---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations email processing

# Security Operations email
processing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can set up the integration of information from external detection systems, provide
granularity in processing security operations records, handle unmatched emails, and prevent
duplication of records using Email Processing.  
Email Processing consists of these features:{#email-processing__table_irw_c1q_dt__entry__2}

| Feature | Description |
|-|-|
| Email Parsing | Generate new Security Operations records from external system emails. |
| Duplication Rules | Identifies new email with known incidents and processes them appropriately. |
| Properties | Specifies accounts used as input in Email Parsing for security, vulnerability, and IoCs. Provides for granularity in processing Security Operations records. |
| Unmatched Emails | Lists emails that do not match any Security Operations record. |
[ ]

{#email-processing__table_irw_c1q_dt}
* **[Security Operations email properties](https://servicenow-prod.fluidtopics.net/6re4ZoC30Of64AwOx~Cmnw)**   
  Email Properties specify which inboxes are used as input in Email Parsing to import information from external detection systems to create records for security, vulnerability, and IoCs. You can set up a general account for all external detection systems to use, or individual email accounts for Security Incident Response, Threat Intelligence, or Vulnerability Response.
* **[Security Operations email parsing](https://servicenow-prod.fluidtopics.net/e3AEPsAj5Z~kDlc_eORyfw)**   
  Generate new Security Operations records from external detection systems using Email Parsing. This feature provides a method for integrating information from external tools such as malware detection, vulnerability detection, firewalls, threat intelligence, and more.
* **[Unmatched Security Operations email events](https://servicenow-prod.fluidtopics.net/fvy7G6dHbSbM3pDcI_4ZTw)**   
  Email events that do not match an email parser have their "matched" flag unset. You can view these email event records from the Unmatched Emails list, to reveal external detection systems whose emails are not yet parsed.

