Create an email data loss prevention rule

Add email Data Loss Prevention (DLP) rules to control information allowed in emails.

To create a new rule, you must edit an existing policy, or create a new policy.

Email Data Loss Prevention policies contain rules that describe what information to look for in emails and the action to take when matched. To create a rule:

  1. Click Settings.
  2. Click either Inbound or Outbound to set the direction of emails this rule checks.
  3. Click Add rule.
  4. Give the rule a Name and Description.
  5. Choose the rule type.

    You can use templates provided by Sophos to protect your data. Templates protect common types of sensitive information. You can also customize rules using content control lists (CCLs), whole message size or message attachment size, and keywords or phrases.

    Choose from:

    • Protect financial information (FI)
    • Protect confidential information (CI)
    • Protect health information (HI)
    • Protect personally identifiable information (PII)
    • Protect using attachment file types
    • Protect using Sophos content control lists (CCLs)
    • Protect using message size
    • Protect using keywords.
  6. Click Next.

    Add items appears.

  7. Choose the lists for the rule.

    For most rule types you can use lists provided by Sophos or build custom lists specific to your needs.

    1. If you chose Protect using attachment file types, we recommend you use the default Sophos list.

      If you use a custom list, you can choose to filter by File extensions or File group.

      If you filter by File group, you can select groups of file types from the list. You can't choose individual file extensions. The rule matches against the file types we detect, not extensions.

      If you filter by File extensions, you can select individual file extensions. You can't choose a file group. You can also add a comma-separated list of file extensions to filter against in Include extensions. The rule matches against file extensions, not the file types we detect.

    2. If you chose Protect using keywords, enter strings to search for. You can also import keywords.
    3. If you chose Protect using message size, you can set size limits for email attachments, or the whole email, or both. Attachment size limits apply to individual attachments, not the total size of all the attachments.

    If you use the message size rule with another rule type, the match is against both types. For example, if you choose attachment size and keyword type, the rule is only matched if the keyword is found in the attachment and the size limit is met.

  8. Click Next.

    Choose action appears.

  9. Choose the actions to take when the rule is triggered, who to notify, and additional options.

    Options change depending on the rule type and direction (Inbound or Outbound).

    For example if you select Inbound, the Bounce action doesn't appear in the list of actions.
    For outbound rules you can override the default encryption method set in Overview > Global Settings > Email Encryption.

    You can combine different rule types by selecting actions that allow processing to continue to the next rule. If you select an action that allows this, Continue processing appears and you can turn it on.

  10. Turn the rule on or off.
  11. Click Save.