Mimecast Security
mimecast security is an email security platform that protects against threats like phishing and malware while offering archiving solutions mimecast security is a comprehensive email security platform that provides advanced threat protection, data leak prevention, and secure email archiving the integration with swimlane turbine enables seamless automation of email threat detection and response, allowing security teams to efficiently manage incidents, retrieve detailed message information, and enforce security policies this integration enhances the ability to automate routine security tasks, streamline workflows, and improve overall security posture by leveraging mimecast's robust capabilities within the swimlane turbine environment prerequisites before you can use the mimecast security connector for turbine, you'll need access to the mimecast api this requires the following hmac authentication using the following parameters url the endpoint url for accessing mimecast's api access key a unique key provided by mimecast for api access app id the application identifier for your mimecast integration app key a key associated with your application id for secure access secret key a secret key used for generating hmac signatures oauth2 authorization using the following parameters url the endpoint url for accessing mimecast's oauth2 service client id the client identifier for your oauth2 application client secret a secret associated with your client id for secure access action api permissions below is the table of required api scopes for the set of credentials used in the asset and broken down by action action required api permissions add or remove group members api permissions https //integrations mimecast com/documentation/endpoint reference/directory/add group member/ archive message search api permissions https //integrations mimecast com/documentation/endpoint reference/archive/search/ create managed url api permissions https //integrations mimecast com/documentation/endpoint reference/targeted threat protection url protect/create managed url/ create remediation incident api permissions https //integrations mimecast com/documentation/endpoint reference/threat intel/create incident/ decode url api permissions https //integrations mimecast com/documentation/endpoint reference/targeted threat protection url protect/get managed url/ get archived file attachment api permissions https //integrations mimecast com/documentation/endpoint reference/archive/get file/ get archived message details api permissions https //integrations mimecast com/documentation/endpoint reference/archive/get message detail/ get archived message part api permissions https //integrations mimecast com/documentation/endpoint reference/archive/get message part/ get archived messages list api permissions https //integrations mimecast com/documentation/endpoint reference/archive/get message list/ get archived search logs api permissions https //integrations mimecast com/documentation/endpoint reference/logs and statistics/get archive search logs/ get group members api permissions https //integrations mimecast com/documentation/endpoint reference/directory/get group members/ get groups api permissions https //integrations mimecast com/documentation/endpoint reference/directory/find groups/ get file api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/get file/ get held messages list api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/get hold message list/ get ttp impersonation protect logs api permissions https //integrations mimecast com/documentation/endpoint reference/logs and statistics/get ttp impersonation protect logs/ get inbound & output message queue hold list api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/inbound outbound queues/ get incident api permissions https //integrations mimecast com/documentation/endpoint reference/threat intel/get incident/ get managed urls api permissions https //integrations mimecast com/documentation/endpoint reference/targeted threat protection url protect/get managed url/ get message detail api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/get message detail/ get message info api permissions https //integrations mimecast com/documentation/endpoint reference/message finder formally tracking/get message info/ get ttp url logs api permissions https //integrations mimecast com/documentation/endpoint reference/logs and statistics/get ttp url logs/ message finder search api permissions https //integrations mimecast com/documentation/endpoint reference/message finder formally tracking/search/ permit or block sender api permissions https //integrations mimecast com/documentation/endpoint reference/managed sender/ reject message from queue api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/reject message/ release message from queue api permissions https //integrations mimecast com/documentation/endpoint reference/message queues/release message/ capabilities the mimecast connector provides the following capabilities add or remove group members archive message search create managed url create remediation incident decode url get account get archived file attachment get archived message details get archived message part get archived messages list get archived search logs get file get group members get groups get held messages list and so on additional information about capabilities see the building search queries https //www mimecast com/tech connect/documentation/tutorials/building search queries/ guide for more information on building search queries notes mimecast endpoint reference documentation https //integrations mimecast com/documentation/endpoint reference/mimecast api documentation https //www mimecast com/tech connect/documentation you will need to use a mimecast base url https //community mimecast com/docs/doc 1070 , see the below table to set access/secrets to never expire you must update the authentication cache ttl setting in the service user's effective authentication profile to "never expire " region api endpoint check for update urls australia au api mimecast com https //updates au mimecast com/update/descriptors/mfo/latest https //updates au mimecast com/update/descriptors/mfo/latest europe (excluding germany) eu api mimecast com https //updates uk mimecast com/update/descriptors/mfo/latest https //updates uk mimecast com/update/descriptors/mfo/latest germany de api mimecast com https //updates de mimecast com/update/descriptors/mfo/latest https //updates de mimecast com/update/descriptors/mfo/latest offshore jer api mimecast com https //updates jer mimecast com/update/descriptors/mfo/latest https //updates jer mimecast com/update/descriptors/mfo/latest required api mimecast com n/a used for initial account discovery south africa za api mimecast com https //updates za mimecast com/update/descriptors/mfo/latest https //updates za mimecast com/update/descriptors/mfo/latest united states us api mimecast com https //updates us mimecast com/update/descriptors/mfo/latest https //updates us mimecast com/update/descriptors/mfo/latest about address alteration policy updates you must define the input required for your use case in the policy update action the policy update action doesn't require any policy input, which is how mimecast defined this endpoint if no policy input is defined, then the action will fail for more information about all the available inputs, see the official api documentation https //integrations mimecast com/documentation/endpoint reference/policies/address alteration/update policy/ additional notes please provide admin access or required premissions to your mimecast account or credentials wherever applicable to make the connector actions working configurations mimecast hmac authenticates using