The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Bulk release quarantined email request

Prev Next

Bulk releases email files present in the quarantine for the given Email Security — Cloud message IDs.

POST https://<etp_instance_addr>/api/v1/quarantine/release/

Required headers:

x-fireeye-api-key: <key>—Specifies your personal API key.

Content-Type: “application/json”—Content-type of the request body.

Request body:

{
  "is_not_spam": Boolean,
  "headers_only": Boolean,
  "message_ids": ["ID1", "ID2"]
}

Options

  • is_not_spam—(Boolean) Report as not spam. Default: true.

  • headers_only—(Boolean) Share only the email headers with Spam Engines. Default: false. Default: false. If is_not_spam is set to false then headers_only is set to false.

  • message_IDs—(array of strings) The message IDs corresponding to the message_id field in the individual documents of Quarantine Summary API.

  • traffic_type—(outbound or inbound) Traffic type defaults to inbound. To handle outbound traffic, set the traffic_type parameter to outbound.

Example request body of inbound request

Values for ID and other fields are for illustration purposes only.

{
  "is_not_spam": true,
  "headers_only": true,
  "message_ids": ["6B6C557623E5BACB5ed800713", "6B6C557623E5BACB5ed800714"]
}

Bulk release quarantined inbound email response

Success:

{
  "data": {
    "type": "quarantine",
    "operation": "release",
    "successful_message_ids": [
      "6B6C557623E5BACB5ed800713",
      "6B6C557623E5BACB5ed800714"
    ],
    "failed_message_ids": []
  },
  "meta": {
    "copyright": "Copyright 2019 Fireeye Inc"
  }
}

Error:

{
  "data": {
    "type": "quarantine",
    "operation": "release",
    "successful_message_ids": [
      "6B6C557623E5BACB5ed800713"
    ],
    "failed_message_ids": [
      "6B6C557623E5BACB5ed800714"
    ]
  },
  "meta": {
    "copyright": "Copyright 2019 Fireeye Inc"
  }
}

Note

After a successful release submission, the release is queued. Use the Email Trace APIs to see the actual release result.

Example request body of outbound alerts

{
    "traffic_type":"outbound",
    "message_ids": ["1200174769D96A1065c72ece1", "A65003672D6953EF53100484e"]
}'

Bulk release quarantined outbound email response

{
    "data": {
        "type": "quarantine",
        "operation": "release",
        "successful_message_ids": [
            "1200174769D96A1065c72ece1",
            "A65003672D6953EF53100484e"
        ],
        "failed_message_ids": []
    },
    "meta": {
        "copyright": "Copyright 2019 Fireeye Inc"
    }
}

cURL code example: bulk release quarantined email

curl -X POST -H "Content-Type: application/json" -H "x-fireeye-api-key: xxxxxxxxxxxxxxxx" https://etp.us.fireeye.com/api/v1/quarantine/release/ -d '{
  "is_not_spam": true,
  "headers_only": true,
  "message_ids": ["6B6C557623E5BACB5ed800713", "6B6C557623E5BACB5ed800714"]
}'

This cURL sample includes the following options:

  • -X POST—This option changes the HTTP method to POST.

  • -H "Content-Type: application/json"—This header specifies that the request body is sent to the server in JSON format.

  • -H 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key.

  • https://etp.us.fireeye.com/v1/quarantine/release/—The quarantine request URL. Replace etp.us.fireeye.com with the address of your Email Security — Cloud instance.

  • -d '{ "is_not_spam": true, "headers_only": true, "message_ids": ["6B6C557623E5BACB5ed800713", "6B6C557623E5BACB5ed800714"] }'—Specifies the request parameters.