Outbound messages are blocked if they contain the word Confidential, unless the recipient is exempt from the rule.
Email contents | Recipient | Expected result |
|---|---|---|
Body: Confidential | external_user@external.com | The message is blocked because it contains the word Confidential. |
Body: Confidential | internal_user@example.com | The message is not blocked because the exception settings mean that confidential material can be sent to people at example.com. |
Body: Attachment: Confidential | external_user@external.com internal_user@example.com | The message is blocked because one of the recipients is not allowed to receive it. |
Create an email address list definition for a domain that is exempt from the rule.
In the Data Protection section in ePO - SaaS, select DLP Policy Manager and click Definitions.
Select the Email Address List definition and create a duplicate copy of the built-in My organization email domain.
Select the email address list definition you created, and click Edit.
In Operator, select Domain name is and set the value to
example.com.Click Save.
Create a rule set with an Email Protection rule.
Click Rule Sets, then select Actions → New Rule Set.
Name the rule set
Block Confidential in email.Create a duplicate copy of the built-in Confidential classification.
An editable copy of the classification appears.
Click Actions → New Rule → Email Protection Rule.
Name the new rule Block Confidential and enable it.
Enforce the rule on Trellix DLP Endpoint for Windows.
Select the classification you created and add it to the rule.
Set the Recipient to any recipient (ALL).
Leave the other settings on the Condition tab with the default settings.
Add exceptions to the rule.
Click Exceptions, then select Actions → Add Rule Exception.
Type a name for the exception and enable it.
Set the classification to Confidential.
Set Recipient to at least one recipient belongs to all groups (AND), then select the email address list definition you created.
Configure the reaction to messages that contain the word Confidential.
Click Reaction.
Set the Action to Block for computers connected to and disconnected from the corporate network.
Save and apply the policy.