How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Malwarebytes Email Protection API

The Email Protection API from Malwarebytes — 79 operation(s) for email protection.

Malwarebytes Email Protection API is one of 52 APIs that Malwarebytes publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Email Protection. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 101 operations across 79 paths. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against a single base URL, https://api.threatdown.com.

101 operations 79 paths 0 schemas 12 DELETE20 GET59 POST10 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://api.threatdown.com
Authentication
OAuth 2.0, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Malwarebytes Email Protection API declares 2 security schemes for authenticating requests. It supports OAuth 2.0 (client_credentials) using the clientCredentials flow, exposing 3 scopes. It accepts HTTP bearer tokens (user_permissions).

Paths & Operations 101

Across 79 paths, the API surfaces 101 operations — 12 DELETE, 20 GET, 59 POST, 10 PUT. Each is listed below with its method, path, parameters, and response codes.

Email Protection 101
PUT
/nebula/v1/email-protection/integrations/domains
Add domains
api.mailware.put.email-protection.integrations.domains 2 params body → 200
DELETE
/nebula/v1/email-protection/integrations/domains
Delete domains
api.mailware.delete.email-protection.integrations.domains 2 params body → 200
GET
/nebula/v1/email-protection/integrations/domains
Get domains
api.mailware.get.email-protection.integrations.domains 2 params → 200
DELETE
/nebula/v1/email-protection/account/911-mailbox
Delete 911 mailbox
api.mailware.delete.email-protection.account.911-mailbox 2 params → 200
GET
/nebula/v1/email-protection/account/911-mailbox
Get 911 mailbox
api.mailware.get.email-protection.account.911-mailbox 2 params → 200
PUT
/nebula/v1/email-protection/account/911-mailbox
Edit 911 mailbox
api.mailware.put.email-protection.account.911-mailbox 2 params body → 200
DELETE
/nebula/v1/email-protection/account/disable
Delete account
api.mailware.delete.account 2 params → 200
DELETE
/nebula/v1/email-protection/account/auto-sync
Disable auto-sync
api.mailware.delete.email-proteciton.account.auto-sync 2 params → 200
GET
/nebula/v1/email-protection/account/auto-sync
Get auto-sync status
api.mailware.get.email-protection.account.auto-sync 2 params → 200
POST
/nebula/v1/email-protection/account/auto-sync
Enable auto-sync
api.mailware.post.email-protection.account.auto-sync 2 params body → 200
DELETE
/nebula/v1/email-protection/configurations/allow-list
Delete allow list entry
api.mailware.delete.email-protection.configurations.allow-list 2 params body → 200
POST
/nebula/v1/email-protection/configurations/allow-list
Create allow list entry
api.mailware.post.email-protection.configurations.allow-list 2 params body → 200
PUT
/nebula/v1/email-protection/configurations/allow-list
Update allow list
api.mailware.put.email-protection.configurations.allow-list 2 params body → 200
DELETE
/nebula/v1/email-protection/integrations/disable
Disable Integration
api.mailware.post.integrations.disable 2 params → 200
GET
/nebula/v1/email-protection/account/details
Get account details
api.mailware.get.account.details 2 params → 200
GET
/nebula/v1/email-protection/account/settings
Get account settings
api.mailware.get.email-protection.account.settings 2 params → 200
PUT
/nebula/v1/email-protection/account/settings
Edit account settings
api.mailware.put.email-protection.account.settings 2 params body → 200
GET
/nebula/v1/email-protection/account/stats
Get statistics
api.mailware.get.stats 3 params → 200
POST
/nebula/v1/email-protection/configurations/allow-list/search
Get allow list
api.mailware.post.email-protection.configurations.allow-list-search 2 params body → 200
GET
/nebula/v1/email-protection/stats/domains
Get email protection domains statistics
api.mailware.get.email-protection.stats.domains 2 params → 200
GET
/nebula/v1/email-protection/incidents/{incident_id}
Get incident details
api.mailware.get.incident_details 3 params → 200
GET
/nebula/v1/email-protection/integrations/status
Get Integration Status status
api.mailware.get.integrations.status 2 params → 200
GET
/nebula/v1/email-protection/configurations/notifications/recipients
Get notification recipients
api.mailware.get.configurations.notifications.recipients 2 params → 200
POST
/nebula/v1/email-protection/configurations/notifications/recipients
Create notification recipients
api.mailware.post.configurations.notifications.recipients 2 params body → 200
POST
/nebula/v1/email-protection/account/register
Register account
api.mailware.post.account.register 2 params body → 200
POST
/nebula/v1/email-protection/integrations/domains/check
Check Domain
api.mailware.post.email-protection.integrations.domains.check 2 params body → 200
POST
/nebula/v1/email-protection/incidents/{incident_id}/classify
Classify Incident
api.mailware.post.incidents.classify 3 params body → 200
POST
/nebula/v1/email-protection/account/daily-usage
Get daily usage
api.mailware.post.account.daily-usage 2 params body → 200
POST
/nebula/v1/email-protection/stats/emails
Get email statistics
api.mailware.post.email-protection.stats.emails 2 params body → 200
POST
/nebula/v1/email-protection/incidents/export
Export incidents
api.mailware.post.incidents.export 2 params body → 200
POST
/nebula/v1/email-protection/mailboxes/export
Export mailboxes
api.mailware.post.mailboxes.export 2 params body → 200
POST
/nebula/v1/email-protection/incidents/scanback/export
Export Scanback incidents
