---
title: "Analyze a provided link using ml.link_analysis functionality"
method: POST
path: "/v0/enrichment/link_analysis/evaluate"
tags: ["Enrichment"]
---

# Analyze a provided link using ml.link_analysis functionality

`POST /v0/enrichment/link_analysis/evaluate`

Analyze a provided link using ml.link_analysis functionality.

## Request body

- LinkAnalysisEvaluateInput
  - `no_logo_detect` boolean — Whether to skip logo detection
  - `url` string, required — URL to analyze

## Response `200`

OK

- HandlerTypesLinkAnalysisResponse
  - `additional_responses` LinkAnalysisTypesAdditionalResponse[] — Additional HTTP responses for the page, which could be additional resources, XHR requests, etc.
    - `content_type` string — Content type of the response
    - `file` LinkAnalysisTypesDownloadedFile — Raw HTTP response payload as a file
      - `file_extension` string — File extension from context such as headers
      - `file_name` string — File name
      - `file_type` '3gp' | '7z' | 'Z' | 'aac' | 'aiff' | 'amr' | 'ar' | 'avi' | 'bmp' | 'bz2' | 'cab' | 'cr2' | 'crx' | 'dcm' | 'deb' | 'dex' | 'dey' | 'doc' | 'docx' | 'dwg' | 'elf' | 'eot' | 'epub' | 'exe' | 'flac' | 'flv' | 'gif' | 'gz' | 'heif' | 'html' | 'ico' | 'ics' | 'iso' | 'jp2' | 'jpg' | 'jxr' | 'lz' | 'm4a' | 'm4v' | 'macho' | 'mid' | 'mkv' | 'mov' | 'mp3' | 'mp4' | 'mpg' | 'nes' | 'ogg' | 'otf' | 'pdf' | 'png' | 'ppt' | 'pptx' | 'ps' | 'psd' | 'rar' | 'rpm' | 'rtf' | 'sqlite' | 'svg' | 'swf' | 'tar' | 'tif' | 'ttf' | 'wasm' | 'wav' | 'webm' | 'webp' | 'wmv' | 'woff' | 'woff2' | 'xls' | 'xlsx' | 'xz' | 'zip' | 'zst' | 'unknown' — File type determined by looking at the magic bytes in the file
      - `md5` string — MD5 hash of the downloaded file
      - `raw` string, base64, nullable — Base64 encoded source of the file
      - `sha1` string — SHA1 hash of the downloaded file
      - `sha256` string — SHA256 hash of the downloaded file
      - `size` integer, nullable — Size of the file in bytes
    - `json` FfiJSON — Response from the URL decoded as a JSON object for application/json content types
    - `status_code` integer — HTTP status code for the response
    - `url` MdmServiceURL — URL details when QR code type is url
      - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
        - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
        - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
        - `root_domain` string, hostname — The root domain, including the TLD
        - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
        - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
        - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
        - `valid` boolean — Whether the domain is valid
      - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
      - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
        - `ip` string, required — The IP in canonical form
        - `translation` MdmServiceIPTranslation
          - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
          - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
        - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
      - `password` string — The password specified before the domain name
      - `path` string — Everything after the TLD and before the query parameters
      - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
      - `query_params` string — The full query parameters of the URL
      - `query_params_decoded` object — The decoded query parameters of the URL
      - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
        - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
        - `original` string, required — Original URL without any unraveling URL rewrites
      - `scheme` string — Protocol for the URL request, e.g. http
      - `url` string, required — Full URL
      - `username` string — The username specified before the domain name of the URL
  - `analyzed` boolean — Whether the target page was successfully analyzed for credential phishing attempts
  - `content_type` string — Content type of the page
  - `credphish` EnrichmentTypesCredPhish — CredPhish analysis of the screenshot taken for the final URL
    - `brand` EnrichmentTypesBrandInfo — Information about the recognized brand on the target page
      - `confidence` 'low' | 'medium' | 'high' — Level of confidence that the correct brand (or none) was identified
