Use case: Prevent exposing external email domains and email recipients in To or Cc fields when sending an email

Prev Next

When sending emails containing request for proposal (RFP), marketing reports, proof of concepts, and so on, to an external organization, you might unintentionally copy an existing distribution list in the To or Cc fields.

For example: Consider that a request for proposal (RFP) or a marketing collateral is sent to multiple recipients, the To and Cc list appears similar to the following to all recipients:

Sender: Sender@senderdomain.com
To: Recipient1@senderdomain.com, Recipient2@VendorA.com, Recipient3@VendorB.com
Cc: Recipient4@senderdomain.com, Recipient5@VendorA.com, Recipient6@VendorB.com

This can expose the recipients' personal email addresses, emails from different organizational domains, or competitors' email addresses.

To prevent the sender from revealing external email addresses when sending emails to many recipients, organizations can set email thresholds for the number of email domains and email recipients allowed in the To and Cc lists by using the Domain Threshold and Email Recipient Threshold settings. You can set this value when you configure an Email Protection rule to allow emails for a specific domain.

Note

This feature is only supported with Trellix DLP Endpoint for Windows.

  1. In ePO - On-prem, go to MenuData ProtectionDLP Policy Manager.

  2. Set the recipient threshold limit.

    1. Click the Definitions tab.

    2. In Source/Destination, select Recipient Threshold.

    3. Click ActionsNew Item.

    4. Enter a name and optional description.

    5. In Available properties, click Domain Threshold* or Email Recipient Threshold* , then select the threshold value for To, Cc, Bcc, Cumulative, and Cumulative (Ignore Bcc). You can also add different domain or email threshold using +.

      Note

      The minimum value that can be entered as a threshold for domain and email recipient is 1.

      Note

      Either Domain Threshold* or Email Recipient Threshold* criteria is allowed in creating a rule.

    6. In Available properties, click Exclusions.

      Note

      These domains and email recipients can be internal.

      Note

      For Exclusions, when using Domain threshold criteria only the domain name value is considered and both the email address and display name are ignored.

    7. Select equals to, then click the three-dots menu to select the email addresses, email address expressions, display names, characters contained in display name, and domain names that need to be excluded.

      Note

      You can create the domain or email recipient definitions in DefinitionsEmail Address List.

    8. Click Save.

  3. Configure the Email Protection rule.

    1. In the Rule Sets tab, create a rule set. For more information, see Create a rule set.

    2. Open the created rule set, then in the Data protection tab, select ActionsNew RuleEmail Protection.

    3. Enter a name for the rule and select StateEnabled.

    4. On the Conditions tab, for Recipient Threshold (can be domain threshold or email recipient threshold), select equals to to select the threshold definition created in step 2.

      Note

      When Recipient Threshold is enabled, other classification criteria conditions and Exceptions are disabled.

    5. Click the three-dots menu to select the email threshold definitions created in step 2.

  4. On the Reaction tab, from the Actions drop-down, select the action as needed.

    You can optionally add a user notification, select the Report Incident option, or select a different action when disconnected from the corporate network.

    1. Click Save and Close.

  5. Assign rule sets to a policy. Before you assign rule sets to a policy, activate the rule set.

    1. Go to MenuPolicyPolicy Catalog.

    2. In the Product drop down list, select Data Loss Prevention <version> and select DLP Policy.

    3. Click the Edit link of the policy you want to update.

    4. In the policy page, go to Active Rule SetsActions, then click Activate Rule Set.

      The Activate Rule Set window opens.

    5. Select the checkboxes of one or more rule sets that you want to apply to the policy.

    6. Click OK and click Apply Policy.

      Trellix DLP displays the status of the policy applied.

  6. Assign and push the policy to Trellix DLP endpoints.

    1. Go to MenuSystemsSystem Tree.

    2. Select the checkbox of one or more systems that you want to assign the policy to.

    3. Click Wake Up Agents to push the policy to Trellix DLP endpoints immediately.

      The Wake Up Trellix Agent window opens.

    4. Next to Wake-up call type, select whether to send an Agent Wake-Up Call or a SuperAgent Wake-Up Call.

    5. Accept the default Randomization (0–60 minutes) or type a different value.

      If you type 0, agents respond immediately.

    6. Click OK to send the wake-up call to the endpoints.

    Or, you can use the Break inheritance and assign the policy and settings below option to push the policy. For information, see Assign and push a policy to a system.

Trellix DLP notifies and requests to move such email addresses to Bcc field.