Create primary DLP Gateway mail flow rule in Exchange On premise

Introduction

This page covers the configuration of the primary mail flow rule for DLP Gateway in Exchnage On premise, which will be responsible for routing selected email traffic to Zivver.

Getting started

  1. Go to the Exchange Administrative Center (EAC).
  2. Log into EAC as an administrator.
  3. Click on mail flow in the menu on the left.
  4. Click on rules.
  5. Click on the add button.
  6. Click on Create a new rule….
  7. Enter a name. For example: Zivver DLP Gateway
  8. On the bottom of the window, click the More options… link.

Set mail flow rule conditions

  1. Under *Apply this rule if… select The sender… and then is external/internal.
  2. In the window that opens, select Inside the organization.
  3. Click OK.
  4. Add any other conditions you want to be satisfied for emails to be routed to Zivver DLP Gateway.
In case of a phased or partial roll-out of DLP Gateway, you can configure conditions based on sender characteristics, e.g. specific users, user groups, or email domains. Further information from Microsoft on mail flow rule conditions can be found here.
Any conditions you apply must apply to the entire message, not to any recipients of the message. Conditions applied on recipient level will lead to only the message to the recipient(s) matching the conditions being relayed to Zivver, resulting in split conversations.

Set mail flow rule actions

  1. Under *Do the following… select Modify the message properties… and then set a message header.
  2. Click the first *Enter text… field.
  3. Set the message header to zivver-relay.
  4. Click OK.
  5. Click the second *Enter text… field.
  6. Set the value to smart.
  7. Click OK.
  8. Click the add action button.
  9. Under And select Redirect the message to… and then these recipients.
  10. Look up the contact person that was created before. Then, select it.
  11. Click add ->.
  12. Click OK.

Set mail flow rule exceptions

  1. Under Except if… click the add exception button.
  2. Select The message header… and then matches these text patterns
  3. Click the *Enter text… field.
  4. Set the message header to skip-zivver-relay.
  5. Click OK
  6. Click the *Enter text patterns… field.
  7. Set the value to ..*. (that is 2 dots, 1 asterisk/wildcard, 1 dot).
  8. Click the add button.
  9. Click OK.
If there are any further exclusions from DLP Gateway related to a phased/partial roll-out of DLP Gateway and/or specific to your organization, you can configure additional exceptions. Further information from Microsoft on mail flow rule exceptions can be found here.

Set rule settings

  1. Leave the Audit this rule with severity level on the default setting of Not specified.
  2. Leave the Rule mode on the default setting of Enforce.
  3. Optional: Enable Activate this rule on the following date and select a date and time, if you want this mail flow rule be automatically activated from a specific date and time.
  4. Leave Deactivate this rule on the following date disabled.
  5. Enable the option Stop processing more rules.
  6. Enable the option Defer the message if rule processing doesn’t complete.
  7. Leave Match sender address in message: to the default setting of Header.
  8. Leave the Comments section blank, unless otherwise desired
  9. Carefully review all rule conditions, actions, exceptions and settings. Any errors in mail flow rule configuration may result in delivery issues of outbound emails.
  10. When you are satisfied that the mail flow rule is configured correctly, click Save.
  11. Under ON, deselect the checkbox to disable this mail flow rule. You will get instructions to enable this mail flow rule in a next chapter.

Modify the priority of the mail flow rule, if needed

Make sure that the priority of all the existing rules is correct. If other rules must process a message first, make sure that the Primary DLP Gateway rule has a lower priority. Also, make sure that the other rules with a higher priority do not have the setting ‘Stop processing other rules’ enabled, unless you explicitly want messages that trigger this/these rule(s) not to be processed by DLP Gateway.
  1. If you need to adjust the priority of the mail flow rule, find the mail flow rule you have created in the overview on the rules page
  2. Click on the name of the rule and use the arrow_upward or arrow_downward buttons to move the mail flow rule up or down into the correct order of priority.
  3. Alternatively, double click the name of the mail flow rule. In the window which opens, under Priority, enter the correct priority for the mail flow rule. Then click Save and wait for the setting to be saved.

Next step

Go back to Setup DLP Gateway and continue with Part 2.