api.mailware.post.incidents.scanback.export 2 params body → 200
POST
/nebula/v1/email-protection/integrations/o365/phishing-button-manifest
Get Phishing Button Manifest
api.mailware.post.integrations.o365.phishing-button-manifest 2 params body → 200
POST
/nebula/v1/email-protection/integrations/gw/admin-consent-url
Get GW Admin Consent URL
api.mailware.post.email-protection.integrations.gw.admin-consent-url 2 params → 200
POST
/nebula/v1/email-protection/integrations/gw/authorize
Authorize GW Integration
api.mailware.post.email-protection.integrations.gw.authorize 2 params → 200
POST
/nebula/v1/email-protection/stats/incidents
Get incident statistics
api.mailware.post.email-protection.stats.incidents 2 params body → 200
POST
/nebula/v1/email-protection/account/monthly-usage
Get monthly usage
api.mailware.post.account.monthly-usage 2 params body → 200
POST
/nebula/v1/email-protection/stats/most-targeted-departments
Get most targeted departments
api.mailware.post.email-proteciton.stats.most-targeted-departments 2 params body → 200
POST
/nebula/v1/email-protection/stats/most-targeted-users
Get most targeted users
api.mailware.post.email-protection.stats.most-targeted-users 2 params body → 200
POST
/nebula/v1/email-protection/integrations/o365/admin-consent-url
Get Admin Consent URL
api.mailware.post.email-protection.integrations.o365.admin-consent-url 2 params body → 200
POST
/nebula/v1/email-protection/integrations/o365/authorize
Authorize O365
api.mailware.post.email-protection.integrations.o365.authorize 2 params body → 200
POST
/nebula/v1/email-protection/incidents/scanback
Search Scanback incidents
api.mailware.post.email-proteciton.incidents.scanback 2 params body → 200
POST
/nebula/v1/email-protection/account/auto-sync/groups
Search auto-sync groups
api.mailware.post.email-protection.account.auto-sync.groups 2 params body → 200
POST
/nebula/v1/email-protection/emails
Search emails
api.mailware.post.email-protection.emails.search 2 params body → 200
POST
/nebula/v1/email-protection/incidents
Search incidents
api.mailware.post.incidents 2 params body → 200
POST
/nebula/v1/email-protection/mailboxes
Search Mailboxes
api.mailware.post.mailboxes 2 params body → 200
PUT
/nebula/v1/email-protection/mailboxes
Edit mailboxes
api.mailware.put.email-protection.mailboxes.edit 2 params body → 200
POST
/nebula/v1/email-protection/incidents/{incident_id}/uncluster
Uncluster incident emails
api.mailware.post.incidents.uncluster 3 params body → 200
PUT
/oneview/v1/accounts/{account_id}/email-protection/integrations/domains
Add domains
api.rmm.put.email-protection.integrations.domains 1 param body → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/integrations/domains
Delete domains
api.rmm.delete.email-protection.integrations.domains 1 param body → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/integrations/domains
Get domains
api.rmm.get.email-protection.integrations.domains 1 param → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/account/911-mailbox
Delete 911 mailbox
api.rmm.delete.email-protection.account.911-mailbox 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/account/911-mailbox
Get 911 mailbox
api.rmm.get.email-protection.account.911-mailbox 1 param → 200
PUT
/oneview/v1/accounts/{account_id}/email-protection/account/911-mailbox
Edit 911 mailbox
api.rmm.put.email-protection.account.911-mailbox 1 param body → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/disable
Disable email protection account
api.rmm.delete.email-protection.disable 1 param → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/auto-sync
Disable account auto-sync
api.rmm.delete.email-proteciton.account.auto-sync 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/auto-sync
Get account auto-sync status
api.rmm.get.email-protection.account.auto-sync 1 param → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/auto-sync
Enable account auto-sync
api.rmm.post.email-protection.account.auto-sync 1 param body → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/configurations/allow-list
Delete allow list entry
api.rmm.delete.email-protection.configurations.allow-list 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/configurations/allow-list
Create allow list entry
api.rmm.post.email-protection.configurations.allow-list 1 param body → 200
PUT
/oneview/v1/accounts/{account_id}/email-protection/configurations/allow-list
Update allow list
api.rmm.put.email-protection.configurations.allow-list 1 param body → 200
DELETE
/oneview/v1/accounts/{account_id}/email-protection/integrations/disable
Disable the integration
api.rmm.delete.email-protection.integrations.disable 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/details
Get account details
api.rmm.get.email-protection.account.details 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/account/settings
Get account settings
api.rmm.get.email-protection.account.settings 1 param → 200
PUT
/oneview/v1/accounts/{account_id}/email-protection/account/settings
Edit account settings
api.rmm.put.email-protection.account.settings 1 param body → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/stats
Get statistics
api.rmm.get.email-protection.stats 2 params → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/configurations/allow-list/search
Get allow list
api.rmm.post.email-protection.configurations.allow-list-search 1 param body → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/stats/domains
Get email protection domains statistics
api.rmm.get.email-protection.stats.domains 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/incidents/{incident_id}
