About Inline Email DLP

Prev Next

Inline Email DLP extends Skyhigh Security Cloud DLP to the messages sent from your organization's mailboxes.

When using Inline Email DLP, Exchange Online remediation actions occur in real time so data never leaves your organization through Exchange Online email messages.

Components

The following components are required for this feature:

  • Exchange Online mail routing (connectors and rules)

  • Skyhigh Security Cloud Gateway (mail is routed from Office 365 to Skyhigh Security Cloud Gateway proxy)

  • Skyhigh Security Cloud Link (API) connection to Exchange Online for quarantine and delete remediation actions

Email flow

Office 365 is configured to send messages through Skyhigh Security Cloud Gateway so it can inspect the contents of the message. Skyhigh Security Cloud Gateway acts as an SMTP proxy and as such never stores or queues messages. Messages are processed in real time and require an active inbound and outbound SMTP session to proxy both legs.

The email flow is as follows:

  1. A user in your organization sends a message.

  2. Based on mail routing rules configured in Exchange Online, messages are forwarded to the Skyhigh Security Cloud Gateway SMTP server.

  3. The Skyhigh Security Cloud Gateway SMTP server proxies the connection from Exchange Online server (2), performs DLP inspection, and proxies back the connection to Exchange Online server (4).

  4. Exchange Online receives the message.

  5. Exchange Online forwards the message onto one or more original destinations.

GUID-F235B2CF-C806-4BCB-9743-48CB28A2909B-low.png

Message Transport Error Handling

As the Skyhigh Security Cloud Gateway acts as an SMTP proxy, it never accepts the SMTP connection unless the outbound leg can be established. Skyhigh Security Cloud Gateway never queues or stores messages so both legs of the connection must be up for messages to flow. This ensures that Exchange Online handles any issues with connections. If a connection fails, the sending Exchange Online will re-queue the message and try again.

Error messages received from the receiving SMTP gateway are relayed back to the sending SMTP gateway so the sending gateway can re-queue the message for transport.

GUID-7E761EBA-6839-4998-8584-CDBA4A2FB243-low.png

Remediation Options

Because Inline DLP is done in real-time, it requires the API-based Skyhigh Security Cloud Gateway integration. Skyhigh Security Cloud Gateway ensures that emails are blocked, deleted, or quarantined before they ever leave a sender's email account. For example, if you set up a DLP policy that deletes emails containing sensitive keywords, any message containing a specified word is deleted from a sender's mailbox. With Skyhigh Security Cloud Gateway you can choose from the following options:

Block — When an email is blocked, the email remains in the sender's Sent folder, but the intended recipient does not receive the message. The Skyhigh Security Cloud administrator does not receive a copy of the email in the Quarantined folder. The email does not leave the sender's account.

Delete — When an email is deleted, the email is removed from the sender's Sent folder, and the intended recipient does not get the email. The Skyhigh Security Cloud administrator does not receive the email in the Quarantined folder.

Quarantine — When an email is quarantined, the email is removed from the sender's Sent folder, and the intended recipient does not receive the email. The Skyhigh Security Cloud administrator receives the email in the Quarantined folder. Emails are quarantined in real-time, 8031 API.

Notifications — You can choose to notify users and Skyhigh Security Cloud administrators by email when messages are blocked, deleted, or quarantined.