Configuring Outbound Inline with Hygiene mode

Prev Next

To configure Outbound Inline with Hygiene mode:

Step 1: Update the SPF record

For messages leaving the Email Security - Cloud outbound infrastructure to have high reputation, you must update the SPF record of the sending domain to contain the list of authorized senders' IP addresses.

Depending on the geographic region of your Email Security - Cloud account, add the following to your SPF records:

Email Security - Cloud region

SPF record

Example SPF record

USA

_spf.fireeyecloud.com

v=spf1 include:_spf.fireeyecloud.com -all

EMEA

APJ

USGOV

_spf.fireeyegov.com

v=spf1 include:_spf.fireeyecloud.com -all

CA

_spf.fireeyecloud.com

v=spf1 include:_spf.fireeyecloud.com -all

For more information, see the SPF documentation online.

Step 2: Configure policies and domains in the Email Security — Cloud Web UI

This step includes 4 sub-steps:

Important

The following message appears in the Create Policy page before you create an outbound message analysis or email routing configuration policy: Creation of outbound scanning policies, and associating those to domains will enable outbound scanning of emails. You acknowledge that such scans may from time to time result in quarantining or blocking of outbound emails. Completing the following steps indicates you acknowledge this statement.

Step 2a: Configure a message analysis policy

  1. In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.

  2. Click Create Policy.

  3. Select Outbound for Traffic Type.

  4. Select Message Analysis for Rule Type.

  5. Enter a policy name and description (optional) and click Create.

  6. The policy configuration page appears. Several configuration fields, including Hygiene Settings and Rate Limit Settings, are auto-populated based on the size of your organization. To adjust these settings, select Manage next to Configuration.

    Important

    Hygiene mode is the default mode for outbound policies.

Step 2b: Configure an email routing configuration policy

  1. In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.

  2. Click Create Policy.

  3. Select Outbound for Traffic Type.

  4. Select Email Routing Configuration for Rule Type.

  5. Enter a policy name and description (optional) and click Create.

  6. The policy configuration page appears. Select Manage next to Email Routing Configuration.

  7. Under Incoming Server Addresses, add the originating IP addresses for your messages.

    1. Click Add.

    2. Enter the originating IP address/subnets for your messages.

    3. Click OK.

  8. (Optional) Under Delivery Overrides, add next-hop destination servers where messages are delivered after the Email Security - Cloud hop. You can leverage third-party scanning solutions while also benefiting from Email Security - Cloud defenses. You can add A records, IP addresses, and MX records. Wildcard syntax is supported for each destination type. You can add multiple destinations for message delivery and determine the priority order under Delivery Overrides.

    Caution

    Email Security - Cloud cannot perform anti-spam/anti-virus scanning on emails after they are delivered to third-party tools.

    1. Click Add. The Add Delivery Override Rule menu appears.

    2. Enter recipient domains for mail delivery. To signify delivery to all domains in a destination (wildcard), enter an asterisk.

    3. In the drop-down menu select what type of destination the recipient domains are associated with.

    4. Enter destinations. Click OK.

  9. Under Deliver TLS Rules, enter the domains that will have TLS rules enforced.

    1. Click Manage next to Recipient Domains. The Manage Recipient Domains window appears.

    2. Under Entries to Add, enter the domains that will have TLS rules enforced. (Optional) Use an asterisk to signify delivery to all domains is TLS enforced.

    3. (Optional) Click Upload CSV to upload a CSV file from your local machine.

    4. Click OK.

      Caution

      If an email is sent by your organization from an IP address that is not listed in an outbound email routing configuration policy, the message will be rejected.

  10. In the policy configuration page, click Save. Allow up to 5 minutes for your changes to appear.

Step 2c: Add and configure an Inbound domain for outbound use

Important

You must provision a domain through inbound mode before enabling it for outbound use. However, you are not required to have inbound mail flow configured and enabled to provision a domain and set up outbound functionality.

  1. In the Email Security - Cloud Web UI, click Configuration > Domains.

  2. In the top right corner, click Provision Domains.

  3. In the Domain Mode section, select Inline with Hygiene.

  4. In the Add Domains section, enter the domain(s) you want to use for outbound mail.

  5. In the Domain Connection Settings section, select the Email Routing Policy you configured in Step 1b.

  6. In the list of domains and domain groups, select the domain you want to use for outbound mail.

  7. Configure the incoming and outgoing server addresses.

  8. Click Save.

  9. Open the Configuration > Domains page and select the domain you created.

  10. The domain configuration page appears. Under Policies - Outbound, click Manage next to Message Analysis Policy.

  11. In the configuration page, click Change to open the list of available message analysis policies.

  12. Select the message analysis policy you configured in Step 1a and click OK.

Step 2d: Generate a domain identification token

Unique domain identification tokens are used to verify and secure your sender identity when sending outbound messages.

  1. Open the configuration page of the domain you selected for outbound use.

  2. Under Policies - Outbound, click Generate Token. A unique, randomized identification token is generated.

  3. Click Copy to copy the full identification token to your clipboard.

Important

You must include the domain identification token in the header of emails you want to send.

