How Trellix DLP Network Prevent protects email traffic

Prev Next

Trellix DLP Network Prevent integrates with any MTA that supports header inspection. It analyzes the email messages and applies Trellix DLP policies.

  1. Users — Incoming or outgoing email messages go to the MTA server.

  2. MTA server — Forwards the email messages to Trellix DLP Network Prevent

  3. Trellix DLP Network Prevent — Receives SMTP connections from the MTA server and:

    • Decomposes the email message into its component parts

    • Extracts the text for fingerprinting and rule analysis

    • Analyzes the email message to detect policy violations

    • Based on the rule that is set, Trellix DLP Network Prevent takes one of these actions:

      • Blocks the email message and sends a notification to the Smart Host (MTA server).

      • Adds an X-RCIS-Action header and sends the message to the configured Smart Host (MTA server).

      • Adds custom headers to the delivered email message when a rule is triggered. The scanned email is sent to the configured Smart Host (MTA server) to classify the email and take appropriate action. The custom header can report the number of rules and the cumulative score of all rules that violated a policy, or any other custom definition.

      Note

      In this example, the configured Smart Host is the original MTA.

  4. MTA server — Forwards the email message to intended recipient or returns the email message:

    1. When the email message is blocked, Smart Host (MTA server) returns the email message to the sender as an attachment with a notification. Optionally, you can configure to send an incident to ePO - On-prem.

    2. When an X-RCIS-Action header is added, based on the information it gets from the X-RCIS-Action header, the Smart Host (MTA server) acts on the email message. Optionally, you can configure to send an incident to ePO - On-prem.

    3. (Optional) When a custom header is configured, Trellix DLP Network Prevent includes the defined custom header values and the basic rule reaction (X-RCIS-Action header or No Action), and sends the scanned email to the Smart Host (MTA server) to classify the email and take appropriate action.

      Note

      This does not change the product behavior with respect to the detection of SMTP headers by Trellix DLP Network Prevent.

  5. Registered documents server — It is a way to define sensitive information, to protect it from being distributed in unauthorized ways.

Trellix DLP Network Prevent email traffic flow
Trellix DLP Network Prevent email traffic flow