Tools

Service Desk (ITSM): Emails not generating new incidents

Instructions for troubleshooting issues where inbound emails are not generating new tickets in SolarWinds Service Desk.

First published date

8/11/2024 11:34 PM

Last published date

8/14/2025 3:59 PM

Overview

There is a dedicated mailbox for each tenant in the format support@accountname.samanage.com. Any email sent (or forwarded) to this address will create new incidents or comments, whichever is applicable.

There are many possible reasons why an email would not create an incident, from the status of the user account to the email and spam filter settings.

Included in this article are the most common reasons for such issues and the steps to troubleshoot each unique scenario.

References:
- Email Settings

Product section

Service Desk

Cause

Here are the most common reasons why an email did not create a new record.
  1. The user account (sender) is disabled.
  2. The "Blocked and Allowed Addresses" setting is not configured correctly.
  3. The email was sent to an internal address, but the forwarding rule was not set up correctly.
  4. The email was added as a comment to an existing incident.
  5. The email was rejected or quarantined (generally a bounceback message is received by the sender).

Resolution

Here are the ways to troubleshoot each unique scenario.
 
  1. The user account (sender) is disabled.
    • If the email address is tied to a user, verifying the corresponding user account is enabled in "Setup > Users & Groups > Users."
  2. The "Blocked and Allowed Addresses" setting is not configured correctly.
    • Verifying the sender is permitted via the allowed and blocked list settings under Setup -> Account -> Email Settings.
    • If you are concerned about unintentionally blocking email domains by using this strict list of authorized domains, SolarWinds recommends leaving the allowed list open and using the blocked domains feature.
    • When adding domains, do not include the at sign (@). For example, enter google.com instead of @google.com.
  3. The email was sent to an internal address, but the forwarding rule was not set up correctly.
    • If the sender sent the email to an internal address, a forwarding rule must exist for emails to reach your SWSD.
    • Any email sent to your dropbox (support@accountname.samanage.com) is received in your SolarWinds Service Desk. If you set up an easy-to-remember support email address, such as support@company.com, you should forward all emails sent to that address to your default mailbox.
    • Please visit this page for more info.
  4. The email was added as a comment to an existing incident.
    • By default, if a user is responding to an email notification, the application is set to check based on the subject (containing Incident #VALUE) or the reference headers corresponding to an existing incident. If none of these conditions are satisfied, a new record will be created.
    • To ensure new emails create new records, the sender must create the email from scratch.
  5. The email was rejected or quarantined (generally a bounceback message is received by the sender).  NOTE: By default, SolarWinds performs SPF/DMARC/DKIM checks on inbound emails sent to the application. As a result, if there's a detection that a sender is not permitted to send emails on behalf of a customer's domain for example, the emails can be quarantined or fully rejected. There are also instances where emails are quarantined due to a false-positive spam interpretation by SolarWinds' inbound email vendor.
    • Customers may need to contact SolarWinds. The options below can generally be offered: 
      1) Turn off SPF/DMARC/DKIM checks entirely -> Should be used as a last resort as such a change can leave a customer's environment to email spoofing.
      2) Whitelist applicable domains on the customer's behalf.
      3) The customer verifies that the applicable domain(s) are permitted per the applicable policy.
      4) Push through quarantined instances on the customer's behalf.