      - `name` 'ABN' | 'ADP' | 'AOL' | 'AT&T' | 'Adobe' | 'AliExpress' | 'Amazon' | 'American Express' | 'Apple' | 'Authentisign' | 'Awardco' | 'BB&T Corporation' | 'BBVA' | 'BT' | 'Bass Pro Shop' | 'Bank of America' | 'Barclays' | 'Belastingdienst' | 'Benteler' | 'BeyondTrust' | 'Bol' | 'Box' | 'CFA' | 'CNA' | 'CVS' | 'Caixabank' | 'Capital One Bank' | 'CalPoly' | 'Captcha' | 'Carta' | 'Chase' | 'ChicagoTitle' | 'Citi' | 'Cloudflare' | 'Coinbase' | 'Couer Mining' | 'CyberArk' | 'DHL' | 'DKB' | 'DPD' | 'Dayforce' | 'Digid' | 'Discord' | 'Discover' | 'Disney' | 'DocuSign' | 'Dropbox' | 'EY' | 'Ebay' | 'Europol' | 'Experian' | 'Facebook' | 'FakeAttachment' | 'FanDuel' | 'FedEx' | 'FidelityTitle' | 'FirstAm' | 'FuboTV' | 'GLS' | 'GM' | 'GeekSquad' | 'Gemini Trust' | 'Generic Captcha' | 'Generic Webmail' | 'Github' | 'Gmail' | 'GoDaddy' | 'Google' | 'GoogleDrive' | 'Google Voice' | 'Gusto' | 'HSBC Bank' | 'Heroku' | 'Home Depot' | 'HubSpot' | 'Hulu' | 'Huntress' | 'ING' | 'IRS' | 'Indeed' | 'Instagram' | 'Invite Company' | 'JFrog' | 'KPN' | 'Kehe' | 'Key Bank' | 'LawyersTitle' | 'Ledger' | 'LinkedIn' | 'Lloyds' | 'M & T Bank' | 'MadisonTitle' | 'MailChimp' | 'Mailgun' | 'Mastercard' | 'McAfee' | 'Meta' | 'MetaMask' | 'Microsoft' | 'Microsoft Office365' | 'Microsoft OneDrive' | 'Microsoft Outlook' | 'Microsoft SharePoint' | 'Microsoft Teams' | 'Mimecast' | 'NATO' | 'NHS' | 'NatWest' | 'Navan' | 'Navy Federal Credit Union' | 'Netflix' | 'Norton' | 'OVO' | 'Okta' | 'OldRepublicTitle' | 'OpenAI' | 'PNC' | 'Palo Alto Networks' | 'Pandora' | 'PayPal' | 'PostNL' | 'Postbank' | 'Proton' | 'Pulley' | 'QuicklySign' | 'Quickbooks' | 'RBS' | 'RLI' | 'Rabobank' | 'Rakuten' | 'Robert Half' | 'RoyalMail' | 'SBB' | 'SSA' | 'Santander' | 'Schwab' | 'SendGrid' | 'Shein' | 'Signal' | 'Silicon Valley Bank' | 'Slack' | 'Snowflake' | 'Sparkasse' | 'Spotify' | 'Square' | 'StewartTitle' | 'Stratus' | 'Stripe' | 'SunTrust Bank' | 'Swiss Post' | 'Swisscom' | 'TD Bank' | 'Target' | 'Targobank' | 'Threads' | 'TicorTitle' | 'Tidal' | 'TikTok' | 'Trezor' | 'TrustWallet' | 'Tyrell' | 'U.S. Bank' | 'UCSB' | 'UPS' | 'USPS' | 'Vanguard' | 'Venmo' | 'Visa' | 'Vodafone' | 'Volksbank' | 'WeTransfer' | 'Wells Fargo' | 'Wex' | 'WhatsApp' | 'Wise' | 'Workday' | 'WoS' | 'X' | 'Yahoo' | 'Zebra' | 'Zelle' | 'Zendesk' | 'Ziggo' | 'Zoom' | 'Zscaler' — Name of identified brand in the target page. Null if no brand was identified.
    - `confidence` 'low' | 'medium' | 'high' — Level in a credential phish assessment, only set if .disposition is phishing
    - `contains_captcha` boolean, nullable — Final page contains a captcha test
    - `contains_login` boolean, nullable — Final page resembles a login screen
    - `disposition` 'benign' | 'phishing' | 'unknown' — Verdict of the link, determined by various stages of analysis
  - `diagnostics` EnrichmentTypesLinkAnalysisRunDiagnostics — INTERNAL
    - `created_at` string, date-time — When the diagnostic object was created
    - `submit_verdict` string — Reason the URL was [not] submitted to Link Analysis
    - `submit_verdict_url` string — The URL upon which the submit verdict was based
  - `effective_url` MdmServiceURL — URL details when QR code type is url
    - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
      - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
      - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
      - `root_domain` string, hostname — The root domain, including the TLD
      - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
      - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
      - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
      - `valid` boolean — Whether the domain is valid
    - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
    - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
      - `ip` string, required — The IP in canonical form
      - `translation` MdmServiceIPTranslation
        - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
        - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
      - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
    - `password` string — The password specified before the domain name
    - `path` string — Everything after the TLD and before the query parameters
    - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
    - `query_params` string — The full query parameters of the URL
    - `query_params_decoded` object — The decoded query parameters of the URL
    - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
      - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
      - `original` string, required — Original URL without any unraveling URL rewrites
    - `scheme` string — Protocol for the URL request, e.g. http
    - `url` string, required — Full URL