Get incident details
api.rmm.get.email-protection.incidents.details 2 params → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/integrations/status
Get Integration status
api.rmm.get.email-proteciton.integrations.status 1 param → 200
GET
/oneview/v1/accounts/{account_id}/email-protection/configurations/notifications/recipients
Get notification recipients
api.rmm.get.configurations.notifications.recipients 1 param → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/configurations/notifications/recipients
Create notification recipients
api.rmm.post.configurations.notifications.recipients 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/o365/authorize
Authorize O365
api.rmm.post.email-protection.integrations.o365.authorize 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/register
Register email protection account
api.rmm.post.email-protection.register 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/domains/check
Check Domain
api.rmm.post.email-protection.integrations.domains.check 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents/{incident_id}/classify
Classify an Incident
api.rmm.post.email-protection.incidents.classify 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/account/daily-usage
Get daily usage
api.rmm.post.email-protection.account.daily-usage 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/stats/emails
Get email statistics
api.rmm.post.email-protection.stats.emails 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents/export
Export incidents
api.rmm.post.email-protection.incidents.export 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/mailboxes/export
Export mailboxes
api.rmm.post.email-protection.mailboxes.export 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents/scanback/export
Export Scanback incidents
api.rmm.post.email-protection.incidents.scanback.export 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/o365/phishing-button-manifest
Get phishing button manifest
api.rmm.post.email-protection.integrations.o365.phishing-button-manifest 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/gw/admin-consent-url
Get GW Admin Consent URL
api.rmm.post.email-protection.integrations.gw.admin-consent-url 1 param → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/gw/authorize
Authorize GW Integration
api.rmm.post.email-protection.integrations.gw.authorize 1 param → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/stats/incidents
Get incident statistics
api.rmm.post.email-protection.stats.incidents 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/migrate
Migrate Email Protection
api.rmm.post.email-protection.migrate 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/migration-eligibility
Migration Eligibility
api.rmm.post.email-protection.migration-eligibility 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/account/monthly-usage
Get monthly usage
api.rmm.email-protection.post.account.monthly-usage 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/stats/most-targeted-departments
Get most targeted departments
api.rmm.post.email-proteciton.stats.most-targeted-departments 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/stats/most-targeted-users
Get most targeted users
api.rmm.post.email-protection.stats.most-targeted-users 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/integrations/o365/admin-consent-url
Get admin consent URL
api.rmm.post.email-protection.integrations.o365.admin-consent-url 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/register-msp
Register email protection MSP account
api.rmm.post.email-protection.register-msp 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents/scanback
Search Scanback incidents
api.rmm.post.email-proteciton.incidents.scanback 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/auto-sync/groups
Search auto-sync groups
api.rmm.post.email-protection.account.auto-sync.groups 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/emails
Search emails
api.rmm.post.email-protection.emails.search 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents
Search incidents
api.rmm.post.email-protection.incidents 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/mailboxes
Search Mailboxes
api.rmm.post.email-protection.mailboxes 2 params body → 200
PUT
/oneview/v1/accounts/{account_id}/email-protection/mailboxes
Edit mailboxes
api.rmm.put.email-protection.mailboxes.edit 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/site/integration/status
Get site integration status
api.rmm.post.email-protection.site.integration.status 1 param body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/incidents/{incident_id}/uncluster
Uncluster incident emails
api.rmm.post.email-protection.incidents.uncluster 2 params body → 200
POST
/oneview/v1/accounts/{account_id}/email-protection/register-msp-site
Register email protection MSP site account
api.rmm.post.email-protection.register-msp-site 1 param body → 200

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

malwarebytes-email-protection-api-openapi.yml Raw ↑

Other APIs Malwarebytes publishes across the network.

Malwarebytes Account API
Malwarebytes AI Detection & Response API
Malwarebytes App Block API
Malwarebytes Assets API
Malwarebytes Authentication API
Malwarebytes Case Management API
Malwarebytes Content Filtering API
Malwarebytes Copilot API
Malwarebytes Detections API
Malwarebytes Device Control API
Malwarebytes DNS API
Malwarebytes DNS Logs API
Where this information came from

This is an independent, third-party profile of Malwarebytes Email Protection API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.