Use case: Block email message and return to the sender

Prev Next

Outbound email messages are blocked if they contain the word Confidential. The email message is not sent to the recipient from the Smart Host. A notification mail with the original email as an attachment is sent back to the sender. You can choose a predefined user notification or customize the definition. In addition, more details about the blocked email message are attached to the notification in HTML file format.

  1. Create a rule set with an Email Protection rule.

    1. In ePO - SaaS, select Data ProtectionDLP Policy Manager.

    2. Click Rule Sets, then select ActionsNew Rule Set.

    3. Name the rule set Block email and return to sender.

    4. Create a duplicate copy of the in-built Confidential classification.

      An editable copy of the classification appears.

    5. Click ActionsNew RuleEmail Protection Rule.

    6. Name the new rule Bounce email and enable it.

    7. Enforce the rule on DLP Network Prevent.

    8. Select the classification you created and add it to the rule.

      Leave the other settings on the Condition tab with the default settings.

  2. Configure the reaction to messages that contain the word Confidential.

    1. Click Reaction.

    2. In DLP Network Prevent, select ActionsBlock and return email to sender.

    3. Select the notification that has to be sent from User Notification.

  3. (Optional) To report an incident, about the bounced email message, select the Report Incident checkbox. To save the evidence, select the Store original email as evidence checkbox.

  4. Save and apply the policy.

  5. Set the sender email address for the bounced email messages.

    1. Open the Policy Catalog.

    2. Select the DLP Appliance Management product, select the Trellix DLP Network Prevent Email Settings category, and open the policy that you want to edit.

    3. Specify the sender email address in the Bounce Messages Sender field. It must be a generic email address.

    4. Click Save.