Network Management

"WARNING" tag appears in SolarWinds Platform alert email subject line

This article explains why SolarWinds Platform alert notification emails may display a "(WARNING)" tag prepended to the subject line, and how to resolve it by updating the Sender Detail email address to match the organization's mail domain.

First published date

4/7/2026 4:21 PM

Last published date

4/7/2026 4:21 PM

Overview

SolarWinds Platform products, such as Network Performance Monitor (NPM), send alert notification emails when monitored thresholds are exceeded. Under normal conditions, these emails arrive with a clean subject line such as:

Critical Alert - Border Router Interface Capacity Level Is Above Threshold

However, some organizations may observe the subject line modified with a "(WARNING)" prefix:

(WARNING) Critical Alert - Border Router Interface Capacity Level Is Above Threshold

This behavior is not caused by SolarWinds itself, but by the organization's mail system applying a security policy to flag emails originating from unrecognized or external sender domains.

Product section

Network Performance Monitor

Cause

The organization's email system (e.g., Microsoft Exchange, a mail gateway, or a spam filter) is configured to flag messages that originate from sender domains that do not belong to the organization. When the default SolarWinds Platform Sender Detail email address uses a domain that is external to the organization's mail domain, the mail system automatically prepends "(WARNING)" to the subject line as a security measure.

Resolution

To resolve this issue, update the sender email address in the SolarWinds Platform alert configuration to use a domain that belongs to your organization's mail system.

  1. Log in to the SolarWinds Platform Web Console as an administrator.

  2. Navigate to Settings > All Settings.

  3. Under the Alerts & Reports section, click Configure Default Alert Sender.

  4. In the Sender/Reply Address field, update the email address to use your organization's domain.

    • For example, change the address to noreply@yourdomain.com (e.g., noreply@solarwinds.edu).

  5. Click Save or Submit to apply the changes.

  6. Trigger a test alert or wait for the next alert cycle to confirm that the "(WARNING)" tag is no longer prepended to the email subject line.

Note: Ensure the updated sender address is authorized in your mail system. Depending on your environment, you may need to add the new sender address to your mail server's allowed senders list, SPF record, or a mail flow rule to prevent delivery issues.

 

If individual alert definitions override the default sender, repeat the process for each affected alert:

  1. Navigate to Alerts & Activity > Alerts.

  2. Edit the alert definition that is affected.

  3. In the Trigger Action or Reset Action section, select the Send an Email/Page action.

  4. Update the From Address field to use the organization's domain.

  5. Save the alert definition.