When sending emails containing request for proposal (RFP), marketing reports, proof of concepts, and so on, to an external organization, you might unintentionally copy an existing distribution list in the To or Cc fields.
For example: Consider that a request for proposal (RFP) or a marketing collateral is sent to multiple recipients, the To and Cc list appears similar to the following to all recipients:
Sender: Sender@senderdomain.com To: Recipient1@senderdomain.com, Recipient2@VendorA.com, Recipient3@VendorB.com Cc: Recipient4@senderdomain.com, Recipient5@VendorA.com, Recipient6@VendorB.com
This can expose the recipients' personal email addresses, emails from different organizational domains, or competitors' email addresses.
To prevent the sender from revealing external email addresses when sending emails to many recipients, organizations can set email thresholds for the number of email domains and email recipients allowed in the To and Cc lists by using the Domain Threshold and Email Recipient Threshold settings. You can set this value when you configure an Email Protection rule to allow emails for a specific domain.
Note
This feature is only supported with Trellix DLP Endpoint for Windows.
In ePO - On-prem, go to Menu → Data Protection → DLP Policy Manager.
Set the recipient threshold limit.
Click the Definitions tab.
In Source/Destination, select Recipient Threshold.
Click Actions → New Item.
Enter a name and optional description.
In Available properties, click Domain Threshold* or Email Recipient Threshold* , then select the threshold value for To, Cc, Bcc, Cumulative, and Cumulative (Ignore Bcc). You can also add different domain or email threshold using +.
Note
The minimum value that can be entered as a threshold for domain and email recipient is 1.
Note
Either Domain Threshold* or Email Recipient Threshold* criteria is allowed in creating a rule.
In Available properties, click Exclusions.
Note
These domains and email recipients can be internal.
Note
For Exclusions, when using Domain threshold criteria only the domain name value is considered and both the email address and display name are ignored.
Select equals to, then click the three-dots menu to select the email addresses, email address expressions, display names, characters contained in display name, and domain names that need to be excluded.
Note
You can create the domain or email recipient definitions in Definitions → Email Address List.
Click Save.
Configure the Email Protection rule.
In the Rule Sets tab, create a rule set. For more information, see Create a rule set.
Open the created rule set, then in the Data protection tab, select Actions → New Rule → Email Protection.
Enter a name for the rule and select State → Enabled.
On the Conditions tab, for Recipient Threshold (can be domain threshold or email recipient threshold), select equals to to select the threshold definition created in step 2.
Note
When Recipient Threshold is enabled, other classification criteria conditions and Exceptions are disabled.
Click the three-dots menu to select the email threshold definitions created in step 2.
On the Reaction tab, from the Actions drop-down, select the action as needed.
You can optionally add a user notification, select the Report Incident option, or select a different action when disconnected from the corporate network.
Click Save and Close.
Assign rule sets to a policy. Before you assign rule sets to a policy, activate the rule set.
Go to Menu → Policy → Policy Catalog.
In the Product drop down list, select Data Loss Prevention <version> and select DLP Policy.
Click the Edit link of the policy you want to update.
In the policy page, go to Active Rule Sets → Actions, then click Activate Rule Set.
The Activate Rule Set window opens.
Select the checkboxes of one or more rule sets that you want to apply to the policy.
Click OK and click Apply Policy.
Trellix DLP displays the status of the policy applied.
Assign and push the policy to Trellix DLP endpoints.
Go to Menu → Systems → System Tree.
Select the checkbox of one or more systems that you want to assign the policy to.
Click Wake Up Agents to push the policy to Trellix DLP endpoints immediately.
The Wake Up Trellix Agent window opens.
Next to Wake-up call type, select whether to send an Agent Wake-Up Call or a SuperAgent Wake-Up Call.
Accept the default Randomization (0–60 minutes) or type a different value.
If you type 0, agents respond immediately.
Click OK to send the wake-up call to the endpoints.
Or, you can use the Break inheritance and assign the policy and settings below option to push the policy. For information, see Assign and push a policy to a system.
Trellix DLP notifies and requests to move such email addresses to Bcc field.