Skip to main content
Connector guides

Connect Mimecast

Mimecast is an email security and archiving platform. It sits in front of a company's mail, holds and inspects what arrives, keeps a searchable archive of what was sent and received, and scores the…

Written By Christopher Scaminaci

Last updated 6 days ago

Mimecast is an email security and archiving platform. It sits in front of a company's mail, holds and inspects what arrives, keeps a searchable archive of what was sent and received, and scores the people who handle it. StackJack talks to Mimecast through its API 2.0, which is the same interface behind the Mimecast Administration console you already use.

Connecting Mimecast to StackJack gives your AI assistant a family of mc_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Answer "where is my email?" — find held and processing messages, trace a message end to end, read the mail queues, see why something was rejected, and decode a rewritten link
  • Release or reject held mail (on Pro plans) — close the most common Mimecast ticket there is, one message or a batch
  • Investigate threats — threat events and statistics, attachment, link-click, impersonation and data-loss logs, reported emails and their analysis, and the security event feeds
  • Search the archive — eDiscovery-shaped searches, message lists and detail, smart tags, retention adjustments and message visibility
  • Look up people and groups — internal users, aliases, attributes, delegates, group membership, and the status of a directory synchronization
  • Report on human risk — safe scores, watchlists, phishing campaign results, per-user training detail, and individual and organizational risk trends
  • Run DMARC — if your Mimecast subscription includes DMARC Analyzer, your AI can look after the domains you send mail from: add and group them, read and set their DKIM selectors, SPF records and DMARC policies (including for domains you manage on someone else's behalf), check what DNS is publishing right now, work through the sending sources it discovers, and pull the compliance and enforcement picture. It can also download a forensic failure report, which arrives as a temporary download link rather than a file in the conversation — and stays encrypted to whatever key you gave Mimecast, so you open it with your own key after you download it.
  • Read and change policy (reads Free, changes on Pro) — greylisting, delivery routes, sender authentication, anti-spoofing, blocked senders, address alteration and managed links
  • Manage domains and connections (reads Free, changes on Pro) — internal, external and pending domains, verification and DNS records, journaling services, and the Active Directory, Google and Microsoft 365 directory connections

How StackJack authenticates to Mimecast

You create an API 2.0 application in the Mimecast Administration console. It gives you a Client ID and a Client Secret, and you paste both into StackJack. There is nothing to renew on a schedule: StackJack exchanges the pair for a short-lived token on its own and gets a fresh one whenever the old one runs out. You never see it.

What the application may do is decided in Mimecast, not in StackJack

This is the one thing worth reading twice, because it causes almost every Mimecast support ticket.

When you create the application, Mimecast asks you for two things that decide everything afterwards:

  • Products — which groups of the API the application may reach. Threat Management, Directories, Gateway, Awareness Training, DMARC Analyzer and so on are separate products. DMARC Analyzer is the one people forget: leave it unticked and every DMARC tool comes back saying the application is not allowed to use that part of the API, which reads exactly like a bad key and is not one.
  • Role — what level of access the application has inside those products, typically read-only or read and write.

Those choices are fixed at creation. StackJack can never ask for more than the application carries, so a read-only role produces read-only behavior no matter what an AI assistant is asked to do. That is a useful safety control, and it is the one we recommend you start with.

The consequence is that a tool can come back saying the application is not allowed to use that part of the API even though your credentials are perfectly good. That is not a bad key and regenerating the secret will not help. Go back to the application in Mimecast and add the missing product.

It is also worth knowing that Mimecast sells more than one email security product and they do not share the same tools. An Email Security Cloud Gateway account will say "not found" to a Cloud Integrated tool and the other way round, and DMARC Analyzer is separate again. Each tool says which product it belongs to.

Pick your data region

Mimecast runs three gateways and your account lives on exactly one of them:

  • Global — the default, and the right answer for most accounts. It moves to the nearest healthy instance by itself if one has a problem.
  • United Kingdom and United States — single-instance services chosen for data residency. Neither has any failover, so requests fail outright while that instance is down. Pick one of these only if your Mimecast account was created on it.

The region decides where your API traffic is processed. If you are not sure which one your account uses, start with Global.

Steps

  1. Decide what the application may reach. Pick the products and the role first, because you cannot change them from StackJack later. Start read-only if you only want reporting. Tick DMARC Analyzer too if you want the DMARC tools.
  2. Create the application. In the Mimecast Administration console, open Services, then API and Platform Integrations, and create a new API 2.0 application. Fill in a name, a description and a contact, then choose your products and role.
  3. Copy the Client ID and generate the Client Secret. Mimecast shows the secret exactly once and it cannot be retrieved afterwards. Copy it before you close the page and treat it as a password.
  4. Confirm your region. Most accounts are Global. Choose United Kingdom or United States only if your account was created on that instance.
  5. Enter the details in StackJack. Open Connectors, choose Mimecast, pick the region, and paste the Client ID and Client Secret.
  6. Run a Test Connection. A failure here is almost always the secret being truncated on copy, or the wrong region.

If you ever need to change the secret, generate a new one on the same application rather than creating a second application — a new application would need its products and role set up again. When you come back to edit a saved connection, the Client Secret box starts blank on purpose; leaving it blank keeps the secret you already stored.

Managing several companies with one set of keys

If you manage other companies' Mimecast accounts, create the application in your partner (NFR) account instead, under Multi Account Controls, then API Gateway. One set of keys then reaches every customer you administer, and there is no second connector to set up per customer.

Every Mimecast tool takes an optional account code that says which customer it acts on. Leave it empty and the tool acts on your own account. mc_list_partner_customers lists the customers you administer along with their account codes, and it is the read to run first.

Two limits are worth knowing before you build anything on this:

  • A partner key reaches a customer only if you actually administer that customer in Mimecast.
  • Mimecast does not let a partner key send email on behalf of a managed customer.

Two Mimecast products, two sets of tools

Mimecast sells Email Security Cloud Gateway — the classic model where your mail is routed through Mimecast — and Email Security Cloud Integrated, which attaches to Microsoft 365 instead. They do not share an API surface.

A Cloud Gateway account answers "not found" to a Cloud Integrated tool, and the reverse, and neither answer means anything is broken. Every tool's description says which product it is for. If you are not sure which you have, mc_get_whoami tells you.

