Email filters
Summarize
Summary of Email filters
Email filters in ServiceNow allow you to specify which inbound emails to ignore or move to specific mailboxes, enhancing email management and reducing unnecessary processing. Ignored emails are saved in the system but not processed, and can be accessed via their Email [sysemail] records. The Email Filters plugin (com.glide.emailfilter) is enabled by default in versions after Kingston; for earlier versions, it must be activated manually.
Show less
Key Features
- Default Email Filters: Several predefined filters come standard:
- Ignore VCAL: Ignores emails containing vCalendar requests to prevent creating unnecessary incident records from email responses.
- Ignore Header: Ignores emails with specified headers, overriding the glide.pop3.ignoreheaders property.
- Junk Email - Sender Equals Recipient: Moves emails sent from the SMTP user back to the Junk folder.
- Ignore Subject: Filters out emails containing specified terms or phrases in the subject line, overriding glide.pop3.ignoresubjects.
- Move Spam to Junk Folder: Moves emails flagged as spam (via the X-ServiceNow-Spam-Status header) to the Junk folder.
- Filter Actions: Filters can be configured to either mark emails as ignored or move them to Junk. Additionally, custom Action scripts can be used for advanced email handling.
- Email Filter Script Include: The EmailUtils script include supports filters such as Ignore VCAL by detecting vCalendar content in emails.
- Spam Scoring and Virus Scanning: ServiceNow evaluates inbound emails for spam likelihood and virus infections, adding headers like X-ServiceNow-Spam-Status and X-ServiceNow-Virus:INFECTED. Virus-infected emails are automatically ignored. These features require the use of ServiceNow's email infrastructure.
Practical Use for ServiceNow Customers
By leveraging email filters, you can streamline email processing, reduce noise from automated or unwanted emails, and protect your instance from spam and virus threats. You can create custom filters with specific conditions and actions to tailor email handling to your organizational needs, ensuring relevant emails are appropriately processed and irrelevant or harmful ones are managed effectively.
Enabling spam scoring and virus scanning enhances email security and reduces manual intervention. The default filters address common scenarios, but you can extend functionality with custom action scripts for specialized workflows.
Specify which inbound emails to ignore or move to a particular mailbox.
When an email is ignored, the email is saved to your instance but is not processed. You can access an ignored email by viewing its Email [sys_email] record.
The Email Filters (com.glide.email_filter) plugin is active by default for releases after Kingston, for releases before Kingston, it needs to be activated, for more information see Activate email filters.
Default email filters
By default, the following filters are available from the module:
| Filter | Description |
|---|---|
| Ignore VCAL | Ignores all email containing vCalendar requests. This filter prevents inbound email actions from creating unnecessary incident records when the instance receives a response to sent email. vCalendar requests in email responses are identified by the EmailUtils script include. |
| Ignore header | Ignores email that contains specific headers. This filter overrides the glide.pop3.ignore_headers property. |
| Junk email - sender equals recipient | Filters out emails that are from the same user as the SMTP user to the Junk folder. |
| Ignore subject | Ignores email with specific terms or phrases in the subject line. This filter overrides the glide.pop3.ignore_subjects property. This filter might not apply to emails arriving from unknown users. Unknown users can be locked out. |
| Move spam to junk folder | Moves email identified as spam to the Junk folder. This filter checks for the value
of the ServiceNow spam header. If the header is
X-ServiceNow-Spam-Status:Yes, the filter moves the email to the
Junk folder |
To learn more about enabling spam scoring and filtering, see Email spam scoring and filtering (instance security hardening) in Instance Security Hardening Settings.
Email filter script include
Email filters use a script include called EmailUtils that contains a simple
utility function to determine if vCalendar is in the body of the response
email. The results of this query are used in a condition script in the Ignore
VCAL email filter.
Spam scoring and virus scanning
Every message sent through email servers is assessed for the likelihood of being spam. Based on this assessment, the instance adds headers to each message that can be used for filtering within the customer instance using the Email Filters plugin.
The system also adds the X-ServiceNow-Virus:INFECTED header to an email
that contains one or more virus-infected attachments. The system ignores the email.
Spam scoring and virus scanning are available only for instances that use the ServiceNow email infrastructure. For more information on spam scoring and filtering, see KB0549426.