To configure Outbound Inline with Hygiene mode:
Step 1: Update the SPF record
For messages leaving the Email Security - Cloud outbound infrastructure to have high reputation, you must update the SPF record of the sending domain to contain the list of authorized senders' IP addresses.
Depending on the geographic region of your Email Security - Cloud account, add the following to your SPF records:
Email Security - Cloud region | SPF record | Example SPF record |
|---|---|---|
USA | _spf.fireeyecloud.com | v=spf1 include:_spf.fireeyecloud.com -all |
EMEA | ||
APJ | ||
USGOV | _spf.fireeyegov.com | v=spf1 include:_spf.fireeyecloud.com -all |
CA | _spf.fireeyecloud.com | v=spf1 include:_spf.fireeyecloud.com -all |
For more information, see the SPF documentation online.
Step 2: Configure policies and domains in the Email Security — Cloud Web UI
This step includes 4 sub-steps:
Important
The following message appears in the Create Policy page before you create an outbound message analysis or email routing configuration policy: Creation of outbound scanning policies, and associating those to domains will enable outbound scanning of emails. You acknowledge that such scans may from time to time result in quarantining or blocking of outbound emails. Completing the following steps indicates you acknowledge this statement.
Step 2a: Configure a message analysis policy
In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.
Click Create Policy.
Select Outbound for Traffic Type.
Select Message Analysis for Rule Type.
Enter a policy name and description (optional) and click Create.
The policy configuration page appears. Several configuration fields, including Hygiene Settings and Rate Limit Settings, are auto-populated based on the size of your organization. To adjust these settings, select Manage next to Configuration.
Important
Hygiene mode is the default mode for outbound policies.
Step 2b: Configure an email routing configuration policy
In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.
Click Create Policy.
Select Outbound for Traffic Type.
Select Email Routing Configuration for Rule Type.
Enter a policy name and description (optional) and click Create.
The policy configuration page appears. Select Manage next to Email Routing Configuration.
Under Incoming Server Addresses, add the originating IP addresses for your messages.
Click Add.
Enter the originating IP address/subnets for your messages.
Click OK.
(Optional) Under Delivery Overrides, add next-hop destination servers where messages are delivered after the Email Security - Cloud hop. You can leverage third-party scanning solutions while also benefiting from Email Security - Cloud defenses. You can add A records, IP addresses, and MX records. Wildcard syntax is supported for each destination type. You can add multiple destinations for message delivery and determine the priority order under Delivery Overrides.
Caution
Email Security - Cloud cannot perform anti-spam/anti-virus scanning on emails after they are delivered to third-party tools.
Click Add. The Add Delivery Override Rule menu appears.
Enter recipient domains for mail delivery. To signify delivery to all domains in a destination (wildcard), enter an asterisk.
In the drop-down menu select what type of destination the recipient domains are associated with.
Enter destinations. Click OK.
Under Deliver TLS Rules, enter the domains that will have TLS rules enforced.
Click Manage next to Recipient Domains. The Manage Recipient Domains window appears.
Under Entries to Add, enter the domains that will have TLS rules enforced. (Optional) Use an asterisk to signify delivery to all domains is TLS enforced.
(Optional) Click Upload CSV to upload a CSV file from your local machine.
Click OK.
Caution
If an email is sent by your organization from an IP address that is not listed in an outbound email routing configuration policy, the message will be rejected.
In the policy configuration page, click Save. Allow up to 5 minutes for your changes to appear.
Step 2c: Add and configure an Inbound domain for outbound use
Important
You must provision a domain through inbound mode before enabling it for outbound use. However, you are not required to have inbound mail flow configured and enabled to provision a domain and set up outbound functionality.
In the Email Security - Cloud Web UI, click Configuration > Domains.
In the top right corner, click Provision Domains.
In the Domain Mode section, select Inline with Hygiene.
In the Add Domains section, enter the domain(s) you want to use for outbound mail.
In the Domain Connection Settings section, select the Email Routing Policy you configured in Step 1b.
In the list of domains and domain groups, select the domain you want to use for outbound mail.
Configure the incoming and outgoing server addresses.
Click Save.
Open the Configuration > Domains page and select the domain you created.
The domain configuration page appears. Under Policies - Outbound, click Manage next to Message Analysis Policy.
In the configuration page, click Change to open the list of available message analysis policies.
Select the message analysis policy you configured in Step 1a and click OK.
Step 2d: Generate a domain identification token
Unique domain identification tokens are used to verify and secure your sender identity when sending outbound messages.
Open the configuration page of the domain you selected for outbound use.
Under Policies - Outbound, click Generate Token. A unique, randomized identification token is generated.
