The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Release quarantined email request

Prev Next

Releases the email file present in the quarantine for the given Email Security — Cloud message ID.

POST https://<etp_instance_addr>/api/v1/quarantine/release/<id>

Required headers:

x-fireeye-api-key: <key>—Specifies your personal API key.

Content-Type: “application/json”—Content-type of the request body.

Options

  • id—(string) The message ID logged when an email is delivered from the Email Security — Cloud stack.

  • is_not_spam—(Boolean) Report as not spam. Default: true.

  • headers_only—(Boolean) Share only the email headers with Spam Engines. Default: false. Default: false. If is_not_spam is set to false then headers_only is set to false.

  • traffic_type—(outbound or inbound) Traffic type defaults to inbound. To handle outbound traffic, set the traffic_type parameter to outbound.

Example of inbound request

Values for ID and other fields are for illustration purposes only.

POST https://etp.us.fireeye.com/api/v1/quarantine/release/6B6C557623E5BACB5ed800712

Release quarantined email inbound response

If email exists in quarantine:

{
    "data": {
        "type": "quarantine",
        "operation": "release",
        "successful_message_ids": [
            "6B6C557623E5BACB5ed800712"
        ],
        "failed_message_ids": []
    },
    "meta": {
        "copyright": "Copyright 2019 Fireeye Inc"
    }
}

If email does not exist in quarantine:

{
  "message": "Invalid etp message ID or the message ID does not exist in quarantine"
}

Example of outbound request

Values for ID and other fields are for illustration purposes only.

POST https://etp.us.fireeye.com/api/v1/quarantine/release/1200174769D96A1065c72ece1 -H 'x-fireeye-api-key: <APIKEY>' -d '{"traffic_type":"outbound"}'

Release quarantined email outbound response

If email exists in quarantine:

{
    "data": {
        "type": "quarantine",
        "operation": "release",
        "successful_message_ids": [
            "1200174769D96A1065c72ece1"
        ],
        "failed_message_ids": []
    },
    "meta": {
        "copyright": "Copyright 2019 Fireeye Inc"
    }
}

cURL code example: release quarantined email

curl -X POST -H "Content-Type: application/json" -H "x-fireeye-api-key: xxxxxxxxxxxxxxxx" https://etp.us.fireeye.com/api/v1/quarantine/release/6B6C557623E5BACB5ed800712 -d '{"is_not_spam":true, "headers_only":true}'

This cURL sample includes the following options:

  • -X POST—This option changes the HTTP method to POST.

  • -H "Content-Type: application/json"—This header specifies that the request body is sent to the server in JSON format.

  • -H 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key.

  • https://etp.us.fireeye.com/v1/quarantine/release/6B6C557623E5BACB5ed800712—The quarantine request URL. Replace etp.us.fireeye.com with the address of your Email Security — Cloud instance, and 6B6C557623E5BACB5ed800712with your message ID.

  • -d '{"is_not_spam":true, "headers_only":true}'—Reports the email as not spam and specifies whether to send only email headers to Spam Engines.