hmac configuration parameters parameter description type required url a url to the target host string required access key access key string required app id app id string required app key app key string required secret key secret key string required verify ssl verify ssl certificate boolean optional http proxy a proxy to route requests through string optional mimecast oauth 2 0 client credentials authenticates using oauth 2 0 client credentials configuration parameters parameter description type required url a url to the target host string required client id the client id string required client secret the client secret string required verify ssl verify ssl certificate boolean optional http proxy a proxy to route requests through string optional actions get archived file attachment retrieve a file attachment from an archived message in mimecast security using specified data parameters endpoint url /api/archive/get file method post input argument name type required description data array optional response data data id string optional response data input example {"json body" {"data" \[{"id" "enpfjkulwjayrf9ltlpi0jzvd07vojpgpqncn6gkn0mwd8mjo4j faigs7mbc8 l3pef4q3obi0qezf57wptn1w1r3briwppvh7nntu t9qiv2w1wewfjo1xezhd3yc km1 rx8v ptzdk1rb9bwekpxo29 bhcis7urso qbcy8dumhrgznk t7ckmyzzroahvbwd30aegmb x1snirafcwe04zwscmzeqs i9zimmkwsgkoefadememysinccsy emy t4a6feswu"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data urls array response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "tue, 16 sep 2025 05 37 26 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "793b7425 5352 48ef 9b2c eb9a5e4aed6a","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fai get archived message details retrieve detailed information about a specific message from mimecast's archive using the provided data parameters endpoint url /api/archive/get message detail method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "enpvzlklgkaubed mq8fze5bd5hugbxtkqsh4y23rns8ywv99 yx5 8cznktaqwrsciyjhnkp8fpgwfhlq wf1mg 8ku3syml9noymakdeyd63f78adegph0uze9jgb34trt6erwcsbrvppxuac7tyefpzoppf qmn1tbi r4csabwfn3bhpkjipyt wztugypnmwois s5 v1duun21nisheknbyvbpkufqyr vtfaiifz 58vo3bc9a"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data attachments array response data data attachments bodytype number response data data attachments contentid string response data data attachments contenttype string response data data attachments extension string response data data attachments filename string response data data attachments id string response data data attachments sha256 string response data data attachments size number response data data attachments verdict string response data data cc array response data data cc displayablename string response data data cc emailaddress string response data data envelopefrom object response data data envelopefrom displayablename string response data data envelopefrom emailaddress string response data data hashtmlbody boolean response data data hastextbody boolean response data data headerdate string response data data headers array response data data headers name string response data data id object response data output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ get archived messages list retrieve a list of archived messages for a specified user in mimecast security requires a data payload endpoint url /api/archive/get message list method post input argument name type required description data array optional response data data end string optional response data data includealiases boolean optional response data data includedelegates boolean optional response data data mailbox string optional response data data start string optional response data data view string required response data input example {"json body" {"data" \[{"end" "2022 10 13t16 57 02+0000","includealiases"\ true,"includedelegates"\ true,"mailbox" "admin\@mctest swimlane com","start" "2022 10 13t16 57 02+0000","view" "inbox"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data attachmentcount number response data data ccm boolean response data data expired boolean response data data from object response data data from displayablename string response data data from emailaddress string response data data id object response data data read boolean response data data recalled boolean response data data received string response data data size number response data data smash string response data data status string response data data subject string response data data to object response data data to displayablename string response data data to emailaddress string response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ get archived message part retrieve a specific part of an archived message from mimecast security using the provided data parameters endpoint url /api/archive/get message part method post input argument name type required description data array optional response data data context string optional response data data id string optional response data data type string optional response data data extractfromhtml boolean optional response data data mailbox string optional response data data stripdangerous boolean optional response data data stripimg boolean optional response data data stripstyles boolean optional response data data transposeinlinecid boolean optional response data input example {"json body" {"data" \[{"context" "delivered","id" "enpvzlklgkaubed mq8fze5bd5hugbxtkqsh4y23rns8ywv99 yx5 8cznktaqwrsciyjhnkp8fpgwfhlq wf1mg 8ku3syml9noymakdeyd63f78adegph0uze9jgb34trt6erwcsbrvppxuac7tyefpzoppf qmn1tbi r4csabwfn3bhpkjipyt wztugypnmwois s5 v1duun21nisheknbyvbpkufqyr vtfaiifz 58vo3bc9a","type" "rfc822","extractfromhtml"\ true,"mailbox" "admin\@mctest swimlane com","stripdangerous"\ true,"stripimg"\ true,"stripstyles"\ true,"transposeinlinecid"\ true}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data urls array response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"meta" {"status" 200 get archived search logs retrieve archived search logs from mimecast security using specified json body parameters endpoint url /api/archive/get search logs method post input argument name type required description data array optional response data data end string optional response data data query string optional response data data start string optional response data input example {"json body" {"data" \[{"end" "2022 10 24t20 51 21+0000","query" "\<?xml version=\\"1 0\\"?> \<xmlquery trace=\\"iql,muse\\"> \<metadata query type=\\"emailarchive\\" archive=\\"true\\" active=\\"false\\" page size=\\"25\\" startrow=\\"0\\"> \<mailboxes> \<mailbox include aliases=\\"true\\">admin\@mctest swimlane com\</mailbox> \</mailboxes> \<smartfolders/> \<return fields> \<return field>attachmentcount\</return field> \<return field>status\</return field> \<return field>subject\</return field> \<return field>size\</return field> \<return field>receiveddate\</return field> \<return field>displayfrom\</return field> \<return field>displayfromaddress\</return field> \<return field>id\</return field> \<return field>displayto\</return field> \<return field>displaytoaddresslist\</return field> \<return field>smash\</return field> \</return fields> \</metadata> \<muse> \<text>\</text> \<date select=\\"last year\\"/> \<sent>\</sent> \<docs select=\\"optional\\"> \</docs> \<route/> \</muse> \</xmlquery>","start" "2022 10 23t20 51 21+0000"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value meta pagination object output field meta pagination meta pagination pagesize number output field meta pagination pagesize meta pagination totalcount number count value data array response data data logs array response data data logs createtime string response data data logs emailaddr string response data data logs source string