Configuring inbound mail flow

Prev Next

Depending on which mode of service you have, you must configure your Email Security - Cloud environment to correctly analyze email and act in coordination with your MTA. Email Security - Cloud domains with their respective analysis modes and features must be provisioned before using Email Security - Cloud. There are three standard modes:

  • BCC/OOB mode—Cloud MVX provides passive (out of band) analysis of incoming email to identify advanced threats, but malicious email is not blocked. Only emails received from domains outside your organization can be provisioned for scanning and analysis. See Configuring Blind Carbon Copy/Out of Band (BCC/OOB) mode for more information.

  • Inline mode—Cloud MVX provides active (inline) analysis of incoming email to identify advanced threats and malicious email is blocked. Only emails received from domains outside your organization can be provisioned to be scanned, analyzed, and blocked. See Configuring Inline mode for more information.

  • Inline with Hygiene mode—Cloud antispam/antivirus with analysis provides active (inline) analysis of incoming email to identify spam, malware, and advanced threats. Malicious email is blocked in Inline with Hygiene mode. Only emails received from domains outside your organization can be provisioned to be scanned, analyzed, and blocked. See Configuring Inline with Hygiene mode for more information.

You can also configure your Email Security — Cloud environment to analyze mail using alternative versions of the three modes listed above. Licenses required to configure standard modes can also be used to deploy alternative modes. For example, Second Hop Hygiene mode, an alternative version of Inline with Hygiene mode, requires a full hygiene license. This document includes details on the following alternative scanning methods:

  • Second Hop Hygiene mode—Cloud antispam/antivirus with analysis provides active (inline) analysis of incoming email to identify spam, malware, and advanced threats. Unlike Inline with Hygiene mode, it is not required for your domain MX records to point to Email Security — Cloud. Because Email Security — Cloud is the second hop in email delivery, SPF/DKIM/DMARC inspection, IP reputation block lists, and two second opinion spam engines are omitted from scanning. Other Hygiene features, including AV/AS, smart DNS detection, newsletter detection, CEO fraud detection, URL rewrite, and advanced threat detection are still available.

Caution

Trellix Email Security - Cloud is designed to scan messages originating from external entities sent into your organization. Messages originating from within a customer's managed network/boundaries, including third-party tools that a customer subscribes to or uses and messages between domains in a customer's organization, must not be forwarded to Email Security — Cloud.

Caution

You must configure allowlists on the next-hop MTAs to ensure that messages are delivered reliably, as described in the following sections. If allowlists are not configured, some or all messages may be lost. Allowlists are mandatory.

This section contains mode and region-specific guidance for integrating your MTA with Email Security - Cloud. For steps specifically tailored to Email Security — Cloud integration with Gmail or Office 365, see the Gmail and Email Security - Cloud Integration Guide or the Office 365 and Email Security - Cloud Integration Guide, respectively.

For questions regarding the configuration steps in this section, contact Trellix Customer Support at https://www.trellix.com/en-us/support.html.

Important

You can integrate your Network Security appliance with Email Security - Cloud, but you must do so before using Email Security - Cloud. For instructions, see Integrating Your Network Security appliance with Email Security - Cloud.

Note

SIEM customers only must add the following IP addresses on any existing firewall and server allowlisting policies for SIEM notifications:

  • USA: 3.93.93.0/24, 34.223.36.0/24

  • USGOV: 15.200.32.0/24

  • EMEA: 3.123.5.0/24, 63.34.218.0/24

  • APJ: 3.112.99.0/24

  • CA: 3.97.207.0/24, 3.97.208.0/24