Tiers

  • Free — every read. Held-message searches, message tracing, threat and click logs, archive search, user and group lookups, awareness and risk scores, audit events, policy and domain reads, and the managed-customer list.
  • Pro — every change. Creating and updating policies, domains, groups, users, journaling services, directory connections and smart tags, and running connection tests; and equally the changes that are hard or impossible to undo — releasing and rejecting held mail, blocking senders, deleting policies, domains, groups, delegates and integrations, purging mailboxes, remediating delivered messages, and restoring a configuration snapshot over the live one.
  • Business — the same tool set as Pro with a higher monthly call quota.

Five more changes are marked destructive because of what their body can do, not what their name says. Importing users can empty the group it imports into, if the import options say so. Replacing a DMARC task, a DMARC domain group or a DMARC notification replaces the lists inside it, so a domain or a group you leave out drops out. And a retention adjustment set to zero days purges the messages it names from the archive at once.

Importing users takes the file itself. Hand your assistant the CSV content, or point it at an XLS or XLSX workbook by URL or as an attachment — the import options travel separately. StackJack downloads a URL for you and refuses anything over 25 MB.

That second group of changes is marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you let an assistant near held mail.

See the generated Mimecast tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Paging and limits

Mimecast returns large results a page at a time, with a maximum of 100 records per page. A page comes back with a token for the next one, and the token is simply absent when there is no more data — so a result with no token is a finished list, not an error.

Mimecast does not publish a request quota for most of its API, so StackJack paces requests conservatively and backs off on its own if Mimecast throttles it. That usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee every call arrives. Narrow the read — a shorter date range, one customer at a time rather than your whole book — and check whether a write landed before repeating it. See Retrying a failed or timed-out write.

Troubleshooting

"Not allowed to use that part of the API." The application's products or role do not cover the tool you ran. Fix it on the application in Mimecast; the keys are fine.

"Client ID and Client Secret not recognized." Check the pair, and copy the secret in full — a truncated paste is the most common cause and looks exactly like a wrong secret. If you no longer have the secret, generate a new one on the same application.

A tool returns "not found" for something you can see in the console. Check which Mimecast product the tool is for. The two email security products answer only their own routes.

Everything is slow or comes back throttled. Narrow the date range, reduce the page size, and work one managed customer at a time.

Mimecast tools

mc_ · 374 tools · Free 194 · Pro 180

Account

ToolWhat it does
mc_get_account
Free · Read-only
This endpoint returns the summary details for an account in Mimecast.
mc_get_dashboard_notifications
Free · Read-only
This feed can be used to return dashboard notifications from the Administration Console Dashboard.
mc_get_emergency_contact
Free · Read-only
Returns the Emergency Contact information for the account.
mc_get_provisioning_packages
Free · Read-only
This endpoint returns products that are available to be provisioned by a partner.
mc_get_support_info
Free · Read-only
This endpoint returns support information that is associated with a Mimecast tenant.
mc_get_whoami
Free · Read-only
Returns details of a partner, including information such as Partner type, Mimecast account code in CI, CG and X1 platform.
mc_replace_emergency_contact
Pro · Destructive
DESTRUCTIVE: creates an Emergency Contact for the account.
mc_update_emergency_contact
Pro · Write
Updates the Emergency Contact information for the account.

Configuration snapshots

ToolWhat it does
mc_create_config_snapshot
Pro · Write
Create a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.
mc_export_config_snapshot
Free · Read-only
Export a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.
mc_list_config_snapshots
Free · Read-only
Get the comprehensive list of configuration snapshots for the customers Mimecast settings, including those for: Managed Senders, Managed URLs and Profile Groups.
mc_restore_config_snapshot
Pro · Destructive
DESTRUCTIVE: restore a backup snapshot of the customers Mimecast configurations for: Managed Senders, Managed URLs and Profile Groups.

Partner (MSP)

ToolWhat it does
mc_get_partner_customer
Free · Read-only
Get one managed customer.
mc_list_partner_customers
Free · Read-only
List managed customers.
ToolWhat it does
mc_get_archive_file
Free · Read-only
Retrieves the file or attachment for given id.
mc_get_archive_message_detail
Free · Read-only
Retrieves archived message details.
mc_get_archive_message_list
Free · Read-only
Retrieves archive message list.
mc_get_archive_message_part
Free · Read-only
Retrieves the message part - HTML, plain or RFC822. POST /api/archive/get-message-part.
mc_search_archive
Free · Read-only
Retrieves archive search items.

Data retention

ToolWhat it does
mc_add_smart_tag_messages
Pro · Write
Add messages to a smart tag.
mc_list_smart_tags
Free · Read-only
Get all smart tags for account.
mc_search_smart_tag_messages
Free · Read-only
Search for messages in a smart tag.
mc_set_message_visibility
Pro · Write
Set message visibility.
mc_update_retention_adjustment
Pro · Destructive
DESTRUCTIVE: update retention adjustment for messages.

Archive access logs

ToolWhat it does
mc_get_archive_search_logs
Free · Read-only
Retrieves archive search logs.
mc_get_search_logs
Free · Read-only
Retrieves the search logs.
mc_get_view_logs
Free · Read-only
Retrieves the email view logs.

Audit events

ToolWhat it does
mc_get_audit_categories
Free · Read-only
Returns the list of audit categories available.
mc_get_audit_events
Free · Read-only
Returns the audit events matching the request.

Delivery monitoring

ToolWhat it does
mc_get_held_release_logs
Free · Read-only
This endpoint can be used to find messages that were either released to the recipient, with details about the user that processed the release.
mc_get_rejections
Free · Read-only
This endpoint can be used to find rejected messages and the reasons for their rejection.

Awareness scores

ToolWhat it does
mc_get_awareness_performance_details
Free · Read-only
This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Performance details by Department and Performance Type (data displayed on Performance > Achievements.
mc_get_awareness_performance_summary
Free · Read-only
This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Performance Summary by total user answer count.
mc_get_awareness_safe_score_details
Free · Read-only
This API endpoint can be used to get Awareness Training Mime | OS SAFE Score user level details and grades, including User Risk, Human Error, Sentiment, Engagement and Knowledge.
mc_get_awareness_safe_score_summary
Free · Read-only
This API endpoint can be used to get Awareness Training Mime | OS Training SAFE Score company-level Summary by User Count per User Risk Grade.
mc_get_awareness_watchlist_details
Free · Read-only
This API endpoint can be used to get Awareness Training Mime | OS Training Module user level Watchlist details by Department and Watchlist Type.
mc_get_awareness_watchlist_summary
Free · Read-only
This API endpoint can be used to get the Awareness Training Mime | OS Training Module company-level Watchlist Summary by total user unwatched count.

