You can take several actions on the email messages that are sent to the Smart Host. You can use the Add header to X-RCIS-Action reaction to add values to the email message headers. The Smart Host implements the action that is indicated in the X-RCIS-Action header.
Priority | Value | Indicates |
|---|---|---|
1 | BYPASS | Added to messages that are bypassed from scanning. |
2 | SCANFAIL | Messages that cannot be analyzed. The appliance generates the SCANFAIL header value automatically. So the header value cannot be configured as an action within a rule. |
3 | BLOCK | Blocks the message. |
4 | QUART | Quarantines the message. |
5 | ENCRYPT | Encrypts the message. |
6 | BOUNCE | Issues a Non-Delivery Receipt (NDR) message to the sender. |
7 | REDIR | Redirects the message. |
8 | NOTIFY | Notifies supervisory staff. |
9 | ALLOW | Allows the message through. The Allow value is added automatically to all messages that do not contain any matched contents. |
When not monitoring, Trellix DLP Network Prevent always delivers an email to a configured Smart Host. The Smart Host implements the action that is indicated in the X-RCIS-Action header.
If the message triggers multiple rules, the highest priority value is inserted into the X-RCIS-Action header (where 1 is the highest priority). If no rules are triggered, the ALLOW value is inserted.
If another appliance analyzes a message and adds an X-RCIS header, Trellix DLP Network Prevent replaces the existing header with its own header.
Adding BYPASS value to the X-RCIS-Action header
You can configure Trellix DLP Network to bypass scanning of emails sent from the specified email addresses. To these bypassed emails, you can choose to add the BYPASS value to the X-RCIS-Action header or not add a header in the message sent to the configured Smart Host.