Trellix DLP Network Prevent Email Settings

Prev Next

Disable SMTP scanning, add permitted hosts and more MTAs, bypass scanning emails sent from the specified email addresses, and specify Transport Layer Security (TLS) settings.

Tip

To stop the appliance being an open relay, specify permitted hosts that can receive email. At times of heavy email traffic, having more than one Smart Host can help to distribute the load.

In ePO - On-prem, open the Policy Catalog. Select the DLP Appliance Management product, choose the Trellix DLP Network Prevent Email Settings category, and open the policy you want to edit.

Option definitions

Option

Definition

Apply Policy

By default, Allow Policy Push is enabled. Deselecting Allow Policy Push doesn't apply the configuration or policy changes you have made and this allows you to review the changes. After reviewing the configuration or policy changes, select Allow Policy Push.

SMTP

  • Enable SMTP — Enabled by default. Allows SMTP communication over port 25. You can disable this option on appliances dedicated to analyzing ICAP traffic.

  • Enable Authenticated Mail Submission (Uses SMTP AUTH over TLS on port 587) — Disabled by default. Allows authenticated email submission over port 587. You can disable this option on appliances dedicated to analyzing ICAP traffic.

Connection Settings

  • Onward connection — The maximum time, in seconds, that Trellix DLP Network Prevent waits to establish a connection with an MTA.

  • Onward delivery — The maximum time, in seconds, that Trellix DLP Network Prevent waits for the final dot to be acknowledged when it delivers an email message.

  • Between SMTP commands — The maximum time, in seconds, that Trellix DLP Network Prevent waits between two SMTP commands.

Bounce Messages Sender

Specify the sender email address for a bounced email message.

Smart Hosts

  • Round-robinTrellix DLP Network Prevent delivers messages to the list of MTAs using a round-robin approach.

  • Host — Add details of the MTAs that you want to use to deliver messages. Trellix DLP Network Prevent tries to deliver the messages to the MTAs from the top to the bottom of the list. Use the arrows to set the priority.

Permitted Hosts

  • Accept mail from any hostTrellix DLP Network Prevent accepts messages from any computer.

  • Accept mail from these hosts only — When selected, you can type the details of permitted hosts that Trellix DLP Network Prevent can receive messages from. Enter the details of the host using its IP address with subnet, domain name, or wildcard domain name.

You can create groups of permitted hosts using subnets or wildcard domains. To add more than one subnet, you must create separate entries for each.

DLP Scan Bypass

  • Add header X-RCIS-Action (BYPASS)Trellix DLP Network Prevent appliance bypasses scanning of emails sent from the specified sender email addresses and adds a header in the message sent to the configured Smart Host.

  • No ActionTrellix DLP Network Prevent appliance bypasses scanning of emails sent from the specified sender email addresses and doesn't add a header in the message sent to the configured Smart Host.

  • Sender Email Address — Sender email address that you want to bypass from scanning. Use the is format to specify the actual email address. Use the matches format to specify multiple email addresses using *@domain_name.com.

Transport Layer Security

  • Inbound communication

    • Always — Rejects email from the sending MTA if their communication does not try to start encryption.

    • Never — Connections to Trellix DLP Network Prevent never use TLS encryption.

    • Opportunistic — This is the default setting. If available, the connection uses TLS encryption.

  • Outbound communication

    • Always — Always use TLS to send messages.

      If the Smart Host is not configured with TLS, Trellix DLP Network Prevent sends a 550 (Denied by policy. TLS conversation required) error message.

    • Never — Connections to the Smart Host never use TLS encryption.

    • Opportunistic — This is the default setting. If available, the connection uses TLS encryption.