# Notification Email List

GET /platform/notification-emails: Lists notification emails that were sent, with the rule that triggered them.

Source: https://docs.deepinfo.com/reference/platform/notification-email-list/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/platform/notification-emails`

Lists notification emails that were sent, with the rule that triggered them.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `ordering` | Optional |  |  |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |
| `rule__id` | Optional |  |  |
| `rule__name__icontains` | Optional |  |  |
| `rule__scope` | Optional | One of: `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added`. |  |
| `rule__frequency` | Optional | One of: `instant`, `hourly`, `daily`, `weekly`, `monthly`. |  |
| `sent_at__gte` | Optional |  |  |
| `sent_at__lte` | Optional |  |  |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].rule` | object |  |
| `results[].sent_at` | string | date-time |
| `results[].recipients` | array of object |  |
| `results[].context` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].rule` | object |
| `results[].rule.id` | string |
| `results[].rule.name` | string |
| `results[].rule.scope` | string |
| `results[].rule.frequency` | string |
| `results[].sent_at` | string |
| `results[].recipients` | array<object> |
| `results[].recipients[].email` | string |
| `results[].recipients[].full_name` | string |
| `results[].context` | object |
| `results[].context.event_date` | string |
| `results[].context.event_date_humanized` | string |
| `results[].context.id` | string |
| `results[].context.asset` | object |
| `results[].context.asset.id` | string |
| `results[].context.asset.name` | string |
| `results[].context.asset.name_unicode` | string |
| `results[].context.asset.tags` | array |
| `results[].context.severity` | string |
| `results[].context.last_seen_date` | string |
| `results[].context.last_seen_date_humanized` | string |
| `results[].context.type` | object |
| `results[].context.type.id` | string |
| `results[].context.type.name` | string |
| `results[].context.type.description` | string |
| `results[].context.type.category` | object |
| `results[].context.type.category.id` | string |
| `results[].context.type.category.name` | string |
| `results[].context.first_seen_date` | string |
| `results[].context.first_seen_date_humanized` | string |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/platform/notification-emails?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "00000000000000000000000ea8430001",
      "rule": {
        "id": "000000000000000e8e040001",
        "name": "Critical issues",
        "scope": "reappeared_issue_detected",
        "frequency": "instant"
      },
      "sent_at": "2025-07-31T08:00:00Z",
      "recipients": [
        {
          "email": "user@acme.example",
          "full_name": "Jane Doe"
        }
      ],
      "context": {
        "event_date": "2025-07-31T08:00:00.000000+00:00",
        "event_date_humanized": "3 months ago",
        "id": "000000000000000e59ba0001",
        "asset": {
          "id": "000000000000000ea4f90001",
          "name": "acme.example",
          "name_unicode": "acme.example",
          "tags": []
        },
        "severity": "High",
        "last_seen_date": "2025-07-31T08:00:00.000000+00:00",
        "last_seen_date_humanized": "3 months ago",
        "type": {
          "id": "000000000000000e16fe0001",
          "name": "Expired SSL certificate",
          "description": "A security finding the platform detects on an asset.",
          "category": {
            "id": "000000000000000e1c170001",
            "name": "SSL/TLS"
          }
        },
        "first_seen_date": "2025-06-01T08:00:00.000000+00:00",
        "first_seen_date_humanized": "3 months ago"
      }
    },
    {
      "id": "00000000000000000000000ea8430002",
      "rule": {
        "id": "000000000000000e8e040002",
        "name": "New vulnerabilities",
        "scope": "reappeared_issue_detected",
        "frequency": "instant"
      },
      "sent_at": "2025-07-24T08:00:00Z",
      "recipients": [
        {
          "email": "user@acme.example",
          "full_name": "Jane Doe"
        }
      ],
      "context": {
        "event_date": "2025-07-24T08:00:00.000000+00:00",
        "event_date_humanized": "3 months ago",
        "id": "000000000000000e59ba0002",
        "asset": {
          "id": "000000000000000ea4f90002",
          "name": "fernhill.example",
          "name_unicode": "fernhill.example",
          "tags": []
        },
        "severity": "Medium",
        "last_seen_date": "2025-07-24T08:00:00.000000+00:00",
        "last_seen_date_humanized": "3 months ago",
        "type": {
          "id": "000000000000000e16fe0002",
          "name": "Missing DMARC record",
          "description": "A security finding the platform detects on an asset.",
          "category": {
            "id": "000000000000000e1c170002",
            "name": "DNS"
          }
        },
        "first_seen_date": "2025-05-25T08:00:00.000000+00:00",
        "first_seen_date_humanized": "3 months ago"
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl 'https://api.deepinfo.com/v1/platform/notification-emails?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
