Trellix DLP Network Prevent enables you to actively block an email message and return the message to the sender with a notification when there is a policy violation.
You can configure Trellix DLP Network Prevent to block an email that violates policy and send a notification to the configured Smart Host.
The Smart Host returns the original email to the sender as an attachment to a notification. An additional details file in HTML format is also attached to this notification. This additional details file includes information about the incident type, severity level, blocked status, date and time about when the incident occurred, sender, and recipient details. The file also shows the evidence details, rules that triggered the incident, and the classification details.
Important
The block and return email to sender reaction always takes priority over the add X-RCIS-Action header reaction.
You can choose the predefined User Notification definition as the notification message or create a customized notification using the placeholder values in the User Notification definition page. You can also choose to send an incident about the bounced message.
If the notification email delivery to the sender fails due to a temporary failure code (4xx), the incident is not generated. The original mail remains in the temporary failed state and is queued on the sending Smart Host. The Smart Host retries sending the email message.
If the notification email delivery to the sender is rejected due to a permanent error (5xx), an incident is generated. The original mail gets rejected with the 5xx error code.
Note
When a notification email delivery fails because of 5xx error code, the original email message from the sender gets blocked. The email message is not returned to the sender and the Incident Manager shows this email message as blocked.