---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Designate email domains as untrusted or trusted

# Designate email domains as untrusted or trusted {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Designate specific email domains as untrusted or trusted so that you can monitor the
metrics for incoming emails from these sources in your instance.

## Vorbereitungen

Role required: security_dashboard_user or admin

## Warum und wann dieser Vorgang ausgeführt wird

When untrusted or trusted domains send emails to your instance, their daily counts appear on the Untrusted Incoming Email or Trusted Incoming Email metrics on the Email page. You can then track email activity from these domains and use email logs to view specific incoming emails. You can also specify a user, usually a manager, or a security analyst, to notify whenever activity occurs from the untrusted or trusted domain.  
Hinweis:  
Designating an email domain as untrusted is for security tracking purposes only. Administrators can also set up a system address filter to ignore emails from untrusted domains. To learn about filtering emails to block their delivery, see [System address
filters](https://www.servicenow.com/docs/access?context=system-address-filters&version=australia&pubname=australia-platform-administration&ft:locale=en-US).

## Prozedur

1. Navigate to AllSystem SecurityInstance Security Center.
2. On the Instance Security Center homepage, select Email from the Metrics menu.  
3. On the Email page, in the Untrusted And Trusted Domains section, click New.
4. On the form, fill in the fields.  
   {#designate-untrusted-trusted-email-domains__table_kxg_qzk_ddb__entry__2}

   | Field | Description |
   |-|-|
   | Domain | Name of the email domain that you are designating as untrusted or trusted. For example, enter <kbd class="ph userinput">servicenow.com</kbd> to designate ServiceNow employees can send trusted emails to the instance. |
   | Category | Category that indicates if the email domain is untrusted or trusted: Untrusted :   Designates that the email domain as untrusted. You use it to identify domains that send suspicious or emails that pose a potential security threat to the instance. Trusted :   Designates that the email domain as trusted. You use it to identify domains when your metrics indicate that the incoming emails from it pose no security threats. Designating the domain as trusted enables you to track its inbound email activity over time. |
   | Active | Check box for enabling or disabling the designated untrusted or trusted status for the specified email domain. |
   | Notify | Name of the user to notify by email when activity occurs in the untrusted or trusted domain. Click the spotlight search icon ( ![Search]()) to search for the name of the user. Leave the Notify field blank if you do not want notifications sent. |
   [Tabelle : 1. Untrusted And Trusted Domain form]

   {#designate-untrusted-trusted-email-domains__table_kxg_qzk_ddb}
5. Select Save.

## Ergebnisse

Untrusted or trusted email domain information is also added to the Untrusted And Trusted Domains listing on the Email page.
**Zugehörige Konzepte**   

* [Instance Security Center](https://servicenow-prod.fluidtopics.net/xpUTpZb5ScUKqSrIXf3_Yg "Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.")
* [Email metrics](https://servicenow-prod.fluidtopics.net/0HSnfDpdKUtG0KUwVI3wrg "Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance.")

