Run Email Actions

Running an Email Action is similar to running any Action in the platform. The procedure below does not include detailed information about runtime options. For information about runtime options, see Running Actions.

TIP: You should clean out your email inboxes and outboxes periodically, as emails will continue to accumulate over time. We cannot recommend best practices for doing this because the procedure will vary, based on your organization and the software / system you are using.

To run an Email Action

  1. Go to Library > Actions.
  2. Search for the Action you want to run.

    Whether you want to run an Action that the Security Validation VRT created or one you created, you can search for Email Actions in the same way. In the example shown in the screenshot, we filtered results by Action Type (Email) and then entered the search term "Malicious" to further narrow results.

    Searching for Email Action containing Malicious attachment

  3. Click on the Action you want to run in the search results.
  4. Click Run.
  5. For the From Email Profile field, select one of your profiles that contains a verified email address as the source of the Action.
  6. Specify the Source Actor.
  7. (Optional) Click Expand  and then enter a Spoofed From Address if you require one for this Email Action.

    Spoofed From Address works for all POP3 and IMAP server types, but does not work for Microsoft Office or Gmail. If the field is greyed out, you are not using a supported server type.

  8. For the To Email Profile field, select one of your profiles that contains a verified email address as the destination of the Action.
  9. Specify the Destination Actor.

    Running an Email Action

  10. Click Run Now.
  • June 5, 2022
  • November 16, 2023
In This Article