Email Protection rule page

Prev Next

Email protection rules block email sent to specific destinations or users.

Option definitions

Category

Option

Definition

Rule options tab

Rule name

Enter a unique name for the rule. This field is required.

Description

Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional.

State

Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting ActionsChange State. The default is Disabled.

Severity

A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field.

Enforce on

Selects the Trellix DLP products that enforce the rule. This rule type is supported on Trellix DLP Endpoint for Windows, McAfee Network DLP, and Cloud DLP.

Note

Selecting McAfee Network DLP makes the rule available to Trellix DLP Network Monitor and Trellix DLP Network Prevent.

Condition tab

Classification

Classifications can be limited to a specific email element (headers, subject, body, attachment) or apply to all elements. The selected elements can contain one or all classifications.

The one of the email elements classification also includes a contains any data (ALL) option which means you do not need to name a classification.

You can select multiple classifications, or use the + icon to add additional classifications.

Note

The option one of the email elements does not include email headers other than subject to email protection rules used by Trellix DLP Network. You must add other email headers separately.

Using classification grouping — When you include multiple classifications in a rule, you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. When more than two rows of conditions are included, a toggle button appears. Click the toggle button to enable custom classification grouping and type the custom classification grouping expression. For example, if classifications 1, 2, and 3 are included in a Classification condition, you can build an expression similar to ((1 AND 2) OR (1 AND 3)).

The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. A classification grouping expression must include all classification item numbers.

Sender

Select a sender from the drop-down list. Senders can be selected from end-user groups or email lists or can be local or non-LDAP users. Using the + icon, you can select multiple senders using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups.

Email Envelope

Specifies the encryption or other protection.

Recipient list includes

Use this option to block mail to specified recipients, using email address list definitions. On the Exceptions tab, specified recipients are excluded from a blocking rule.

Exceptions tab

Note

The Exceptions tab is optional.

Actions

Adds or deletes a rule exception.

Name

Enter a unique name for the exception. This field is required.

Description

Optional descriptive text.

State

Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state.

Classification

Select a classification. See above for option details. The exception classification is independent of the rule classification.

Using classification grouping — When you include multiple classifications in an exception, you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. When more than two rows of classifications are included, a toggle field appears. Click the toggle button to enable custom classification grouping and type the custom classification grouping expression. For example, if classifications 1, 2, and 3 are included in Classification, you can build an expression similar to ((1 AND 2) OR (1 AND 3)).

The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and expressions are computed from left to right. A classification grouping expression must include all classification item numbers.

Sender

Select a sender from the drop-down list. See above for option details. The exception sender is independent from the rule sender.

Email Envelope

Specifies the encryption or other protection. The exception email envelope is independent from the rule email envelope.

Recipient list includes

Specifies the recipient list. See above for option details. The exception recipient list is independent from the rule recipient list.

ReactionTrellix DLP Endpoint

Data protection and device protection rules have a granular Action definition. You can define different actions for the following:

  • Computer connected to corporate network

  • Computer disconnected from the corporate network

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

For a list of actions for different types of rules, see the available reactions table.

When the computer is disconnected from the network, the default is React the same way as connected system. Selecting another option displays the notification and reporting options.

User Notification

User notification definitions are stored in the DLP Policy category in the Policy Catalog. Select a predefined definition, or click New Item to create one.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.

Store original email as evidence

Select to store the original email as evidence. If the hit highlighting option is enabled for the evidence server, the trigger text is highlighted and stored as a separate file.

ReactionTrellix DLP Network Prevent

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

For a list of actions for different types of rules, see the available reactions table.

  • Selecting Block and return email to sender blocks the email that violates the policy and returns the original email to the sender as an attachment to a notification. An additional details file in HTML format is also attached to this notification. You can choose a predefined User Notification definition or create a custom notification.

  • Selecting Add header X-RCIS-Action displays the Value drop-down list for action options.

    The actions are scan fail, block, quarantine, encrypt, bounce, redirect, notify, and allow.

  • (Optional) Selecting the definition for Add Custom Header includes custom header in the delivered email message. You can also choose the values from the built-in custom header definitions.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.

Store original email as evidence

Select to store the original email as evidence. If the hit highlighting option is enabled for the evidence server, the trigger text is highlighted and stored as a separate file.

ReactionTrellix DLP Network Monitor

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.

Store original email as evidence

Select to store the original email as evidence. If the hit highlighting option is enabled for the evidence server, the trigger text is highlighted and stored as a separate file.

ReactionSkyhigh Cloud DLP

Note

You can set the action separately for Skyhigh Cloud DLP configured as inline protection (able to block) and Skyhigh Cloud DLP configured as passive protection (only monitoring and no blocking).

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.

Store classification match files

Select to store the classification matches that trigger the rule.