response data data logs searchtext string response data data logs searchpath string response data data logs searchreason string response data data logs isadmin boolean response data data logs musequery string response data data logs description string response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "mon, 24 oct 2022 21 18 56 gmt","content type" "application/json","content length" "3360","connection" "keep alive","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","x ratelimit limit" "800","x ratelimit remaining" "799","x ratelimit reset" "5000"},"reason" "ok","json body" {"meta" {"status" 200,"pagination" {}},"data" \[{}],"fail" \[]}} archive search conduct a comprehensive search in mimecast security's archive using specified data parameters endpoint url /api/archive/search method post input argument name type required description meta object optional parameter for archive search meta pagination object optional parameter for archive search meta pagination pagetoken string optional parameter for archive search data array optional response data data admin boolean required response data data query string required response data input example {"json body" {"meta" {"pagination" {"pagetoken" "pagetoken"}},"data" \[{"admin"\ false,"query" "\<?xml version=\\"1 0\\"?> \<xmlquery trace=\\"iql,muse\\"> \<metadata query type=\\"emailarchive\\" archive=\\"true\\" active=\\"false\\" page size=\\"100\\" startrow=\\"0\\"> \<muse> \<text>subject\ subject\</text> \<date select=\\"last year\\"/> \<sent>\</sent> \<docs select=\\"optional\\"> \</docs> \<route/> \</muse> \</xmlquery>"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data queryduration number response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key query string output field fail key query fail key admin boolean output field fail key admin output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail add group member add a new member to a specified group in mimecast security using the provided json body endpoint url /api/directory/add group member method post input argument name type required description data array optional response data data domain string optional response data data notes string optional response data data emailaddress string optional response data data id string required response data input example {"json body" {"data" \[{"domain" "www test1 com","emailaddress" "test\@test1 com","id" "enovzk0lgjayaod 8l4tytvkhq6mkngnlaxqredrlc2fc5ok nt2fw7pbyqyvsppwabungvziomyxuepgmw 1bpydq9w47fxjur8fg xmosnfrgpojsj x0wizheduh3xcjf6ozwagunuxppu 8ltax8wqvrhhjgf 31bbbvulgwt2olkrhqzskt7dwpjrralgzea2smmuwubnhwymsh1oygxlpyuyfndmhfmwh9 w4tsgj5 ga76ubc"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data emailaddress string response data data folderid string response data data id string response data data internal boolean response data data notes string response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key domain string output field fail key domain fail key emailaddress string output field fail key emailaddress fail key id string unique identifier fail key notes string output field fail key notes output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ get groups retrieve matching groups from mimecast using query parameters specified in the json body data endpoint url /api/directory/find groups method post input argument name type required description data array optional response data data query string optional response data data source string optional response data input example {"json body" {"data" \[{"query" "query string","source" "source string"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data folders array response data data folders description string response data data folders foldercount number response data data folders id string response data data folders parentid string response data data folders source string response data data query string response data data source string response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key query string output field fail key query fail key source string output field fail key source output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail get group members retrieve a list of members for a specified group in mimecast security using the provided json body details endpoint url /api/directory/get group members method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "enovzk0lgjayaod 8l4tytvkhq6mkngnlaxqredrlc2fc5ok nt2fw7pbyqyvsppwabungvziomyxuepgmw 1bpydq9w47fxjur8fg xmosnfrgpojsj x0wizheduh3xcjf6ozwagunuxppu 8ltax8wqvrhhjgf 31bbbvulgwt2olkrhqzskt7dwpjrralgzea2smmuwubnhwymsh1oygxlpyuyfndmhfmwh9 w4tsgj5 ga76ubc"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data groupmembers array response data data groupmembers domain string response data data groupmembers emailaddress string response data data groupmembers internal boolean response data data groupmembers name string response data data groupmembers type string response data data groupmembers notes string response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key id string unique identifier output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail remove group member remove specified members from a mimecast security group using the provided json body for configuration endpoint url /api/directory/remove group member method post input argument name type required description data array optional response data data domain string optional response data data emailaddress string optional response data data id string required response data input example {"json body" {"data" \[{"domain" "www test1 com","emailaddress" "test\@test1 com","id" "enovzk0lgjayaod 8l4tytvkhq6mkngnlaxqredrlc2fc5ok nt2fw7pbyqyvsppwabungvziomyxuepgmw 1bpydq9w47fxjur8fg xmosnfrgpojsj x0wizheduh3xcjf6ozwagunuxppu 8ltax8wqvrhhjgf 31bbbvulgwt2olkrhqzskt7dwpjrralgzea2smmuwubnhwymsh1oygxlpyuyfndmhfmwh9 w4tsgj5 ga76ubc"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data id string response data data folderid string response data data emailaddress string response data data internal boolean response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "mon, 10 oct 2022 16 06 53 gmt","content type" "application/json","content length" "606","connection" "keep alive","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","x ratelimit limit" "800","x ratelimit remaining" "799","x ratelimit reset" "5000"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fail" \[]}} get inbound and outbound message queue hold list retrieve inbound and outbound email queue messages from mimecast security using specified data parameters endpoint url /api/email/get email queues method post input argument name type required description data array optional response data data start string required response data data end string required response data input example {"json body" {"data" \[{"start" "2015 11 16t14 49 18+0000","end" "2015 11 16t14 49 18+0000"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data inboundemailqueue array response data data inboundemailqueue count number response data data inboundemailqueue date string response data data outboundemailqueue array response data data outboundemailqueue count number response data data outboundemailqueue date string response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key end string output field fail key end fail key start string output field fail key start output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail get held messages list retrieve details of messages on hold in mimecast security using specified criteria within the required data payload endpoint url /api/gateway/get hold message list method post input argument name type required description data array optional response data data admin boolean optional response data data start