own account. Returns raw Mimecast JSON.

ParamTypeRequiredDefaultDescription
accountCodestringnonullOptional. A managed customer's Mimecast account code, for a partner credential. Sent as the x-mc-account header. Omit it to act on your own account; mc_list_partner_customers lists the codes.
timestampRangeEndsAtstringnonullOptional. End timestamp (exclusive) to retrieve data up to. Extended ISO-8601 format with mandatory time zone designator (which must be the same as the one specified in the `timestampRangeStartsAt` field). Default to current...
timestampRangeStartsAtstringyesRequired. Start timestamp (inclusive) to retrieve data from. Extended ISO-8601 format with mandatory time zone designator. Note - Data is only available for 90 days.