---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - Email Search and Delete flow

# Security Operations Integration - Email Search and Delete flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations Integration - Email Search and Delete flow returns the number of threat emails from an email server search and, optionally, return details for each email found. After the email search is completed, you
can delete the emails.

## Before you begin

Role required: sn_si.analyst

## About this task

The search query can take some time to complete. After the count is received, approval is required to delete emails from an email server.

This flow is triggered by the Delete from Email Server(s) and Search on Email Server(s) buttons on the Email Search form in a security incident. For more information, see [Search for and delete phishing emails](https://servicenow-prod.fluidtopics.net/QqzrRi19NWal7aOyPGG09g "Deleting phishing emails can help reduce exposure to a specific attack across an organization. You can manage phishing emails on your email server by searching, granting approvals, and deleting them.").
Figure 1. Email Search and Delete

Activities specific to this flow are described here. For more information on other activities, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
The flow process activities include:
* **[Legacy: Execution Tracking Begin (Mail Search) action](https://servicenow-prod.fluidtopics.net/QYChfnl8P16l56xTRiVK4w)**   
  The Execution Tracking - Begin (Mail Search) capability execution action creates an execution tracking record and marks the record state as Started. This action is used by all capability and implementation flows to keep track of their state.