string optional response data data searchby object optional response data data searchby fieldname string optional response data data searchby value string optional response data data end string optional response data input example {"json body" {"data" \[{"admin"\ true,"start" "2015 11 16t14 49 18+0000","searchby" {"fieldname" "field name","value" "value"},"end" "2015 11 16t14 49 18+0000"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data datereceived string response data data from object response data data from displayablename string response data data from emailaddress string response data data fromheader object response data data fromheader displayablename string response data data fromheader emailaddress string response data data hasattachments string response data data id string response data data policyinfo string response data data reason string response data data reasoncode string response data data route string response data data size number response data data subject string response data data to object response data data to displayablename string response data data to emailaddress string response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ get message details retrieve detailed information about a specific message from mimecast security using the provided data parameters endpoint url /api/gateway/message/get message detail method post input argument name type required description data array optional response data data viewtype string optional response data data id string required response data data context string optional response data data mailbox string optional response data input example {"json body" {"data" \[{"viewtype" "archive","id" "mimecast secure id","context" "delivered","mailbox" "mailbox\@mailbox com"}]}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" {}} reject message from queue reject a specific message from the mimecast held queue using provided data parameters endpoint url /api/gateway/hold reject method post input argument name type required description data array optional response data data message string optional response data data ids array required response data data reasontype string optional response data data notify boolean optional response data input example {"json body" {"data" \[{"message" "rejection message to be returned to sender","ids" \["enpvzl0lgjaybed smshzc1c0eukpfkhlaeqhb9v vgt3obi6l9nl10 53dog3hizqdvgezi1wjthucjx7z 4a9bo uzbazqcgmnjsj8bdukjun1ti sazylibspz3hoqr6yomhurhdl00tqvsvzhdgv3npmepbfsvtlxfo3wvzskyr1gtxbia2v9 l5w8auemwyhooaeg 2 yk5go6bx1apha9ahubgikyaexxdhoepqcllv 5aqapqs0"],"reasontype" "message contains undesirable content","notify"\ false}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data id string response data data reject boolean response data fail array output field fail fail errors array error message if any fail errors code string error message if any fail errors message string response message fail errors retryable boolean error message if any fail key object output field fail key fail key ids array unique identifier fail key message string response message fail key notify boolean output field fail key notify fail key reasontype string type of the resource output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail release message from queue release a specific message from mimecast's hold queue using provided data parameters endpoint url /api/gateway/hold release method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "enpvzlklgkaubed mq8fze5bd5hugbxtkqsh4y23rns8ywv99 yx5 8cznktaqwrsciyjhnkp8fpgwfhlq wf1mg 8ku3syml9noymakdeyd63f78adegph0uze9jgb34trt6erwcsbrvppxuac7tyefpzoppf qmn1tbi r4csabwfn3bhpkjipyt wztugypnmwois s5 v1duun21nisheknbyvbpkufqyr vtfaiifz 58vo3bc9a"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data id string response data data release boolean response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "thu, 13 oct 2022 20 07 50 gmt","content type" "application/json","content length" "317","connection" "keep alive","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","x ratelimit limit" "800","x ratelimit remaining" "799","x ratelimit reset" "5000"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fail" \[]}} get account retrieve account details from mimecast security using the provided json body input endpoint url /api/account/get account method post output parameter type description status code number http status code of the response reason string response reason phrase fail array output field fail fail file name string name of the resource fail file string output field fail file meta object output field meta meta status number status value data array response data data maxretention number response data data accountcode string response data data domain string response data data automatedsegmentpurge boolean response data data databasecode string response data data supportcode string response data data region string response data data accountname string response data data maxretentionconfirmed boolean response data data archive boolean response data data gateway boolean response data data policyinheritance boolean response data data passphrase string response data data type string response data data mailplatform string response data data packages array response data data mimecastid string response data output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"fail" \[],"meta" {"status" 200},"data" \[{}]}} get ttp attachment logs get ttp attachment logs from mimecast security using the provided json body to analyze email security events endpoint url /api/ttp/attachment/get logs method post input argument name type required description data array optional response data data from string optional start date of logs to return in the following format 2015 11 16t14 49 18 +0000 default is the start of the current day data oldestfirst boolean optional default false orders results with the most recent first data result string optional filters logs by scan result, must be one of safe, malicious, timeout, error, unsafe, or all data route string optional filters logs by route, must be one of inbound, outbound, internal, or all data to string optional end date of logs to return in the following format 2015 11 16t14 49 18 +0000 input example {"json body" {"data" \[{"from" "2016 10 01t14 49 18+0000","oldestfirst"\ false,"result" "unsafe","route" "all","to" "2017 10 13t23 59 59+0000"}]}} output parameter type description status code number http status code of the response reason string response reason phrase fail array output field fail fail file name string name of the resource fail file string output field fail file meta object output field meta meta status number status value meta pagination object output field meta pagination meta pagination pagesize number output field meta pagination pagesize meta pagination next string output field meta pagination next data array response data data attachmentlogs array response data data attachmentlogs result string response data data attachmentlogs date string response data data attachmentlogs senderaddress string response data data attachmentlogs filename string response data data attachmentlogs actiontriggered string response data data attachmentlogs route string response data data attachmentlogs details string response data data attachmentlogs recipientaddress string response data data attachmentlogs filetype string response data data attachmentlogs filehash string response data output example {"status code" 200,"response headers" {},"reason" "ok","json body" {"fail" \[],"meta" {"status" 200,"pagination" {}},"data" \[{}]}} create remediation incident initiate a new remediation incident in mimecast security using specified data parameters endpoint url /api/ttp/remediation/create method post input argument name