Configuring Inline with Hygiene mode

Prev Next

Inline with Hygiene mode, or Hygiene analysis uses MVX active (inline) analysis of incoming emails to identify spam, malware, and advanced threats. Malicious email is blocked and impersonation protection is enabled. For more information about impersonation protection, see Message analysis policies. Inline with Hygiene mode is sometimes referred to as Hygiene mode in this guide.

To enable outbound email scanning, you need to configure your existing inbound domain with outbound policies. Refer to Configuring outbound mail flow for the process.

Important

Failure to properly complete the following steps may result in disruption of message deliveries or loss of messages.

To configure Inline with Hygiene mode:

  1. Configure your firewall to allow incoming TCP traffic on port 25 to your MTA from the following IP addresses, depending on the Email Security — Cloud region of your account.

    Note for multi-domain tenants with outbound scanning: If your Email Security - Cloud tenant hosts multiple associated domains and you have enabled Outbound Email Scanning, you must include both the Inbound and Outbound Trellix IP ranges in this list.

    When an email is sent from one domain to another within the same tenant (e.g., Domain A to Domain B), Email Security - Cloud processes the outbound message and routes it back to O365 via its outbound delivery IPs. If this connector only includes Inbound IPs, internal messages between your domains will be rejected.

    Email Security - Cloud region

    IP addresses

    USA

    34.223.36.0/24

    3.93.93.0/24

    Required for Outbound Users:

    34.223.9.0/24

    34.223.11.128/25

    34.223.12.0/25

    100.25.99.0/25

    100.24.127.128/25

    EMEA

    3.123.5.0/24

    63.34.218.0/24

    Required for Outbound Users:

    34.223.9.0/24

    34.223.11.128/25

    34.223.12.0/25

    100.25.99.0/25

    100.24.127.128/25

    APJ

    3.112.99.0/24

    3.112.100.0/24

    Required for Outbound Users:

    34.223.9.0/24

    34.223.11.128/25

    34.223.12.0/25

    100.25.99.0/25

    100.24.127.128/25

    USGOV

    15.200.32.0/24

    CA

    3.97.207.0/24

  2. Disable any SPF, DKIM, DMARC, RBL, DHAP, and PTR record checks, GeoIP checks, antispam engines, antivirus engine, and mail throttling rules for messages received from the IP addresses mentioned in step 1, depending on the Email Security — Cloud region of your account.

  3. Allowlist any traffic originating from the following IP addresses mentioned in step 1, depending on the Email Security — Cloud region of your account.

  4. Change your domain MX records to the following, depending on the Email Security — Cloud region of your account:

    US A records (all 4 entries are required):

    • primary.us.email.fireeyecloud.com (priority 10)

    • alt1.us.email.fireeyecloud.com (priority 20)

    • alt2.us.email.fireeyecloud.com (priority 30)

    • alt3.us.email.fireeyecloud.com (priority 40)

    USGOV A records (all 4 entries are required):

    • primary.us.etp.fireeyegov.com (priority 10)

    • alt1.us.etp.fireeyegov.com (priority 20)

    • alt2.us.etp.fireeyegov.com (priority 30)

    • alt3.us.etp.fireeyegov.com (priority 40)

    EMEA A records (all 4 entries are required):

    • primary.emea.email.fireeyecloud.com (priority 10)

    • alt1.emea.email.fireeyecloud.com (priority 20)

    • alt2.emea.email.fireeyecloud.com (priority 30)

    • alt3.emea.email.fireeyecloud.com(priority 40)

    APJ A records (all 4 entries are required):

    • primary.ap.email.fireeyecloud.com (priority 10)

    • alt1.ap.email.fireeyecloud.com(priority 20)

    • alt2.ap.email.fireeyecloud.com (priority 30)

    • alt3.ap.email.fireeyecloud.com (priority 40)

    CA A records (all 4 entries are required):

    • primary.ca.email.fireeyecloud.com

    • alt1.ca.email.fireeyecloud.com

    • alt2.ca.email.fireeyecloud.com

    • alt3.ca.email.fireeyecloud.com

  5. In the Email Security - Cloud Web portal, create an email routing policy for a domain using the instructions in Email routing configuration policies.

  6. In the Email Security - Cloud Web portal, provision a domain using the instructions in Configuring domains.

  7. In the Email Security - Cloud Web portal, create a message analysis policy for the domain using the instructions in Configuring message analysis policy settings.