Protecting email content and attachments

Prev Next

Email protection rules monitor or block email sent to specific destinations or users. They are supported on Trellix DLP Endpoint - SaaS for Windows, Trellix DLP Endpoint – SaaS for Mac (supports monitoring emails only), Trellix DLP Network Monitor – SaaS, Trellix DLP Network Prevent – SaaS, and Skyhigh Security Cloud.

Email protection rules can block emails according to the following parameters:

  • Classification definitions limit the rule to specific content fingerprinting or content classification criteria. You can apply classifications to the whole email, or just the subject, body, email headers, or attachments.

    the one of the email elements option does not include email headers other than subject for email protection rules used by the Trellix DLP Network - SaaS appliances. You must add other email headers separately.

  • Sender definitions limit the rule to specific user groups or email address lists. User group information can be obtained from registered LDAP servers. You can also limit the rule to local or non-LDAP users.

  • The Email Envelope field specifies the email is protected by RMS permissions, PGP encryption, digital signature, or S/MIME encryption. This option is typically used to define exceptions.

    Note

    When the envelope is S/MIME and there is no S/MIME certificate for the recipient, the Outlook pop up allowing the email to be sent unencrypted appears. But, if there is a matching rule to block the email, Trellix DLP Network Prevent – SaaS blocks the email.

  • The Recipient list includes email address list definitions. The definitions can use wildcards in the operator field.

Messages that cannot be analyzed

If Trellix DLP Network Prevent – SaaS is unable to extract text from a message to analyze it because, for example, the message is corrupt, it takes the following action:

  • Rejects the email and returns it to the MTA.

  • The MTA keeps trying to deliver the message to Trellix DLP Network Prevent – SaaS .

  • When Trellix DLP Network Prevent – SaaS identifies that it cannot analyze the message, it adds the X-RCIS-Action header with the SCANFAIL value to the message.

  • Trellix DLP Network Prevent – SaaS sends the message with the modified X-RCIS-Action header to one of the configured smart hosts.

    Note

    Trellix DLP Network Prevent – SaaS makes no other change to the message.

If the message contains an encrypted, corrupt, or password-protected attachment, the message is analyzed for data loss triggers, but the attachment is not analyzed. The SCANFAIL value is not added because the message contents were partially analyzed.