type required description data array optional response data data reason string required the reason for the remediation incident data searchby string required the field to search by data hashormessageid string optional the hash or message id to search by data end string optional the end date and time of the remediation incident data url string optional the url to remediate data start string optional the start date and time of the remediation incident input example {"json body" {"data" \[{"reason" "remediate by url","searchby" "hash","hashormessageid" \["c6617708516e3"],"end" "2022 01 22t00 00 00+00 00","url" "https //www domain tld/path/to/unwanted/content","start" "2022 01 20t00 00 00+00 00"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data id string response data data code string response data data create string response data data failed number response data data fileremediationcanbecancelled boolean response data data fileremediationcancelled string response data data fileremediationexpirytime string response data data identified number response data data modified string response data data reason string response data data remediatedby string response data data removefromdevice string response data data restored number response data data searchcriteria object response data data searchcriteria end string response data data searchcriteria filehash string response data data searchcriteria from string response data data searchcriteria messageid string response data data searchcriteria restorecode string response data data searchcriteria start string response data data searchcriteria subject string response data data searchcriteria to string response data output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ get remediation incident retrieve detailed information about a specific remediation incident in mimecast security using the provided data endpoint url /api/ttp/remediation/get incident method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "incidentidstring"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data id string response data data code string response data data create string response data data failed number response data data identified number response data data modified string response data data reason string response data data restored number response data data searchcriteria object response data data searchcriteria end string response data data searchcriteria filehash string response data data searchcriteria from string response data data searchcriteria messageid string response data data searchcriteria messageids array response data data searchcriteria restorecode string response data data searchcriteria start string response data data searchcriteria to string response data data searchcriteria unremediatecode string response data data successful number response data data type string response data fail array output field fail fail errors array error message if any output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[ find incidents locate existing remediation incidents in mimecast security using optional search criteria requires a json body with data endpoint url /api/ttp/remediation/find incidents method post input argument name type required description data array optional response data data start string optional response data data searchby array optional response data data searchby fieldname string optional response data data searchby value string optional response data data end string optional response data data filterby array optional response data data filterby fieldname string optional response data data filterby value string optional response data input example {"json body" {"data" \[{"start" "2015 11 16t14 49 18+0000","searchby" \[{"fieldname" "string","value" "string"}],"end" "2015 11 16t14 49 18+0000","filterby" \[{"fieldname" "string","value" "string"}]}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data incidents array response data data incidents id string response data data incidents code string response data data incidents create string response data data incidents failed number response data data incidents identified number response data data incidents modified string response data data incidents reason string response data data incidents restored number response data data incidents searchcriteria object response data data incidents searchcriteria end string response data data incidents searchcriteria filehash string response data data incidents searchcriteria from string response data data incidents searchcriteria messageid string response data data incidents searchcriteria messageids array response data data incidents searchcriteria restorecode string response data data incidents searchcriteria start string response data data incidents searchcriteria to string response data data incidents searchcriteria unremediatecode string response data data incidents successful number response data data incidents type string response data fail array output field fail output example {"status code" 200,"response headers" {"date" "tue, 10 jun 2025 10 09 08 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "48b4c8e7 6150 45a4 bd51 a86d8d0372d0","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{},{}],"fail permit or block sender permit or block a specified sender in mimecast security using provided data endpoint url /api/managedsender/permit or block sender method post input argument name type required description data array optional response data data action string required response data data to string required response data data sender string required response data input example {"json body" {"data" \[{"action" "block","to" "admin\@mctest swimlane com","sender" "test\@test com"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data id string response data data sender string response data data to string response data data type string response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "thu, 13 oct 2022 18 33 04 gmt","content type" "application/json","content length" "370","connection" "keep alive","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","x ratelimit limit" "800","x ratelimit remaining" "799","x ratelimit reset" "5000"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fail" \[]}} message finder search execute a search for messages in mimecast security using specified criteria and return matching results requires a json body with data endpoint url /api/message finder/search method post input argument name type required description data array optional response data data advancedtrackandtraceoptions object optional response data data advancedtrackandtraceoptions from string optional the sending email address or domain of the messages to track data advancedtrackandtraceoptions senderip string optional the source ip address of messages to track data advancedtrackandtraceoptions subject string optional the subject of the messages to track data advancedtrackandtraceoptions to string optional the recipient email address or domain of the messages to track data advancedtrackandtraceoptions url string optional an url from the email content data attachments boolean optional if set to true then searches for emails with attachments data end string optional the date and time of the latest message to track, in the following format, 2011 12 03t10 15 30 +0000 data messageid string optional the internet message id of the message to track data route string optional an array of routes to filter by possible values are internal, outbound and inbound data searchreason string optional reason for tracking a email, used for activity tracking purposes data start string optional the date and time of the earliest message to track, in the following format, 2011 12 03t10 15 30 +0000 data status string optional