Click Copy to copy the full identification token to your clipboard.
Important
You must include the domain identification token in the header of emails you want to send.
For example:
X-ETP-DOMAIN-AUTH-TOKEN: <identification-token>Outbound messages that do not include a domain identification token in the header are rejected by Email Security - Cloud.
Step 3: Create the Inbound gateway rule in Gmail
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-4 of "Set up an inbound gateway" in the Google documentation.
For step 5, enter the following configuration settings:
Under Gateway IPs, click Add.
Depending on the geographic region of your Email Security - Cloud account, enter the following IP addresses:
Email Security - Cloud region
IP addresses
USA
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
EMEA
52.215.218.128/25
63.34.31.0/25
3.122.63.0/25
3.122.63.128/25
APJ
3.112.100.0/24
USGOV
15.200.33.0/24
CA
3.97.208.0/24
Click Save.
Note
If your geographic region has multiple IP ranges, you must repeat steps 3a through 3c for each individual IP range. For example, EMEA users must complete these steps four times while APJ users must only complete these steps once.
Verify that the Automatically detect external IP option is unchecked.
Verify that the Reject all mail not from gateway IPs option is unchecked.
Note
If Reject all mail not from gateway IPs is selected, internal mail delivery will be disrupted.
Verify that the Require TLS for connections from the email gateways listed above option is unchecked.
Click Save.
Step 3a (Optional): Add Google IP ranges to inbound gateway rule
Important
This section contains advanced configuration. Read the entire section before attempting implementation.
This step is available for administrators who want to enable Gmail to only accept emails from Email Security - Cloud. As mentioned in Step 3e in the previous section, enabling the Reject all mail not from gateway IPs option stops the delivery of internal mail. Following the instructions in this section enables administrators to select that option and ensure that only email that passes through Email Security - Cloud is delivered to recipient mailboxes.
Caution
If you choose to perform this optional step, you are responsible for maintaining the IP addresses in this rule. Trellix accepts no responsibility for internal email delivery issues related to IP address mismatches that might occur when Google updates the sending IP addresses used for mail delivery.
Using a DNS client, recursively look up all MX records for google.com.
Important
The MX records may change and you are responsible for maintaining and resolving any changes to the IP ranges that are added to your Inbound Gateway Rule.
Add the Google SPF records to the Inbound Gateway rule created in Step 2: Create the Inbound gateway rule in Gmail.
Important
You must enter the IPv6 addresses, even if you do not use IPv6. Google uses IPv6 addresses internally for routing.
Step 4: Create the Email Security - Cloud outbound host in Gmail
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-3 under "Add a mail route for your domain" in the Google documentation.
For step 4, enter the following configuration settings:
For Name, enter Outbound ETP MX.
Under Specify email server, select Single host.
Depending on the geographic region of your Email Security - Cloud, enter the following MX record in the Enter host name or IP entry box:
Email Security - Cloud region
MX record
USA
mx.us.email-out.fireeyecloud.com
EMEA
mx.emea.email-out.fireeyecloud.com
APJ
mx.ap.email-out.fireeyecloud.com
USGOV
mx.us.email-out.fireeyegov.com
CA
mx.ca.email-out.fireeyecloud.com
For the port, enter 25.
Verify that the Perform MX lookup on host option is selected.
Verify that the Require mail to be transmitted via a secure (TLS) connection option is selected.
Verify that the Require CA signed certificate option is selected.
Click Save.
Step 5: Create individual routing rules in Gmail for each domain
Important
You must repeat this step for each individual domain in your organization.
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-4 under "Add a routing setting" in the Google documentation.
For step 5, enter the following configuration settings:
For the description, enter Route outbound traffic to ETP.
Under Email messages to affect, select Outbound.
Under For the above types of messages, do the following, ensure that Modify message is selected from the drop-down menu.
Under Headers:
Select Add custom headers.
Click Add.
Enter the domain identification key generated in Step 1d: Generate a domain identification token. For example,
X-ETP-DOMAIN-AUTH-TOKEN: <identification-token>.Click Save.
Under Route:
Select Change route.
Select Also reroute spam.
In the drop-down menu, select the Outbound ETP MX host created in Step 3: Create the Email Security - Cloud outbound host in Gmail.
Scroll to the bottom of the page and select Show options.
Under A. Address lists, verify that everything is unselected.
Under B. Account types to affect, verify that only Users is selected.
Under C. Envelope filter:
Select Only affect specific envelope senders.
In the drop-down menu, select Pattern match.
Under Regexp, enter regex that matches the domain name for which Email Security - Cloud Outbound has been enabled.
Verify Only affect specific envelope recipients is unselected.
Click Save.