Second Hop Hygiene is a variation of Inline mode. Cloud antispam/antivirus with analysis provides active (inline) analysis of incoming email to identify spam, malware, and advanced threats. Unlike Inline with Hygiene mode, it is not required for your domain MX records to point to Email Security — Cloud. Because Email Security — Cloud is the second hop in email delivery, SPF/DKIM/DMARC inspection, IP reputation block lists, and two second opinion spam engines are omitted from scanning. Other Hygiene features, including AV/AS, smart DNS detection, newsletter detection, CEO fraud detection, URL rewrite, and advanced threat detection are still available.
Important
You must have a hygiene license to configure Second Hop Hygiene mode.
An Inline with Hygiene license
To configure Second Hop Hygiene mode:
In the Email Security — Cloud Web portal, provision your domains in inline mode. See Provisioning domains for more information.
In the Email Security — Cloud Web portal, create an email routing policy for your inline domains using the instructions in Email routing configuration policies.
For Incoming Server Address, enter your gateway MTA that will send traffic to Email Security — Cloud.
For Outgoing Server Address, enter your downstream mail server.
In the Email Security — Cloud Web portal, create a message analysis policy for your inline domains. See Configuring message analysis policy settings for more information.
Under Hygiene Settings, enable Inline Spam Analysis.
Under Hygiene Settings, enable Inline Virus Analysis.
Select whether flagged impersonation attempts are reported as Spam or as Advanced Threats. By default, impersonation alerts are reported as spam.
Begin routing traffic to Email Security — Cloud.