Human risk

ToolWhat it does
mc_get_individual_risk_profiles
Free · Read-only
Get individual risk profiles with scores.
mc_get_organization_attacks
Free · Read-only
Get organizational attack data.
mc_get_organization_behaviors
Free · Read-only
Get organizational behavior data.
mc_get_organization_risk
Free · Read-only
Get organization risk trends.
mc_list_risk_departments
Free · Read-only
List departments with aggregated risk data.
mc_list_risk_locations
Free · Read-only
List locations with aggregated risk data.
mc_search_individuals_risk
Free · Read-only
Search individuals with risk data.

Phishing campaigns

ToolWhat it does
mc_get_phishing_campaign
Free · Read-only
This API endpoint can be used to get all campaign-level information on Awareness Training Mime | OS Phishing Campaigns created, both pending and launched.
mc_get_phishing_campaign_user_data
Free · Read-only
This API endpoint can be used to get an aggregated summary of Awareness Training Mime | OS Phishing Campaigns grouped by recipient email address.

Training queue and users

ToolWhat it does
mc_get_awareness_queue
Free · Read-only
This API endpoint can be used to get all module-level information on Awareness Training Mime | OS Training Modules created, both pending and launched.
mc_get_user_training_details
Free · Read-only
This API endpoint can be used to get user enrollment and completion information on Awareness Training Mime | OS Training Modules.

Administrator roles

ToolWhat it does
mc_list_admin_roles
Free · Read-only
Retrieves a list of roles for the account.

Directory connections

ToolWhat it does
mc_create_ad_integration
Pro · Write
Creates a new directory integration for Active Directory.
mc_create_directory_sync_request
Pro · Write
Requests a sync of all directory integrations for account.
mc_create_google_integration
Pro · Write
Creates a new directory integration for Google.
mc_create_m365_integration
Pro · Write
Creates a new directory integration for M365. POST /directory/cloud-gateway/v1/integrations/m365. Email Security Cloud Gateway.
mc_delete_ad_integration
Pro · Destructive
DESTRUCTIVE: deletes an Active Directory directory integration.
mc_delete_google_integration
Pro · Destructive
DESTRUCTIVE: deletes a Google directory integration.
mc_delete_m365_integration
Pro · Destructive
DESTRUCTIVE: deletes a M365 directory integration.
mc_execute_directory_sync
Pro · Write
This endpoint can be used to initiate directory synchronization.
mc_get_ad_integration
Free · Read-only
Gets an Active Directory directory integration.
mc_get_directory_connection
Free · Read-only
This endpoint can be used to retrieve directory connectors that are configured on the tenant.
mc_get_google_integration
Free · Read-only
Gets a Google directory integration.
mc_get_m365_integration
Free · Read-only
Gets a M365 directory integration.
mc_list_directory_integrations
Free · Read-only
Gets all (m365, google, ldap) directory integrations for account.
mc_test_ad_authentication
Pro · Write
Tests if Active directory integration can authenticate.
mc_test_ad_certificates
Pro · Write
Tests the certificates of an Active Directory integration.
mc_test_ad_connectivity
Pro · Write
Tests the connectivity of an Active Directory integration.
mc_test_ad_egress_connectivity
Pro · Write
Tests the Egress connectivity of an Active Directory integration.
mc_test_ad_email
Pro · Write
Tests if an Active Directory integration can retrieve directory samples.
mc_test_ad_validation
Pro · Write
Tests the validity of an Active Directory integration.
mc_test_google_authentication
Pro · Write
Tests a Google directory authentication.
mc_test_google_authorization
Pro · Write
Tests a Google directory has the correct authorised permission set.
mc_test_google_connectivity
Pro · Write
Tests the connectivity of a Google directory integration.
mc_test_google_email
Pro · Write
Tests if a Google Directory integration can retrieve directory samples.
mc_test_m365_authentication
Pro · Write
Tests a Microsoft 365 directory authentication.
mc_test_m365_authorization
Pro · Write
Tests a M365 directory has the correct authorised permission set.
mc_test_m365_connectivity
Pro · Write
Tests the connectivity of a Microsoft 365 directory integration.
mc_test_m365_connector
Pro · Write
Tests the connector associated to a M365 directory authorisation.
mc_test_m365_email
Pro · Write
Tests if a Microsoft 365 Directory integration can retrieve directory samples.
mc_update_ad_integration
Pro · Write
Updates an Active Directory directory integration.
mc_update_google_integration
Pro · Write
Updates a Google directory integration.
mc_update_m365_integration
Pro · Write
Updates an M365 directory integration.

Groups

ToolWhat it does
mc_add_group_member_mx
Pro · Write
This endpoint can be used to add user email addresses or domains to a profile group.
mc_add_group_members
Pro · Write
This endpoint can be used to add user email addresses or domains to a profile group.
mc_create_group
Pro · Write
Creates a new Profile Groups at the root level, or as a child-group.
mc_create_group_mx
Pro · Write
This API endpoint can be used to create new Profile Groups at the root level, or as a child-group.
mc_delete_group_mx
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to delete an exiting profile group.
mc_find_groups
Free · Read-only
This endpoint can be used to find groups that exist on a tenant.
mc_get_group
Free · Read-only
This endpoint can be used to get a profile group from a tenant.
mc_get_group_members_mx
Free · Read-only
This endpoint can be used to retrieve group members from groups the exist on a tenant.
mc_list_group_members
Free · Read-only
This endpoint can be used to get group members from a tenant.
mc_list_groups
Free · Read-only
This endpoint can be used to find groups that exist on a tenant.
mc_remove_group_member_mx
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups.
mc_remove_group_members
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to remove group members from Mimecast Profile groups.
mc_update_group_mx
Pro · Write
The update group endpoint can be used to update the description of Mimecast Profile groups.

