You can configure Trellix DLP Network Prevent – SaaS to bypass scanning of emails sent from the specified email addresses.
Specify the Smart Hosts that can send messages.
Note
The bypassed emails are not reported in incidents. The appliances also don't generate evidence from the bypassed emails.
In ePO - SaaS, open the Policy Catalog.
Select the DLP Appliance Management <version> product, choose the Trellix DLP Network Prevent Email Settings category, and open the policy that you want to edit.
In the DLP Scan Bypass field, type the sender email address that you want to bypass from scanning. Use the is format to specify the actual email address. Use the matches format to specify multiple email addresses using *@domain_name.com. Click Update after typing each email address or domain name.
To add an email address, click +.
To remove an email address, click –.
From Actions, choose the action header that you want to include in the message sent to the configured Smart Host. By default, you can select Add header X-RCIS-Action (BYPASS)
Selecting Add header X-RCIS-Action (BYPASS) adds the BYPASS value to the X-RCIS-Action header in the message sent to the configured Smart Host. Selecting No Action doesn't add any header value in the message sent to the configured Smart Host.
Click Save.