an email status to filter by email status possible values {accepted, processing, bulk processing, delivery, bulk delivery, held, bounced, deferred, rejected and archived} input example {"json body" {"data" \[{"advancedtrackandtraceoptions" {"from" "","senderip" "","subject" "","to" "","url" ""},"attachments"\ true,"end" "2011 12 03t10 15 30+0000","messageid" "","route" "internal","searchreason" "","start" "2011 12 03t10 15 30+0000","status" "accepted"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data trackedemails array response data data trackedemails info string response data data trackedemails id string response data data trackedemails status string response data data trackedemails fromenv object response data data trackedemails fromenv emailaddress string response data data trackedemails fromhdr object response data data trackedemails fromhdr emailaddress string response data data trackedemails to array response data data trackedemails to displayablename string response data data trackedemails to emailaddress string response data data trackedemails received string response data data trackedemails subject string response data data trackedemails senderip string response data data trackedemails attachments boolean response data data trackedemails route string response data data trackedemails sent string response data data trackedemails spamscore number response data data trackedemails detectionlevel string response data fail array output field fail output example {"status code" 200,"response headers" {"date" "wed, 28 jan 2026 09 50 17 gmt","content type" "application/json","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","content encoding" "gzip","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "960adbb5 57d0 4f99 baef d8629ac05678","via" "1 1 google","transfer encoding" "chunked"},"reason" "ok","json body" {"meta" {"status" 200 get file download an email attachment from mimecast's message queue using specified data parameters endpoint url /api/gateway/message/get file method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "enpvkotv2jauxf vkv hw4 ysdldiqbqh7ah0llyhit8uiestxkhqaf973nktw5frot7js756f4kwjbda6knxke635 bqslwn4p54vijtx qzeh4o1ehmd0vyet0of3lp2zfnhzjwta9mdezzq0d ljovmxxr7lejkrdxfdwnvhrdoq5wdez3edtt1jdujhe7 e3590ppqyxg z8eaydjjgcknz1wgfjssvzyvba26od5fwvdbwrmig9mcbmkhlqzcvosjikrfcnq4uzugwsthzprdg86zmud0geyeqykogxgfhwh803k eu2rdqunavcoo hgarkom4ekmegofsawllmsbmidawplfu 6w2ymraihgoiyomoigasnxquhy ajww39p6tfxa8fyprf8rtdl8cnl8l5ijfkqme5tx6feit5b3my5ixsswcygizisybdc6aipwixddvreqe3dzvjp00mhvy 0 9jsf8xgqrvpukjdw5wz04fd21n dmr4grrtgxt7kc64o 9axfl8wfqwkaez17hrf8dpz37bhzihsld1f9pspueq6qg"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data urls array response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "wed, 11 jun 2025 17 32 48 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "53346ffa a419 4d9b 957c 33ac460010d9","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fai get message info retrieve detailed information about a specific message in mimecast using the provided data parameters endpoint url /api/message finder/get message info method post input argument name type required description data array optional response data data id string required response data input example {"json body" {"data" \[{"id" "enpvzl0lgjaybed smshzc1c0eukpfkhlaeqhb9v vgt3obi6l9nl10 53dog3hizqdvgezi1wjthucjx7z 4a9bo uzbazqcgmnjsj8bdukjun1ti sazylibspz3hoqr6yomhurhdl00tqvsvzhdgv3npmepbfsvtlxfo3wvzskyr1gtxbia2v9 l5w8auemwyhooaeg 2 yk5go6bx1apha9ahubgikyaexxdhoepqcllv 5aqapqs0"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data deliveredmessage object response data data deliveredmessage ullamco6 object response data data deliveredmessage ullamco6 messageinfo object response data data deliveredmessage ullamco6 messageinfo attachments array response data data deliveredmessage ullamco6 messageinfo cc array response data data deliveredmessage ullamco6 messageinfo contentexpiration string response data data deliveredmessage ullamco6 messageinfo fromenvelope string response data data deliveredmessage ullamco6 messageinfo fromheader string response data data deliveredmessage ullamco6 messageinfo htmlbody string response data data deliveredmessage ullamco6 messageinfo metadataexpiration string response data data deliveredmessage ullamco6 messageinfo processed string response data data deliveredmessage ullamco6 messageinfo route string response data data deliveredmessage ullamco6 messageinfo sent string response data data deliveredmessage ullamco6 messageinfo subject string response data data deliveredmessage ullamco6 messageinfo textbody string response data data deliveredmessage ullamco6 messageinfo to array response data data deliveredmessage ullamco6 messageinfo transmissioninfo string response data data deliveredmessage ullamco6 policyinfo array response data data deliveredmessage ullamco6 policyinfo policytype string response data data deliveredmessage ullamco6 policyinfo policyname string response data data deliveredmessage ullamco6 policyinfo inherited string response data data deliveredmessage ullamco6 deliverymetainfo object response data output example {"data" \[{"deliveredmessage" {},"id" "12345678 1234 1234 1234 123456789abc","recipientinfo" {},"retentioninfo" {},"spaminfo" {},"status" "active"}],"fail" \[{"file name" "example name","file" "string"}]} policy update update an existing address alteration policy in mimecast security using specified data parameters endpoint url /api/policy/address alteration/update policy method post input argument name type required description data array optional response data data id string optional response data data addressalterationsetid string optional response data data policy object optional response data data policy bidirectional boolean optional response data data policy comment string optional response data data policy conditions object optional response data data policy conditions sourceips array optional response data data policy description string optional response data data policy enabled boolean optional response data data policy enforced boolean optional response data data policy from object optional response data data policy from attribute object optional response data data policy from attribute id string optional response data data policy from attribute name string optional response data data policy from attribute value string optional response data data policy from emailaddress string optional response data data policy from emaildomain string optional response data data policy from groupid string optional response data data policy from type string optional response data data policy fromdate string optional response data data policy frometernal boolean optional response data data policy frompart string optional response data data policy override boolean optional response data data policy to object optional response data input example {"json body" {"data" \[{"id" "enpfjkulwjayrf9ltlpi0jzvd07vojpgpqncn6gkn0mwd8mjo4j faigs7mbc8 l3pef4q3obi0qezf57wptn1w1r3briwppvh7nntu t9qiv2w1wewfjo1xezhd3yc km1 rx8v ptzdk1rb9bwekpxo29 bhcis7urso qbcy8dumhrgznk t7ckmyzzroahvbwd30aegmb x1snirafcwe04zwscmzeqs i9zimmkwsgkoefadememysinccsy emy t4a6feswu","addressalterationsetid" "enpfjkulwjayrf9ltlpi0jzvd07vojpgpqncn6gkn0mwd8mjo4j faigs7mbc8 l3pef4q3obi0qezf57wptn1w1r3briwppvh7nntu t9qiv2w1wewfjo1xezhd3yc km1 rx8v ptzdk1rb9bwekpxo29 bhcis7urso qbcy8dumhrgznk t7ckmyzzroahvbwd30aegmb x1snirafcwe04zwscmzeqs i9zimmkwsgkoefadememysinccsy emy t4a6feswu","policy" {"bidirectional"\ true,"comment" "this is a test comment","conditions" {"sourceips" \["192 168 1 1","192 168 1 2"]},"description" "this is a test description","enabled"\ true,"enforced"\ true,"from" {"attribute" {"id" "1234567890","name" "this is a test