Users

ToolWhat it does
mc_add_delegate_user
Pro · Write
This API endpoint provides the ability to create a new delegate permission for a user based on their primary address.
mc_add_user_to_purge_list
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to add internal or external users to the Purge List.
mc_create_user
Pro · Write
This endpoint allows the creation of a new user within the account.
mc_create_user_mx
Pro · Write
This endpoint can be used to create new cloud-users in Mimecast's Internal Directories.
mc_find_attribute_types
Free · Read-only
This API endpoint can be used to find account attribute types.
mc_find_delegate_users
Free · Read-only
This API endpoint provides the ability to return delegate permissions for a user based on their primary address.
mc_get_internal_users
Free · Read-only
This endpoint can be used to retrieve all internal users for a given domain.
mc_get_most_used_contacts
Free · Read-only
This endpoint returns the most used contacts synced from Azure Active Directory.
mc_get_user_aliases
Free · Read-only
The get aliases endpoint can be used to retrieve aliases associated with a primary email address.
mc_get_user_attributes
Free · Read-only
This endpoint can be used to retrieve attributes that are registered on the tenant, for a given user.
mc_get_user_import_status
Free · Read-only
This endpoint can the used to get the current status of a user import request, using /api/user/import-users.
mc_import_users
Pro · Destructive
DESTRUCTIVE: the import users endpoint can be used to import users to an Internal Directory or a Profile Group.
mc_list_users
Free · Read-only
Get internal users for account.
mc_remove_delegate_user
Pro · Destructive
DESTRUCTIVE: this API endpoint provides the ability to remove delegate permissions for a user based on their primary address.
mc_remove_user_alias
Pro · Destructive
DESTRUCTIVE: the remove alias endpoint can be used to remove a alias that has been associated with a primary email address.
mc_remove_user_from_purge_list
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to remove internal or external users from the Purge List in case you added them by accident.
mc_update_user
Pro · Write
The update user endpoint can be used to update users within an Internal Directory.
mc_update_user_alias
Pro · Write
This API endpoint can be used to modify secondary email addresses for users.
mc_update_user_attributes
Pro · Write
This API endpoint can be used to update a non-directory synced user's attributes.

DMARC DNS checks

ToolWhat it does
mc_check_dmarc_dns_bimi
Free · Read-only
Get BIMI record check.
mc_check_dmarc_dns_dkim
Free · Read-only
Get DKIM record check.
mc_check_dmarc_dns_dmarc
Free · Read-only
Get DMARC record check.
mc_check_dmarc_dns_spf
Free · Read-only
Get SPF record check.

DMARC delegated domains

ToolWhat it does
mc_create_dmarc_delegated_dkim_selector
Pro · Write
Create a DKIM definition.
mc_create_dmarc_delegated_dmarc_record
Pro · Write
Create a DMARC definition.
mc_create_dmarc_delegated_domain
Pro · Write
Create a delegated domain entry.
mc_delete_dmarc_delegated_dkim_all
Pro · Destructive
DESTRUCTIVE: delete all DKIM delegation for a domain.
mc_delete_dmarc_delegated_dkim_selector
Pro · Destructive
DESTRUCTIVE: delete DKIM definition.
mc_delete_dmarc_delegated_dmarc_record
Pro · Destructive
DESTRUCTIVE: delete DMARC definition.
mc_delete_dmarc_delegated_domains_bulk
Pro · Destructive
DESTRUCTIVE: delete delegated domains.
mc_delete_dmarc_delegated_spf_record
Pro · Destructive
DESTRUCTIVE: delete SPF definition.
mc_get_dmarc_delegated_dkim_details
Free · Read-only
Get DKIM delegation details.
mc_get_dmarc_delegated_dkim_selector
Free · Read-only
Get a DKIM definition.
mc_get_dmarc_delegated_dmarc_record
Free · Read-only
Get DMARC definition.
mc_get_dmarc_delegated_domain_statistics
Free · Read-only
Get delegated domains statistics.
mc_get_dmarc_delegated_spf_details
Free · Read-only
Get SPF definition details.
mc_get_dmarc_delegated_spf_record
Free · Read-only
Get SPF definition.
mc_list_dmarc_delegated_dkim_selectors
Free · Read-only
List DKIM definitions.
mc_list_dmarc_delegated_domains
Free · Read-only
Get delegated domains.
mc_replace_dmarc_delegated_dkim_selector
Pro · Destructive
DESTRUCTIVE: update a DKIM definition.
mc_replace_dmarc_delegated_spf_record
Pro · Destructive
DESTRUCTIVE: update the SPF definition.

DMARC detected domains

ToolWhat it does
mc_list_dmarc_detected_domains
Free · Read-only
Get detected domains.
mc_set_dmarc_detected_domain_status
Pro · Write
Update detected domain status.
mc_update_dmarc_detected_domains
Pro · Write
Batch update detected domains status.

DMARC domain groups

ToolWhat it does
mc_create_dmarc_domain_group
Pro · Write
Create a domain group.
mc_create_dmarc_domain_group_association
Pro · Write
Add domains to domain group.
mc_delete_dmarc_domain_group_association
Pro · Destructive
DESTRUCTIVE: remove domains from domain group.
mc_delete_dmarc_domain_groups_bulk
Pro · Destructive
DESTRUCTIVE: delete domain groups.
mc_get_dmarc_domain_group
Free · Read-only
Get a domain group.
mc_list_dmarc_domain_groups
Free · Read-only
Get domain groups.
mc_update_dmarc_domain_group
Pro · Destructive
DESTRUCTIVE: update a domain group.

DMARC domains

ToolWhat it does
mc_create_dmarc_domain
Pro · Write
Create a managed domain entry.
mc_delete_dmarc_domains_bulk
Pro · Destructive
DESTRUCTIVE: delete domains.
mc_get_dmarc_domain
Free · Read-only
Get a managed domain.
mc_get_dmarc_domain_statistics
Free · Read-only
Get managed domain statistics.
mc_list_dmarc_domains
Free · Read-only
Get managed domains.
mc_list_dmarc_vendor_configurations
Free · Read-only
Get domain vendor configurations.
mc_refresh_dmarc_domain_dns
Pro · Write
Refresh managed domain DNS records.
mc_update_dmarc_domain
Pro · Write
Update managed domain activity status.

DMARC policy presets

ToolWhat it does
mc_create_dmarc_policy_preset
Pro · Destructive
DESTRUCTIVE: create a new DMARC policy preset.
mc_delete_dmarc_policy_presets_bulk
Pro · Destructive
DESTRUCTIVE: delete a DMARC policy preset by ID.
mc_list_dmarc_policy_presets
Free · Read-only
Get DMARC policy presets.
mc_update_dmarc_policy_preset
Pro · Destructive
DESTRUCTIVE: update a DMARC policy preset by ID.

