Alerting

Adding emails to Trusted group

im_bharath
Path Finder

Hello All, 

Currently we have setup the use case to send the emails whenever a condition is satisfied and an alert is fired up.

My concern is whenever the email is received we are receiving the address in the FROM field as "abc.xyz+untrusted@jkl.com",   and we think that some mail boxes are not getting these emails from the specific untrusted email address, 

please correct me if i am misunderstood. 

Also, is there a way to add this "abc.xyz@jkl.com" to the trusted email group or something like that?

or is there a different way to get the actual email address instead of the +untrusted email whenever an email is sent out from splunk.

Hope this makes sense. 

Thanks, 

Labels (3)
0 Karma

im_bharath
Path Finder

Okay Thanks for the suggestions.. i will reach out to our exchange team and see if they can provide a solution and will post the outcome here.

Thanks.  

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@im_bharath - I think this is being done by your email security system rather than Splunk.

 

I hope this helps!!!

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as @VatsalJagani said this syntax ab.cd+something@foo.bar is used by some mail systems to reroute addresses to correct recipient by that "+something". So you must contact to your email provider to add that new domain to trusted ones.

r. Ismo

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you use on-prem Splunk Enterprise then you can set the From email address to any value you wish.  If you use Splunk Cloud then the From address cannot be changed.

Either way, I get the impression "+untrusted" is being added to the From field after the message leaves Splunk - probably by your email service.  You should talk to your email admin about that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...