name","value" "this is a test value"},"emailaddress" "test\@example com","emaildomain" "example com","groupid" "1234567890","type" "profile group"},"fromdate" "2021 01 01","frometernal"\ true,"frompart" "both","override"\ true,"to" {"attribute" {"id" "1234567890","name" "this is a test name","value" "this is a test value"},"emailaddress" "test\@example com","emaildomain" "example com","groupid" "1234567890","type" "internal addresses"},"todate" "2021 01 01","toeternal"\ true}}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data addressalterationsetid string response data data id string response data data policy object response data data policy bidirectional boolean response data data policy conditions object response data data policy conditions sourceips array response data data policy createtime string response data data policy description string response data data policy enabled boolean response data data policy enforced boolean response data data policy from object response data data policy from attribute object response data data policy from attribute id string response data data policy from attribute name string response data data policy from attribute value string response data data policy from emailaddress string response data data policy from emaildomain string response data data policy from group object response data data policy from group description string response data data policy from group foldercount number response data data policy from group id string response data data policy from group parentid string response data output example {"status code" 200,"response headers" {"date" "tue, 17 jun 2025 05 48 58 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "ad48d523 1983 492a 91d4 c2e1eb97cbac","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[]}} create block sender policy establish new blocked sender policies in mimecast security, managing sender and recipient restrictions with specified data endpoint url /api/policy/blockedsenders/create policy method post input argument name type required description data array optional response data data option string optional response data data policy object optional response data data policy bidirectional boolean optional response data data policy comment string optional response data data policy conditions object optional response data data policy conditions sourceips array optional response data data policy description string optional response data data policy enabled boolean optional response data data policy enforced boolean optional response data data policy from object optional response data data policy from attribute object optional response data data policy from attribute id string optional response data data policy from attribute name string optional response data data policy from attribute value string optional response data data policy from emailaddress string optional response data data policy from emaildomain string optional response data data policy from groupid string optional response data data policy from headerdisplayname string optional response data data policy from type string optional response data data policy fromdate string optional response data data policy frometernal boolean optional response data data policy frompart string optional response data data policy override boolean optional response data data policy to object optional response data input example {"json body" {"data" \[{"option" "no action","policy" {"bidirectional"\ true,"comment" "this is a test comment","conditions" {"sourceips" \["192 168 1 1","192 168 1 2"]},"description" "this is a test description","enabled"\ true,"enforced"\ true,"from" {"attribute" {"id" "1234567890","name" "this is a test name","value" "this is a test value"},"emailaddress" "test\@example com","emaildomain" "example com","groupid" "1234567890","headerdisplayname" "this is a test header display name","type" "email domain"},"fromdate" "2021 01 01","frometernal"\ true,"frompart" "envelope from","override"\ true,"to" {"attribute" {"id" "1234567890","name" "this is a test name","value" "this is a test value"},"emailaddress" "test\@example com","emaildomain" "example com","groupid" "1234567890","headerdisplayname" "this is a test header display name","type" "everyone"},"todate" "2021 01 01","toeternal"\ true}}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data id string response data data option string response data data policy object response data data policy bidirectional boolean response data data policy comment string response data data policy conditions object response data data policy conditions sourceips array response data data policy createtime string response data data policy description string response data data policy enabled boolean response data data policy enforced boolean response data data policy from object response data data policy from attribute object response data data policy from attribute id string response data data policy from attribute name string response data data policy from attribute value string response data data policy from device object response data data policy from device description string response data data policy from device foldercount number response data data policy from device folders array response data data policy from device id string response data data policy from device parentid string response data output example {"status code" 200,"response headers" {"date" "tue, 17 jun 2025 05 48 58 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "ad48d523 1983 492a 91d4 c2e1eb97cbac","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[]}} create managed url add a specified url to mimecast's managed list for targeted threat protection using provided data parameters endpoint url /api/ttp/url/create managed url method post input argument name type required description data array optional response data data matchtype string optional response data data disablerewrite boolean optional response data data action string required response data data comment string optional response data data disableuserawareness boolean optional response data data url string required response data data disablelogclick boolean optional response data input example {"json body" {"data" \[{"matchtype" "explicit","disablerewrite"\ false,"action" "block","comment" "this is a comment","disableuserawareness"\ false,"url" "https //example com","disablelogclick"\ false}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data action object response data data action name string response data data action ordinal number response data data action whitelist boolean response data data comment string response data data disablelogclick boolean response data data disablerewrite boolean response data data disableuserawareness boolean response data data domain string response data data id string response data data matchtype object response data data matchtype matchtype object response data data matchtype matchtype id number response data data matchtype matchtype name string response data data matchtype matchtype ordinal number response data data matchtype name string response data data matchtype ordinal number response data data path string response data data port number response data data querystring string response data data scheme string response data fail array output field fail output example {"status code" 200,"response headers" {"date" "tue, 17 jun 2025 05 48 58 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "ad48d523 1983 492a 91d4 c2e1eb97cbac","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[]}} decode url decode mimecast's threat protection urls to their original form using the 'data' parameter for input endpoint url /api/ttp/url/decode url method post input argument name type required description data array optional response