Recipient Domain Threshold allows you to specify the number of domains that are allowed in the To, Cc, and Bcc list. You can set this value when you configure an Email Protection rule to allow emails for a specific domain and block the other domains listed in the To, Cc, and Bcc list. This makes sure that information meant for specific domains is not exposed to other external domains.
In Trellix ePO - On-prem, go to Menu → Data Protection → DLP Policy Manager.
Set the recipient domain threshold limit.
Click the Definitions tab.
In Source/Destination, select Recipient Domain Threshold.
Click Actions → New Item.
Enter a name and optional description.
In Available properties, click Domains to be excluded.
Select equals to, then click the three-dots menu to select the domain names that need to be excluded.
Note
You can create the domain definitions in Definitions → Email Address List.
In Available properties, click Threshold*, then click + to add the threshold value for To, Cc, and Bcc.
Click Save.
Configure the Email Protection rule.
In the Rule Sets tab, create a rule set. For more information, see Create a rule set.
Open the created rule set, then in the Data protection tab, select Actions → New Rule → Email Protection.
Enter a name for the rule and select State → Enabled.
On the Conditions tab, for Recipient Domain Threshold, select equals to to select the threshold definition created in step 2.
Click the three-dots menu to select the email threshold criteria created in step 2.
Provide the other conditions and exceptions (optional).
On the Reaction tab, from the Actions drop-down, select the action as needed.
You can optionally add a user notification, select the Report Incident option, or select a different action when disconnected from the corporate network.
Click Save and Close.
Assign rule sets to a policy. Before you assign rule sets to a policy, activate the rule set.
Go to Menu → Policy → Policy Catalog.
In the Product drop down list, select Data Loss Prevention <version> and select DLP Policy.
Click the Edit link of the policy you want to update.
In the policy page, go to Active Rule Sets → Actions, then click Activate Rule Set.
The Activate Rule Set window opens.
Select the checkboxes of one or more rule sets that you want to apply to the policy.
Click OK and click Apply Policy.
Trellix DLP – SaaS displays the status of the policy applied.
Assign and push the policy to Trellix DLP – SaaS endpoints.
Go to Menu → Systems → System Tree.
Select the checkbox of one or more systems that you want to assign the policy to.
Click Wake Up Agents to push the policy to Trellix DLP – SaaS endpoints immediately.
The Wake Up McAfee Agent window opens.
Next to Wake-up call type, select whether to send an Agent Wake-Up Call or a SuperAgent Wake-Up Call.
Accept the default Randomization (0–60 minutes) or type a different value.
If you type 0, agents respond immediately.
Click OK to send the wake-up call to the endpoints.
Or, you can use the Break inheritance and assign the policy and settings below option to push the policy. For information, see Assign and push a policy to a system.
The emails are sent to the specified domains only if they meet the threshold criteria.