Use case: Add custom headers to email messages

Prev Next

You can choose to add custom header values to an email message. Trellix DLP Network Prevent allows you to add three built-in custom headers and an additional custom header with the basic rule reactions when a policy is violated. The custom headers can report the number of rules and the cumulative score of all rules that violated a policy, or any other custom header value in the delivered email message.

  1. Create a custom header definition:

    1. In ePO - On-prem, open Data ProtectionDLP Policy Manager.

    2. Select Definitions and in the Others category, click Custom Header.

    3. Click ActionsNew Item.

    4. In the New Custom Header Details page, enter the custom header name and header value.

      The custom header name and value must be entered using ASCII values and must not contain space or colon(:). The priority of the custom header is shown in the top-down order. Click the up arrow and down arrow to change the priority.

    5. Click Save.

  2. Create a rule set or modify an existing rule set:

    • Click ActionsNew Rule Set and enter the details to create the rule set. Click the rule set.

      OR

    • Click the existing rule set to modify the rule set.

    The DLP Rule Set page opens.

  3. Create a rule or modify an existing rule:

    • In the DLP Rule SetData Protection page, click ActionsNew Rule Email Protection to create a rule.

      OR

    • Click the existing rule to modify the rule.

  4. Add custom headers to a rule reaction:

    1. In the Email Protection rule page, enter the rule details, enable or disable the rule, and set the rule severity.

    2. Set the conditions and exceptions for the rule.

    3. Select the Reaction tab.

    4. In the Trellix DLP Network Prevent section, set the Action to No Action or Add header X-RCIS Action.

    5. (Optional) Configure the custom header using the Add Custom Header field. Click the three dots menu to select the custom header from the set of custom header definitions you created in Step 1. You can choose to add one custom header and the built-in custom headers for a rule. The built-in custom headers are enabled by default.

    6. Select Report Incident.

    7. Save the rule and click Close.

  5. Assign the rule set to a policy and apply the policy for the changes to become effective immediately:

    1. In the DLP Policy Manager, select Policy Assignment.

      Note

      Pending Changes are shown as Yes.

    2. Select ActionsAssign Rule Sets to a policy.

    3. Select the rule set you created.

    4. Select ActionsApply Selected Policies.

    5. Click Apply policy.

      Pending Changes are now shown as No.