data data url string required response data input example {"json body" {"data" \[{"url" "example com"}]}} output parameter type description status code number http status code of the response reason string response reason phrase meta object output field meta meta status number status value data array response data data url string response data data success boolean response data fail array output field fail fail file name string name of the resource fail file string output field fail file output example {"status code" 200,"response headers" {"date" "mon, 10 oct 2022 18 22 06 gmt","content type" "application/json","content length" "79","connection" "keep alive","cache control" "no store","pragma" "no cache","x robots tag" "noindex, nofollow","x ratelimit limit" "800","x ratelimit remaining" "799","x ratelimit reset" "5000"},"reason" "ok","json body" {"meta" {"status" 200},"data" \[{}],"fail" \[]}} get managed urls retrieve all managed urls or domains from mimecast security using the specified 'data' query parameter endpoint url /api/ttp/url/get all managed urls method post input argument name type required description data array optional response data data domainorcomment string optional response data data domainorurl string required response data data exactmatch boolean optional response data data filterby array optional response data data filterby fieldname string optional response data data filterby value string optional response data data sortbyurl boolean optional response data data sortorder string optional response data input example {"json body" {"data" \[{"domainorcomment" "this is a test comment","domainorurl" "example com","exactmatch"\ true,"filterby" \[{"fieldname" "this is a test field name","value" "this is a test value"},{"fieldname" "this is a test field name","value" "this is a test value"}],"sortbyurl"\ true,"sortorder" "asc"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data action object response data data action name string response data data action ordinal number response data data action whitelist boolean response data data comment string response data data disablelogclick boolean response data data disablerewrite boolean response data data disableuserawareness boolean response data data domain string response data data id string response data data matchtype object response data data matchtype matchtype object response data data matchtype matchtype id number response data data matchtype matchtype name string response data data matchtype matchtype ordinal number response data data matchtype name string response data data matchtype ordinal number response data data path string response data data port number response data data querystring string response data data scheme string response data fail array output field fail output example {"status code" 200,"response headers" {"date" "tue, 17 jun 2025 05 48 58 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "ad48d523 1983 492a 91d4 c2e1eb97cbac","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[]}} get ttp url logs fetch log data for urls processed by mimecast's targeted threat protection service using the 'data' parameter endpoint url /api/ttp/url/get logs method post input argument name type required description data array optional response data data oldestfirst boolean optional response data data from string optional response data data route string optional response data data to string optional response data data scanresult string optional response data input example {"json body" {"data" \[{"oldestfirst"\ false,"from" "2016 10 01t14 49 18+0000","route" "all","to" "2017 10 13t23 59 59+0000","scanresult" "all"}]}} output parameter type description status code number http status code of the response reason string response reason phrase data array response data data clicklogs array response data data clicklogs action string response data data clicklogs actions string response data data clicklogs adminoverride string response data data clicklogs advancedphishingresult object response data data clicklogs category string response data data clicklogs creationmethod string response data data clicklogs date string response data data clicklogs emailpartsdescription array response data data clicklogs fromuseremailaddress string response data data clicklogs heuristicdomainsource string response data data clicklogs messageid string response data data clicklogs route string response data data clicklogs scanresult string response data data clicklogs sendingip string response data data clicklogs similardomain string response data data clicklogs subject string response data data clicklogs tagmap object response data data clicklogs ttpdefinition string response data data clicklogs url string response data data clicklogs userawarenessaction string response data data clicklogs useremailaddress string response data output example {"status code" 200,"response headers" {"date" "tue, 17 jun 2025 05 48 58 gmt","content type" "application/json","cache control" "no store","strict transport security" "max age=31536000; includesubdomains","x frame options" "sameorigin","referrer policy" "same origin","x request id" "ad48d523 1983 492a 91d4 c2e1eb97cbac","via" "1 1 google","alt svc" "h3=\\" 443\\"; ma=2592000,h3 29=\\" 443\\"; ma=2592000","transfer encoding" "chunked"},"reason" "ok","json body" {"data" \[{}],"fail" \[]}} get ttp impersonation protect logs retrieve logs of impersonation attempts from mimecast security using specified data parameters endpoint url /api/ttp/impersonation/get logs method post input argument name type required description data array optional response data data actions array optional response data data from string optional response data data identifiers array optional response data data oldestfirst boolean optional response data data query string optional response data data searchfield string optional response data data taggedmalicious boolean optional response data data to string optional response data input example {"json body" {"data" \[{"actions" \["hold","bounce"],"from" "2022 10 13t16 57 02+0000","identifiers" \["newly observed domain","internal user name"],"oldestfirst"\ true,"query" "this is a test query","searchfield" "subject","taggedmalicious"\ true,"to" "2022 10 13t16 57 02+0000"}]}} output parameter type description status code number http status code of the response reason string response reason phrase output example {"status code" 200,"response headers" {},"reason" "ok","json body" {}} response headers header description example alt svc http response header alt svc h3=" 443 "; ma=2592000,h3 29=" 443 "; ma=2592000 cache control directives for caching mechanisms no store connection http response header connection keep alive content encoding http response header content encoding gzip content length the length of the response body in bytes 317 content type the media type of the resource application/json date the date and time at which the message was originated mon, 24 oct 2022 21 18 56 gmt pragma http response header pragma no cache referrer policy http response header referrer policy same origin strict transport security http response header strict transport security max age=31536000; includesubdomains transfer encoding http response header transfer encoding chunked via http response header via 1 1 google x frame options http response header x frame options sameorigin x ratelimit limit the number of requests allowed in the current rate limit window 800 x ratelimit remaining the number of requests remaining in the current rate limit window 799 x ratelimit reset the time at which the current rate limit window resets 5000 x request id a unique identifier for the request 53346ffa a419 4d9b 957c 33ac460010d9 x robots tag http response header x robots tag noindex, nofollow