For example: X-ETP-DOMAIN-AUTH-TOKEN: <identification-token>

Outbound messages that do not include a domain identification token in the header are rejected by Email Security - Cloud.

Step 3: Create the Inbound gateway rule in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-4 of "Set up an inbound gateway" in the Google documentation.

  3. For step 5, enter the following configuration settings:

    1. Under Gateway IPs, click Add.

    2. Depending on the geographic region of your Email Security - Cloud account, enter the following IP addresses:

      Email Security - Cloud region

      IP addresses

      USA

      34.223.9.0/24

      34.223.11.128/25

      34.223.12.0/25

      100.25.99.0/25

      100.24.127.128/25

      EMEA

      52.215.218.128/25

      63.34.31.0/25

      3.122.63.0/25

      3.122.63.128/25

      APJ

      3.112.100.0/24

      USGOV

      15.200.33.0/24

      CA

      3.97.208.0/24

    3. Click Save.

      Note

      If your geographic region has multiple IP ranges, you must repeat steps 3a through 3c for each individual IP range. For example, EMEA users must complete these steps four times while APJ users must only complete these steps once.

    4. Verify that the Automatically detect external IP option is unchecked.

    5. Verify that the Reject all mail not from gateway IPs option is unchecked.

      Note

      If Reject all mail not from gateway IPs is selected, internal mail delivery will be disrupted.

    6. Verify that the Require TLS for connections from the email gateways listed above option is unchecked.

  4. Click Save.

Step 3a (Optional): Add Google IP ranges to inbound gateway rule

Important

This section contains advanced configuration. Read the entire section before attempting implementation.

This step is available for administrators who want to enable Gmail to only accept emails from Email Security - Cloud. As mentioned in Step 3e in the previous section, enabling the Reject all mail not from gateway IPs option stops the delivery of internal mail. Following the instructions in this section enables administrators to select that option and ensure that only email that passes through Email Security - Cloud is delivered to recipient mailboxes.

Caution

If you choose to perform this optional step, you are responsible for maintaining the IP addresses in this rule. Trellix accepts no responsibility for internal email delivery issues related to IP address mismatches that might occur when Google updates the sending IP addresses used for mail delivery.

  1. Using a DNS client, recursively look up all MX records for google.com.

    Important

    The MX records may change and you are responsible for maintaining and resolving any changes to the IP ranges that are added to your Inbound Gateway Rule.

  2. Add the Google SPF records to the Inbound Gateway rule created in Step 2: Create the Inbound gateway rule in Gmail.

    Important

    You must enter the IPv6 addresses, even if you do not use IPv6. Google uses IPv6 addresses internally for routing.

Step 4: Create the Email Security - Cloud outbound host in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-3 under "Add a mail route for your domain" in the Google documentation.

  3. For step 4, enter the following configuration settings:

    1. For Name, enter Outbound ETP MX.

    2. Under Specify email server, select Single host.

    3. Depending on the geographic region of your Email Security - Cloud, enter the following MX record in the Enter host name or IP entry box:

      Email Security - Cloud region

      MX record

      USA

      mx.us.email-out.fireeyecloud.com

      EMEA

      mx.emea.email-out.fireeyecloud.com

      APJ

      mx.ap.email-out.fireeyecloud.com

      USGOV

      mx.us.email-out.fireeyegov.com

      CA

      mx.ca.email-out.fireeyecloud.com

    4. For the port, enter 25.

    5. Verify that the Perform MX lookup on host option is selected.

    6. Verify that the Require mail to be transmitted via a secure (TLS) connection option is selected.

    7. Verify that the Require CA signed certificate option is selected.

  4. Click Save.

Step 5: Create individual routing rules in Gmail for each domain

Important

You must repeat this step for each individual domain in your organization.

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-4 under "Add a routing setting" in the Google documentation.

  3. For step 5, enter the following configuration settings:

    1. For the description, enter Route outbound traffic to ETP.

    2. Under Email messages to affect, select Outbound.

    3. Under For the above types of messages, do the following, ensure that Modify message is selected from the drop-down menu.

    4. Under Headers:

      1. Select Add custom headers.

      2. Click Add.

      3. Enter the domain identification key generated in Step 1d: Generate a domain identification token. For example, X-ETP-DOMAIN-AUTH-TOKEN: <identification-token>.

      4. Click Save.

    5. Under Route:

      1. Select Change route.

      2. Select Also reroute spam.

      3. In the drop-down menu, select the Outbound ETP MX host created in Step 3: Create the Email Security - Cloud outbound host in Gmail.

    6. Scroll to the bottom of the page and select Show options.

    7. Under A. Address lists, verify that everything is unselected.

    8. Under B. Account types to affect, verify that only Users is selected.

    9. Under C. Envelope filter:

      1. Select Only affect specific envelope senders.

      2. In the drop-down menu, select Pattern match.

      3. Under Regexp, enter regex that matches the domain name for which Email Security - Cloud Outbound has been enabled.

      4. Verify Only affect specific envelope recipients is unselected.

    10. Click Save.