DMARC compliance

ToolWhat it does
mc_get_dmarc_compliance_statistics
Free · Read-only
Get DMARC compliance statistics.
mc_list_dmarc_dns_suggestions
Free · Read-only
Get DNS configuration suggestions for all domains.
mc_list_dmarc_enforcement
Free · Read-only
Get domains eligible for DMARC policy enforcement.
mc_list_dmarc_policy_changes
Free · Read-only
Get DMARC policy changes from data platform.

DMARC customer settings

ToolWhat it does
mc_delete_dmarc_encryption_key
Pro · Destructive
DESTRUCTIVE: delete customer PGP key.
mc_get_dmarc_customer
Free · Read-only
Get customer details.
mc_get_dmarc_encryption_key
Free · Read-only
Get customer PGP key.
mc_replace_dmarc_encryption_key
Pro · Destructive
DESTRUCTIVE: save customer PGP key.

DMARC events and issues

ToolWhat it does
mc_delete_dmarc_issues_bulk
Pro · Destructive
DESTRUCTIVE: delete issues.
mc_list_dmarc_events
Free · Read-only
Get events.
mc_list_dmarc_issues
Free · Read-only
Get issues.

DMARC notifications

ToolWhat it does
mc_create_dmarc_notification
Pro · Write
Create notification.
mc_delete_dmarc_notifications_bulk
Pro · Destructive
DESTRUCTIVE: delete a notification.
mc_get_dmarc_notification
Free · Read-only
Get a notification.
mc_list_dmarc_notifications
Free · Read-only
List notifications.
mc_update_dmarc_notification
Pro · Destructive
DESTRUCTIVE: update a notification.

DMARC reports

ToolWhat it does
mc_download_dmarc_forensic_report
Pro · Read-only
Download a DMARC forensic (failure) report.
mc_get_dmarc_report_results
Free · Read-only
Get paginated report results.
mc_list_dmarc_report_metadata
Free · Read-only
Get report metadata.
mc_query_dmarc_report
Free · Read-only
Query report data.

DMARC sources

ToolWhat it does
mc_create_dmarc_source_vendor_association
Pro · Write
Associate a vendor with a customer.
mc_delete_dmarc_source_vendor_association
Pro · Destructive
DESTRUCTIVE: delete vendor association.
mc_get_dmarc_source_compliance_statistics
Free · Read-only
Get source compliance statistics.
mc_get_dmarc_source_vendor
Free · Read-only
Get a single vendor.
mc_list_dmarc_source_compliance_actions
Free · Read-only
Get compliance actions.
mc_list_dmarc_source_vendors
Free · Read-only
Get vendors.
mc_list_dmarc_sources
Free · Read-only
Get sources.
mc_update_dmarc_source_vendor
Pro · Write
Update vendor status.

DMARC tasks

ToolWhat it does
mc_create_dmarc_task
Pro · Write
Create a new task.
mc_delete_dmarc_tasks_bulk
Pro · Destructive
DESTRUCTIVE: delete or archive tasks.
mc_get_dmarc_task
Free · Read-only
Get a task by ID.
mc_get_dmarc_task_summary
Free · Read-only
Get task summary by status.
mc_list_dmarc_tasks
Free · Read-only
Get all tasks (paginated).
mc_replace_dmarc_task
Pro · Destructive
DESTRUCTIVE: update a task.
mc_update_dmarc_task
Pro · Write
Partially update a task.

DMARC users

ToolWhat it does
mc_create_dmarc_user
Pro · Write
Add a new user.
mc_delete_dmarc_user
Pro · Destructive
DESTRUCTIVE: delete a user.
mc_get_dmarc_current_user
Free · Read-only
Get current user.
mc_get_dmarc_user
Free · Read-only
Get user details.
mc_list_dmarc_users
Free · Read-only
Get all user details (paginated).
mc_update_dmarc_user
Pro · Destructive
DESTRUCTIVE: update a user.

Domain onboarding

ToolWhat it does
mc_create_domain
Pro · Write
This endpoint can be used to add new domains to your Mimecast account.
mc_create_pending_domain
Pro · Write
Creates one or more “pending” domains that must be verified.
mc_delete_pending_domain
Pro · Destructive
DESTRUCTIVE: deletes an unverified domain.
mc_delete_pending_domain_mx
Pro · Destructive
DESTRUCTIVE: delete a pending domain.
mc_generate_pending_domain_token
Pro · Write
Returns the code to be added to TXT records of the new domain and also extends the expiry of the code to 30 days from the time of the request.
mc_get_pending_domain
Free · Read-only
Gets a single pending domain.
mc_get_pending_domain_mx
Free · Read-only
Retrieve pending domain information.
mc_get_provision_status
Free · Read-only
Retrieve provisioning status for a pending domain.
mc_get_verification_code
Free · Read-only
Retrieve verification code for a pending domain.
mc_list_pending_domains
Free · Read-only
Gets all pending domains.
mc_verify_domain
Pro · Write
Verify a pending domain.
mc_verify_pending_domain
Pro · Write
Verifies a pending domain via TXT record and moves it from pending to registered.

External domains

ToolWhat it does
mc_get_external_domain
Free · Read-only
Gets a single external domain.
mc_list_external_domains
Free · Read-only
Gets a list all external domains.

Internal domains

ToolWhat it does
mc_get_internal_domain
Free · Read-only
Gets a single internal domain.
mc_get_internal_domain_dns_records
Free · Read-only
Returns the DNS record lookup for internal domain.
mc_get_internal_domain_mx
Free · Read-only
Retrieve internal domain information.
mc_list_internal_domains
Free · Read-only
Gets a list all internal domains.
mc_lookup_m365_internal_domains
Free · Read-only
Returns domains from the Microsoft 365 tenant linked to the specified M365 directory integration instance.
mc_register_m365_internal_domains
Pro · Write
Registers one or more internal domains from the Microsoft 365 tenant associated with the specified M365 directory integration instance.
mc_update_internal_domain
Pro · Write
Updates an internal domain.
mc_verify_internal_domain
Pro · Write
The Api endpoint checks all the internal domains to ensure the customer has updated their MX records correctly.

