---
sourceDocument: Brazil ServiceNow AI Platform Administration
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-administration

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Inbound email actions

# Inbound email actions {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Inbound email actions

Inbound email actions in ServiceNow enable you to define scripted responses to inbound emails, allowing the system to automatically take specific actions based on email content and conditions.
These actions operate similarly to business rules by using conditions and scripts to act on target tables, typically creating or updating records like incidents.
Show full answer Show less  
Inbound email flows take precedence over inbound email actions, meaning emails are processed first by flows if they are configured with inbound email triggers.

## Inbound Email Processing and Action Types

The system classifies incoming emails into three types:

* **Forward:** Identified by recognized forward prefixes in the subject (e.g., "FW:") and forward strings in the body (e.g., "From:"). These take priority over any watermark that would classify the email as a reply.
* **Reply:** Determined by the presence of watermarks referencing existing records, reply prefixes (e.g., "RE:"), recognized record numbers, or thread-index headers (supported only for Microsoft Outlook emails when enabled via a system property).
* **New:** Emails that do not match criteria for forward or reply are classified as new and can trigger creation of new records.

Watermarks are used to associate emails with existing tasks, with the last watermark in the email body considered if multiple are present.

## Actions and Outcomes

* **Record action:** Sets or updates field values on the target table record associated with the email.
* **Email reply:** Sends an automated email response back to the email sender.

By default, emails without identifiable watermarks trigger creation of new incidents, while emails with watermarks update existing incidents.

## Attachments and Character Encoding

* Attachments from inbound emails are added to the first record created or updated by the inbound email action.
* Character encoding is preserved if ASCII-7 or UTF-8. ISO-8859-1 encoding is converted to Windows 1252, and other encodings are converted to plain text, which may affect readability.

## Domain Separation and Processing State

Inbound email actions should be maintained in the global domain to ensure correct record creation respecting user domains. When creating records such as incidents, the domain is determined by the caller's domain or defaults to global if the caller is not found.

All incoming emails processed by inbound email actions have their state updated to "Processed," even if no matching action was triggered.  
Define an inbound email action to script how the system responds to an inbound email.  
Note:  
Inbound email flows take priority over inbound email actions. If you create flows with inbound email triggers, emails are first processed by the inbound email triggers before they are processed by inbound email actions.
Inbound email actions are similar to business rules: both use conditions and scripts that take action on a target table. An inbound email action checks the email for a watermark that associates it with a task and checks for other conditions. If the conditions are met, the system takes the inbound email action that you configure. The system can take two types of actions:

* Record action: setting a value for a field in the target table.
* Email reply: sending an email back to the source that triggered the action.
{#c_InboundEmailActions__ul_sx1_twz_zr}

By default, if an email has no identifiable watermark, an
inbound email action attempts to create an incident from the message. If the email has a
watermark of an existing incident, an inbound email action updates the existing incident
according to the action's script.

## Inbound email receive types {#c_InboundEmailActions__section_nln_vqq_2cb}

The system classifies all incoming email into one of three types: forward, reply, or new. {#c_InboundEmailActions__table_pzp_cx2_bx__entry__3}

| Order | Type | Criteria |
|-|-|-|
| 1 | Forward | The system classifies an email as a forward only when it meets all these criteria: * The subject line contains a recognized forward prefix such as FW:. * The email body contains a recognized forward string such as From:. {#c_InboundEmailActions__ul_e2f_fx2_bx} The system classifies any email that meets these criteria as a forward, even if the message contains a watermark or record number that otherwise classifies it as a reply. |
| 2 | Reply | The system classifies an email as a reply when it fails to match it to the forward receive type and it meets any one of these criteria: 1. The subject line or email body contains a recognized watermark such as Ref:MSG0000008. 2. There is no watermark and the subject line contains a recognized reply prefix such as RE: and a recognized record number such as INC0005574 3. There is no watermark and the Reply-To header contains a recognized message ID of an email with watermark. 4. If an email does not meet any of the previous criteria, the system checks the email header for a thread-index. When a thread-index is present, the system classifies the email as a reply and associates it with the relevant conversation or thread view. This functionality is supported only for emails originating from Microsoft Outlook. Note: To enable thread indexing, create the system property glide.inbound.email.classify.by.thread_index and set it to true. {#c_InboundEmailActions__ol_mgl_p4r_m3c} |
| 3 | New | The system classifies an email as new when it fails to match it to the forward and reply receive types. |
[Table 1. Inbound action classifications]

{#c_InboundEmailActions__table_pzp_cx2_bx}  
Note:  
From Paris release and beyond, if an email body has multiple watermarks, the last watermark in the email body is considered.  
Figure 1. Determining the type of incoming email

## Attachments

If an inbound email contains one or more email attachments, the inbound email action adds the attachments to the first record the action produces.

## Character encoding

* If the email encoding is ASCII-7 or UTF-8, inbound email actions preserve the character encoding in any associated task records they produce.
* If the email encoding is ISO-8859-1, the inbound email action attempts to convert the email to Windows 1252.
* Inbound email actions convert any other encodings (for example, Mac OS Roman) to plain text, which may or may not be readable.
{#c_InboundEmailActions__ul_dbr_22r_n4}  
See the [System email log and mailboxes](https://www.servicenow.com/docs/s_c4WEybGO~oxwwfDhdXAQ "The system email log records all emails that the instance creates or receives. System mailboxes are filtered views of this log.") for examples of what you might see if a notification or inbound email action is not processed.  
Note:  
The state of all incoming emails that have been run against inbound email actions, even if there is no matching action, is changed to Processed.

## Domain separation

The system ignores the domain that the inbound email action record is in when it creates a record based on the inbound email action. Keep inbound actions in the global domain. For example, if your inbound email action creates an
incident, the system creates the incident in the same domain as the user in the Caller field. If that user is not in the User \[sys_user\] table, the incident is in the global domain.
**Related concepts**   

* [Notification variables](https://www.servicenow.com/docs/JYObQZXDtl_xdeCLaGKVKg "Use notification variables to display dynamic information in the body of a notification such as a field value, a link to a record, or a link to system preferences.")
* [Watermarks on notification emails](https://www.servicenow.com/docs/TVju~bKzJxsHy1VKG1OKfA "By default, a unique watermark label will be generated at the bottom of each notification email to allow matching incoming email to existing records.")

