Trellix DLP Network Prevent Custom header behavior

Prev Next

When configuring an Email Protection rule reaction, in addition to the basic rule reactions — No Action and Add header X-RCIS Action, you can optionally choose to add custom headers in the delivered email message. The custom header can report details about the rules that violated a policy, or any other custom header value when a rule is triggered.

During an email message delivery, Trellix DLP Network Prevent includes the basic rule reaction and the custom header values and sends the scanned email to the Smart Host. The Smart Host implements the action that is indicated in these reactions. The basic rule reactions take precedence in priority over the custom header values.

Trellix DLP Network Prevent allows you to use three built-in custom headers and one of the defined custom headers. To create a custom header definition, use DLP Policy ManagerDefintions and set the priority for the custom header definition.

Trellix DLP Network Prevent supports these built-in custom headers and are selected by default:

Built-in custom headers

Custom headers

Indicates

X-Rules-Matched-Count

Shows the total number of rules that matched the policy violation.

X-Cumulative-Score

Shows the cumulative score of all rules that matched the policy violation.

Scores are calculated based on the rule severity: High=4, Medium=3, Low=2, and Info=1. For example, if a message violates three rules, one with a severity of medium and two with a severity of low, the custom header: X-Cumulative-Score: 5 is included in the email header.

X-Strictest-Action

Shows the strictest rule of all rules that matched the policy violation.



When more than one rule is triggered for an email, the rule's action with highest severity is used in the custom header response. This is determined by the rule priority based on the rule severity and action priority. If custom headers are configured in two Email Protection rules with conflicting values and if both rules are triggered for the same email, the prioritization is computed based on rule severity, standard built-in action priority, and custom header priority to decide which rule-specific custom header is added to the email. Example of conflicting rules: Rule 1 custom-header="PCI" and Rule2 custom-header="SSN".