Protection mode

ToolWhat it does
mc_update_protection_mode
Pro · Write
Updates the account protection mode (gateway or gatewayless).

Gateway configuration

ToolWhat it does
mc_delete_outbound_ip_addresses
Pro · Destructive
DESTRUCTIVE: deletes all outbound IP Addresses for customer’s mail platform.
mc_get_email_statistics
Free · Read-only
This endpoint can be used to the email statistics for an account.This can used to check that mail delivery is working.
mc_get_gateway_details
Free · Read-only
Returns outbound config information such as hostnames, mail platform(s).
mc_list_outbound_ip_addresses
Free · Read-only
Gets list of all outbound IP Addresses for customer’s mail platform.
mc_replace_outbound_ip_addresses
Pro · Destructive
DESTRUCTIVE: replaces all outbound IP Addresses for customer’s mail platform.
mc_update_gateway_details
Pro · Write
Updates outbound config information such as Outbound enabled flag mail platform(s), updates umbrella accounts when mail platform is M365, GSuite or Google workspace.

Held messages

ToolWhat it does
mc_find_held_messages
Free · Read-only
This API endpoint can be used to find messages currently held for review, including the hold reason, hold group, policy information, sender and recipients.
mc_get_hold_message_list
Free · Read-only
This API endpoint can be used to get information about held messages, including the reason, hold level, sender and recipients.
mc_get_hold_summary_list
Free · Read-only
This API endpoint can be used to get counts of currently held messages for each hold reason.
mc_reject_held_messages
Pro · Destructive
DESTRUCTIVE: this API endpoint can be used to reject a currently held message based on the Find Held Messages API endpoint.
mc_release_held_messages
Pro · Destructive
DESTRUCTIVE: this API endpoint can be used to release a currently held message based on the Find Held Messages API endpoint.

Journaling

ToolWhat it does
mc_create_journaling_service
Pro · Write
When the customer subscribes to Internal Email Protect, Continuity or Archiving we need to ensure that internal messages (that normally remain internal to the customers' email infrastructure) get.
mc_delete_journaling_service
Pro · Destructive
DESTRUCTIVE: this endpoint deletes journaling connector specified with the journaling id in the endpoint.
mc_get_journaling_service
Free · Read-only
This endpoint returns journaling connector, their configuration and current status specified with the journaling id in the endpoint.
mc_get_journaling_service_mx
Free · Read-only
This endpoint returns journaling connectors, their configuration and current status.
mc_list_journaling_services
Free · Read-only
This endpoint returns all journaling connectors, their configuration and current status within the customer’s account.
mc_update_journaling_service
Pro · Write
The endpoint updates journaling connector specified in the journaling id.

Managed senders

ToolWhat it does
mc_bulk_delete_managed_internal_addresses
Pro · Destructive
DESTRUCTIVE: delete all Managed Senders entries that contain internal recipients as senders on the account.
mc_bulk_delete_managed_recipient_senders
Pro · Destructive
DESTRUCTIVE: delete Managed Senders entries for a specific internal recipient.
mc_bulk_delete_managed_senders
Pro · Destructive
DESTRUCTIVE: delete Managed Senders entries based on sender email addresses or sender domains in addition to optional filtering criteria (Type, Action and Trusted).
mc_permit_or_block_sender
Pro · Destructive
DESTRUCTIVE: permit or block a managed sender.

Message tracking

ToolWhat it does
mc_decode_ttp_url
Free · Read-only
Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Account | Dashboard | Read.
mc_find_processing_messages
Free · Read-only
This API endpoint will return messages currently being processed by Mimecast.
mc_get_email_queues
Free · Read-only
This endpoint can be used to get the count of the inbound and outbound email queues at specified times.
mc_get_gateway_message_file
Free · Read-only
This API endpoint can be used to retrieve the file or attachment for given id.
mc_get_message_info
Free · Read-only
This API endpoint can be used to retrieve detailed information about a specific message.
mc_search_messages
Free · Read-only
Search for messages.

Outbound email

ToolWhat it does
mc_send_email
Pro · Destructive
DESTRUCTIVE: this API endpoint can be used to send an email.
mc_upload_email_file
Pro · Write
Upload a file so it can be attached to an outbound email.

Cloud Integrated policies

ToolWhat it does
mc_create_ci_policy
Pro · Write
Add a policy.
mc_delete_ci_policy
Pro · Destructive
DESTRUCTIVE: delete a policy.
mc_get_ci_default_policy
Free · Read-only
Get default policy.
mc_get_ci_policy
Free · Read-only
Find policy by ID.
mc_onboard_ci_account
Pro · Write
Onboard a customer account.
mc_update_ci_default_policy
Pro · Write
Update default policy.
mc_update_ci_policy
Pro · Write
Update a policy.

Connectors

ToolWhat it does
mc_create_connector
Pro · Write
Initiate consent management request.
mc_delete_connector
Pro · Destructive
DESTRUCTIVE: deletes an existing Connector.
mc_get_connector
Free · Read-only
Fetches Connector information for an account by Connector ID Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors creation.
mc_list_connectors
Free · Read-only
Fetches all existing Connectors information for an account.
mc_update_connector
Pro · Write
Updates Connectors with following details - Connector Name, Connector description Please note that this endpoint only work for Directory Synchronisation - Azure Standard and Azure GCC High Connectors.

Marketplace integrations

ToolWhat it does
mc_create_marketplace_integration
Pro · Write
Start integration onboarding (consent request).
mc_delete_marketplace_consent_request
Pro · Destructive
DESTRUCTIVE: cancel consent request.
mc_delete_marketplace_integration
Pro · Destructive
DESTRUCTIVE: delete an integration.
mc_get_marketplace_consent_request
Free · Read-only
Get consent request status.
mc_get_marketplace_integration
Free · Read-only
Get integration details (includes enabled).
mc_list_marketplace_consent_requests
Free · Read-only
List consent requests.
mc_list_marketplace_integrations
Free · Read-only
List integrations (includes enabled).
mc_update_marketplace_integration
Pro · Write
Update an integration.