    - `username` string — The username specified before the domain name of the URL
  - `files_downloaded` LinkAnalysisTypesDownloadedFile[] — All downloads from the page. These must download without interaction and within a few seconds
    - `file_extension` string — File extension from context such as headers
    - `file_name` string — File name
    - `file_type` '3gp' | '7z' | 'Z' | 'aac' | 'aiff' | 'amr' | 'ar' | 'avi' | 'bmp' | 'bz2' | 'cab' | 'cr2' | 'crx' | 'dcm' | 'deb' | 'dex' | 'dey' | 'doc' | 'docx' | 'dwg' | 'elf' | 'eot' | 'epub' | 'exe' | 'flac' | 'flv' | 'gif' | 'gz' | 'heif' | 'html' | 'ico' | 'ics' | 'iso' | 'jp2' | 'jpg' | 'jxr' | 'lz' | 'm4a' | 'm4v' | 'macho' | 'mid' | 'mkv' | 'mov' | 'mp3' | 'mp4' | 'mpg' | 'nes' | 'ogg' | 'otf' | 'pdf' | 'png' | 'ppt' | 'pptx' | 'ps' | 'psd' | 'rar' | 'rpm' | 'rtf' | 'sqlite' | 'svg' | 'swf' | 'tar' | 'tif' | 'ttf' | 'wasm' | 'wav' | 'webm' | 'webp' | 'wmv' | 'woff' | 'woff2' | 'xls' | 'xlsx' | 'xz' | 'zip' | 'zst' | 'unknown' — File type determined by looking at the magic bytes in the file
    - `md5` string — MD5 hash of the downloaded file
    - `raw` string, base64, nullable — Base64 encoded source of the file
    - `sha1` string — SHA1 hash of the downloaded file
    - `sha256` string — SHA256 hash of the downloaded file
    - `size` integer, nullable — Size of the file in bytes
  - `final_dom` LinkAnalysisTypesFinalDOM — Full DOM of the analyzed URL
    - `display_text` string, nullable — Visible text of the HTML document, with invisible characters removed and non-ASCII characters converted to ASCII spaces.
    - `inner_text` string, nullable — Inner text of the HTML document that doesn't include HTML tags.
    - `links` MdmServiceLink[] — Links found within the DOM
      - `display_text` string — The text of a hyperlink, if it's not a URL
      - `display_url` MdmServiceURL — URL details when QR code type is url
        - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
          - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
          - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
          - `root_domain` string, hostname — The root domain, including the TLD
          - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
          - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
          - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
          - `valid` boolean — Whether the domain is valid
        - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
        - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
          - `ip` string, required — The IP in canonical form
          - `translation` MdmServiceIPTranslation
            - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
            - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
          - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
        - `password` string — The password specified before the domain name
        - `path` string — Everything after the TLD and before the query parameters
        - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
        - `query_params` string — The full query parameters of the URL
        - `query_params_decoded` object — The decoded query parameters of the URL
        - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
          - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
          - `original` string, required — Original URL without any unraveling URL rewrites
        - `scheme` string — Protocol for the URL request, e.g. http
        - `url` string, required — Full URL
        - `username` string — The username specified before the domain name of the URL
      - `href_url` MdmServiceURL — URL details when QR code type is url
        - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
          - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
          - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
          - `root_domain` string, hostname — The root domain, including the TLD
          - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
          - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
          - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
          - `valid` boolean — Whether the domain is valid
        - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
        - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
          - `ip` string, required — The IP in canonical form
          - `translation` MdmServiceIPTranslation
            - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
            - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
          - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
        - `password` string — The password specified before the domain name
        - `path` string — Everything after the TLD and before the query parameters
        - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
        - `query_params` string — The full query parameters of the URL
        - `query_params_decoded` object — The decoded query parameters of the URL
        - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
          - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
          - `original` string, required — Original URL without any unraveling URL rewrites
        - `scheme` string — Protocol for the URL request, e.g. http
        - `url` string, required — Full URL
        - `username` string — The username specified before the domain name of the URL
      - `mismatched` boolean, nullable — Whether the display URL and href URL root domains are mismatched (i.e. .href_url.domain.root_domain != .display_url.domain.root_domain, where both are not null and valid domains)
      - `parser` 'plain' | 'hyperlink' — The parser that was used to derived the link
      - `visible` boolean, nullable — Whether the link is visible to a human when previewing an email or page
    - `raw` string, nullable — Decoded raw content of a body text type (text/[subtype] section)
  - `original_url` MdmServiceURL — URL details when QR code type is url
    - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
      - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
      - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
      - `root_domain` string, hostname — The root domain, including the TLD
      - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
      - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
      - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
      - `valid` boolean — Whether the domain is valid
    - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
    - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
      - `ip` string, required — The IP in canonical form
      - `translation` MdmServiceIPTranslation
        - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
        - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
      - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
    - `password` string — The password specified before the domain name
    - `path` string — Everything after the TLD and before the query parameters
    - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
    - `query_params` string — The full query parameters of the URL
    - `query_params_decoded` object — The decoded query parameters of the URL
    - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
      - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
      - `original` string, required — Original URL without any unraveling URL rewrites
    - `scheme` string — Protocol for the URL request, e.g. http
    - `url` string, required — Full URL
    - `username` string — The username specified before the domain name of the URL
  - `page_status_code` integer, nullable — HTTP status code of the page
  - `redirect_history` MdmServiceURL[] — Each URL which the link analysis service was redirected through
    - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
      - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
      - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
      - `root_domain` string, hostname — The root domain, including the TLD
      - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
      - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
      - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
      - `valid` boolean — Whether the domain is valid
    - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
    - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
      - `ip` string, required — The IP in canonical form
      - `translation` MdmServiceIPTranslation
        - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
        - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
      - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
    - `password` string — The password specified before the domain name
    - `path` string — Everything after the TLD and before the query parameters
    - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
    - `query_params` string — The full query parameters of the URL
    - `query_params_decoded` object — The decoded query parameters of the URL
    - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
      - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
      - `original` string, required — Original URL without any unraveling URL rewrites
    - `scheme` string — Protocol for the URL request, e.g. http
    - `url` string, required — Full URL
    - `username` string — The username specified before the domain name of the URL
  - `retrieved` boolean — Whether the page was successfully retrieved
  - `retrieved_at` string, date-time, nullable — Time the page was retrieved
  - `screenshot` MdmServiceFile — File containing screenshot of final_url
    - `file_extension` string — File extension from context such as headers
    - `file_name` string — File name
    - `file_type` '3gp' | '7z' | 'Z' | 'aac' | 'aiff' | 'amr' | 'ar' | 'avi' | 'bmp' | 'bz2' | 'cab' | 'cr2' | 'crx' | 'dcm' | 'deb' | 'dex' | 'dey' | 'doc' | 'docx' | 'dwg' | 'elf' | 'eot' | 'epub' | 'exe' | 'flac' | 'flv' | 'gif' | 'gz' | 'heif' | 'html' | 'ico' | 'ics' | 'iso' | 'jp2' | 'jpg' | 'jxr' | 'lz' | 'm4a' | 'm4v' | 'macho' | 'mid' | 'mkv' | 'mov' | 'mp3' | 'mp4' | 'mpg' | 'nes' | 'ogg' | 'otf' | 'pdf' | 'png' | 'ppt' | 'pptx' | 'ps' | 'psd' | 'rar' | 'rpm' | 'rtf' | 'sqlite' | 'svg' | 'swf' | 'tar' | 'tif' | 'ttf' | 'wasm' | 'wav' | 'webm' | 'webp' | 'wmv' | 'woff' | 'woff2' | 'xls' | 'xlsx' | 'xz' | 'zip' | 'zst' | 'unknown' — File type determined by looking at the magic bytes in the file
    - `raw` string, base64, nullable — Base64 encoded source of the file
    - `size` integer, nullable — Size of the file in bytes
  - `status_code` integer — HTTP status code for the requested page
  - `submitted` boolean — Whether the page was submitted to be retrieved for analysis
  - `unique_urls_accessed` MdmServiceURL[] — All unique URLs accessed during the analysis
    - `domain` MdmServiceDomain — Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain of the sending organization. This field provides additional context for analyzing the legitimacy of the sender
      - `domain` string, hostname, required — The fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
      - `punycode` string — Interpreted punycode if the domain starts with xn--. For example, if 'domain' is 'xn--ublimesecurity-4xc.com' then 'punycode' is śublimesecurity.com
      - `root_domain` string, hostname — The root domain, including the TLD
      - `sld` string — Second-level domain, e.g. 'windows' for the domain 'windows.net'
      - `subdomain` string — Subdomain, e.g. 'drive' for the domain 'drive.google.com'
      - `tld` string — The domain's top-level domain. E.g. the TLD of google.com is 'com'
      - `valid` boolean — Whether the domain is valid
    - `fragment` string — Fragment identifier; the text following the # in the URL (also called the anchor tag)
    - `ip` MdmServiceIP — X-Originating-IP header, which identifies the originating IP address of the sender client
      - `ip` string, required — The IP in canonical form
      - `translation` MdmServiceIPTranslation
        - `original` string, nullable — The IP in its original format if it is an IPv4-mapped-IPv6 source address
        - `v4_to_v6` boolean — Whether 'Original' is IPv4-mapped-IPv6
      - `version` integer, nullable — The version of IP (i.e., 4 or 6), null for backward compatibility.
    - `password` string — The password specified before the domain name
    - `path` string — Everything after the TLD and before the query parameters
    - `port` integer, nullable — The port used for the URL. If no explicit port is set, the port will be inferred from the protocol
    - `query_params` string — The full query parameters of the URL
    - `query_params_decoded` object — The decoded query parameters of the URL
    - `rewrite` MdmServiceRewriteDetails — Information about an original URL that was unfurled from rewrite detection
      - `encoders` string[] — List of detected URL rewrite encoders while unraveling the URL
      - `original` string, required — Original URL without any unraveling URL rewrites
    - `scheme` string — Protocol for the URL request, e.g. http
    - `url` string, required — Full URL
    - `username` string — The username specified before the domain name of the URL
  - `would_analyze` boolean — Whether the link would have been analyzed if run in a rule
  - `would_submit` boolean — Whether the link would have been submitted if run in a rule

---

[API](https://skmtc.net/sublime/apis/sublime-platform-api.md) · [All operations](https://skmtc.net/sublime/apis/sublime-platform-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sublime/sublime-platform-api/revisions/d5df82850357/schema)
