Trellix DLP Network Prevent – SaaS X-RCIS-Action header behavior

Prev Next

You can take several actions on the email messages that are sent to the Smart Host. You can use the Add header to X-RCIS-Action reaction to add values to the email message headers. The Smart Host implements the action that is indicated in the X-RCIS-Action header.

X-RCIS-Action header values

Priority

Value

Indicates

1

BYPASS

Added to messages that are bypassed from scanning.

2

SCANFAIL

Messages that cannot be analyzed. The appliance generates the SCANFAIL header value automatically. So the header value cannot be configured as an action within a rule.

3

BLOCK

Blocks the message.

4

QUART

Quarantines the message.

5

ENCRYPT

Encrypts the message.

6

BOUNCE

Issues a Non-Delivery Receipt (NDR) message to the sender.

7

REDIR

Redirects the message.

8

NOTIFY

Notifies supervisory staff.

9

ALLOW

Allows the message through. The Allow value is added automatically to all messages that do not contain any matched contents.



When not monitoring, Trellix DLP Network Prevent – SaaS always delivers an email to a configured Smart Host. The Smart Host implements the action that is indicated in the X-RCIS-Action header.

If the message triggers multiple rules, the highest priority value is inserted into the X-RCIS-Action header (where 1 is the highest priority). If no rules are triggered, the ALLOW value is inserted.

If another appliance analyzes a message and adds an X-RCIS header, Trellix DLP Network Prevent – SaaS replaces the existing header with its own header.

Adding BYPASS value to the X-RCIS-Action header

You can configure Trellix DLP Network - SaaS to bypass scanning of emails sent from the specified email addresses. To these bypassed emails, you can choose to add the BYPASS value to the X-RCIS-Action header or not add a header in the message sent to the configured Smart Host.