Address alteration

ToolWhat it does
mc_create_address_alteration_definition
Pro · Write
This API endpoint can be used to create new Address Alteration definitions within an Address Alteration Set or at the root level for policy-less processing.
mc_create_address_alteration_policy
Pro · Write
This API endpoint can be used to create new Address Alteration policy to apply an alteration definition based on sender and recipient values.
mc_create_address_alteration_set
Pro · Write
This API endpoint can be used to create new Address Alteration Set, to hold a number of alteration definitions.
mc_delete_address_alteration_definition
Pro · Destructive
DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration definitions within an Address Alteration Set.
mc_delete_address_alteration_policy
Pro · Destructive
DESTRUCTIVE: this API endpoint can be used to remove an existing Address Alteration policy.
mc_get_address_alteration_definition
Free · Read-only
This API endpoint can be used to find an existing Address Alteration Definition.
mc_get_address_alteration_policy
Free · Read-only
This API endpoint can be used to find an existing Address Alteration policy.
mc_get_address_alteration_set
Free · Read-only
This API endpoint can be used to find an existing Address Alteration Set.
mc_update_address_alteration_policy
Pro · Write
This API endpoint can be used to update an existing Address Alteration policy.

Anti-spoofing

ToolWhat it does
mc_create_anti_spoofing_policy
Pro · Write
Creates a anti-spoofing policy for an account.
mc_delete_anti_spoofing_policy
Pro · Destructive
DESTRUCTIVE: deletes a anti-spoofing policy.
mc_get_anti_spoofing_policy
Free · Read-only
Gets an anti-spoofing policy for an account.
mc_list_anti_spoofing_policies
Free · Read-only
Gets all anti-spoofing policies for an account.
mc_update_anti_spoofing_policy
Pro · Write
Updates a anti-spoofing policy for an account.

Anti-spoofing bypass

ToolWhat it does
mc_create_anti_spoofing_bypass_policy
Pro · Write
Creates a anti-spoofing bypass policy for an account.
mc_create_anti_spoofing_bypass_policy_mx
Pro · Write
This endpoint can be used to create a new Anti-Spoofing SPF based Bypass policy.
mc_delete_anti_spoofing_bypass_policy
Pro · Destructive
DESTRUCTIVE: deletes a anti-spoofing bypass policy.
mc_delete_anti_spoofing_bypass_policy_mx
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies.
mc_get_anti_spoofing_bypass_policy
Free · Read-only
Gets a anti-spoofing bypass policy for an account.
mc_get_anti_spoofing_bypass_policy_mx
Free · Read-only
This endpoint can be used to find existing Anti-Spoofing SPF based Bypass policies.
mc_list_anti_spoofing_bypass_policies
Free · Read-only
Gets all anti-spoofing bypass policies for an account.
mc_update_anti_spoofing_bypass_policy
Pro · Write
Updates a anti-spoofing policy for an account.
mc_update_anti_spoofing_bypass_policy_mx
Pro · Write
This endpoint can be used to update an existing Anti-Spoofing SPF based Bypass policy.

Blocked senders

ToolWhat it does
mc_create_blocked_senders_policy
Pro · Destructive
DESTRUCTIVE: creates a blocked senders policy for an account.
mc_create_blocked_senders_policy_mx
Pro · Destructive
DESTRUCTIVE: this endpoint creates new blocked sender policies, which can be used to manage a combination of sender and recipient restrictions.
mc_delete_blocked_senders_policy
Pro · Destructive
DESTRUCTIVE: deletes a blocked senders policy.
mc_get_blocked_senders_policy
Free · Read-only
Gets an blocked senders policy for an account.
mc_get_blocked_senders_policy_mx
Free · Read-only
This endpoint retrieves blocked sender policies.
mc_list_blocked_senders_policies
Free · Read-only
Gets all blocked senders policies for an account.
mc_update_blocked_senders_policy
Pro · Destructive
DESTRUCTIVE: updates a blocked senders policy for an account.

DNS authentication

ToolWhat it does
mc_create_dns_auth_outbound_definition
Pro · Write
The Api endpoint can be used to create a DNS Authentication - Outbound definition, DKIM keys and the DNS entry.
mc_create_dns_auth_outbound_policy
Pro · Write
The Api endpoint can be used to create DNS Authentication - Outbound policy.
mc_delete_dns_auth_outbound_definition
Pro · Destructive
DESTRUCTIVE: the Api endpoint can be used to delete a DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_delete_dns_auth_outbound_policy
Pro · Destructive
DESTRUCTIVE: the Api endpoint can be used to delete DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_get_dns_auth_outbound_definition
Free · Read-only
The Api endpoint can be used to get DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_get_dns_auth_outbound_policy
Free · Read-only
The Api endpoint can be used to get DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_list_dns_auth_outbound_definitions
Free · Read-only
The Api endpoint can be used to get all DNS Authentication - Outbound definitions.
mc_list_dns_auth_outbound_policies
Free · Read-only
The Api endpoint can be used to get all DNS Authentication - Outbound policies within the customer’s account.
mc_update_dns_auth_outbound_definition
Pro · Write
The Api endpoint can be used to update a DNS Authentication - Outbound definition with definition id specified in the endpoint.
mc_update_dns_auth_outbound_policy
Pro · Write
The Api endpoint can be used to update DNS Authentication - Outbound policies with policy id specified in the endpoint.
mc_verify_dns_auth_outbound_definition
Pro · Write
The Api endpoint can be used to verify that DKIM within the DNS Authentication - Outbound policies with policy id specified in the endpoint is configured correctly.

Delivery routes

ToolWhat it does
mc_create_delivery_route_definition
Pro · Write
The Api endpoint can be used to create a delivery route definition.
mc_create_delivery_route_policy
Pro · Write
The Api endpoint can be used to create a Delivery Route policy.
mc_delete_delivery_route_definition
Pro · Destructive
DESTRUCTIVE: the Api endpoint can be used to delete a delivery route definition with definition id specified in the uri.
mc_delete_delivery_route_policy
Pro · Destructive
DESTRUCTIVE: the Api endpoint can be used to delete the delivery route with policy id specified in the uri.
mc_get_delivery_route_definition
Free · Read-only
The Api endpoint can be used to get a delivery route definition with definition id specified in the uri.
mc_get_delivery_route_policy
Free · Read-only
The Api endpoint can be used to get a delivery route policy with policy id specified in the uri.
mc_list_delivery_route_definitions
Free · Read-only
The Api endpoint can be used to get all existing delivery route definitions.
mc_list_delivery_route_policies
Free · Read-only
The Api endpoint can be used to get all existing delivery route policies.
mc_update_delivery_route_definition
Pro · Write
The Api endpoint can be used to update a delivery route definition with definition id specified in the uri.
mc_update_delivery_route_policy
Pro · Write
The Api endpoint can be used to update the delivery route with policy id specified in the uri.
mc_verify_delivery_route
Pro · Write
The Api endpoint can be used to verify that the delivery route policy is valid and that Mimecast can sucessfully communicate with the provided IP address or Hostname.

Greylisting

ToolWhat it does
mc_create_greylisting_policy
Pro · Write
Creates a greylisting policy.
mc_delete_greylisting_policy
Pro · Destructive
DESTRUCTIVE: deletes a greylisting policy.
mc_get_greylisting_policy
Free · Read-only
Get greylisting policy by an id.
mc_list_greylisting_policies
Free · Read-only
Gets all greylisting policies for an account.
mc_update_greylisting_policy
Pro · Write
Updates a greylisting policy.

Managed URLs

ToolWhat it does
mc_create_managed_url
Pro · Write
This endpoint can be used to add new managed URL entries for URL Protection.
mc_delete_managed_url
Pro · Destructive
DESTRUCTIVE: this API endpoint allows for the removal of an existing Managed URL entry.
mc_list_managed_urls
Free · Read-only
This endpoint can be used to return all entries currently in an accounts Managed URL list.

Web security

ToolWhat it does
mc_create_web_white_url_policy
Pro · Write
This endpoint can be used to create a Web Security Block or Allow List policy for domains or URLs.
mc_delete_web_white_url_policy
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to delete an existing Web Security Block or Allow List policy for domains or URLs.
mc_get_web_white_url_policy
Free · Read-only
This endpoint can be used to get information about an existing Web Security Block or Allow List policy for domains or URLs.
mc_update_web_white_url_policy
Pro · Write
This endpoint can be used to update an existing Web Security Block or Allow List policy for domains or URLs.

Protection logs

ToolWhat it does
mc_get_dlp_logs
Free · Read-only
This endpoint can be used to retrieve messages that triggered a DLP or Content Examination policy.
mc_get_ttp_attachment_logs
Free · Read-only
Pre-requisites In order to to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | Attachment Protection.
mc_get_ttp_impersonation_logs
Free · Read-only
This endpoint can be used to get messages containing information flagged by an Impersonation Protection configuration.
mc_get_ttp_url_logs
Free · Read-only
Pre-requisites In order to successfully use this endpoint the role assigned to the app must have at least the following level of application permissions granted Monitoring | URL Protection | Read.

Remediation

ToolWhat it does
mc_create_ttp_remediation
Pro · Write
This endpoint can be used to create a remediation incident, by messageId, file hash or a url contained in an email.
mc_create_ttp_remediation_v2
Pro · Write
This endpoint can be used to create a remediation incident, by file hash or a url of by one or more messageId.
mc_find_ttp_remediation_incidents
Free · Read-only
This endpoint can be used to search for existing remediation incidents.
mc_get_bulk_remediation_status
Free · Read-only
Get the bulk remediation status by batch ID.
mc_get_event_remediation_status
Free · Read-only
Get remediation status by event ID.
mc_get_ttp_remediation_incident
Free · Read-only
This endpoint can be used to get information about an existing incident.
mc_remediate_security_event
Pro · Destructive
DESTRUCTIVE: remediate a security event by event ID.
mc_remediate_security_events_bulk
Pro · Destructive
DESTRUCTIVE: remediate bulk security threat events.
mc_search_ttp_remediation_hash
Free · Read-only
This endpoint can be used to identify if an account has seen a specific file hash within messages over the last year.

Reported emails

ToolWhat it does
mc_create_threat_report_subscription
Pro · Write
Create Subscriptions.
mc_delete_threat_report_subscription
Pro · Destructive
DESTRUCTIVE: delete Subscription.
mc_get_reported_email
Free · Read-only
Retrieve reported email.
mc_get_threat_analysis
Free · Read-only
Retrieve Threat Analysis by Id.
mc_list_reported_emails
Free · Read-only
List Reported Emails.
mc_list_threat_report_subscriptions
Free · Read-only
List Subscriptions.
mc_list_threat_reports
Free · Read-only
List Threat Reports.
mc_update_threat_report_subscription
Pro · Write
Renew Subscription.

SIEM feeds

ToolWhat it does
mc_list_siem_batch_events_cg
Free · Read-only
Retrieve CG Events.
mc_list_siem_batch_events_ci
Free · Read-only
Retrieve CI Events.
mc_list_siem_events_cg
Free · Read-only
Retrieve CG Events.
mc_list_siem_events_ci
Free · Read-only
Retrieve CI Events.

Threat events

ToolWhat it does
mc_get_threat_event_details
Free · Read-only
Developer API to fetch threat details.
mc_list_threat_events
Free · Read-only
List Threat events.

Threat intelligence

ToolWhat it does
mc_create_byo_threat_intel_batch
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to import a single or batch of multiple indicators.
mc_delete_byo_threat_intel_batch
Pro · Destructive
DESTRUCTIVE: this endpoint can be used to remove a batch of indicators.
mc_get_byo_threat_intel_batches
Free · Read-only
This endpoint can be used to retrieve information about all existing batches.
mc_get_byo_threat_intel_quota
Free · Read-only
This endpoint can be used to retrieve the number of indicators in use and the number of remaining indicators that can be added.
mc_get_ttp_threat_intel_feed
Free · Read-only
This feed can be used to return identified malware threats at a customer or regional grid level.

Threat statistics

ToolWhat it does
mc_get_attachment_scan_stats
Free · Read-only
Get Attachment Scan stats.
mc_get_gateway_detection_stats
Free · Read-only
Get Gateway Detection stats by type.
mc_get_impersonation_stats
Free · Read-only
Get Impersonation stats.
mc_get_phishing_stats
Free · Read-only
Get phishing stats.
mc_get_suspicious_stats
Free · Read-only
Get suspicious stats.
mc_get_threats_by_recipient_stats
Free · Read-only
List Threat statistics by recipient.
mc_get_threats_by_sender_stats
Free · Read-only
List Threat statistics by sender.
mc_get_unwanted_stats
Free · Read-only
Get unwanted stats.
mc_get_url_click_stats
Free · Read-only
Get URL Click stats.