Configure Scan Rule

The Scan rule is used to select emails for scanning. This rule adds a Nightfall header to all the emails that are to be scanned.

Important

It is mandatory for you to create the scan rule.

To create Scan rule:

  1. Login to your Google Workspace with an admin account.

  2. Click the menu icon.

  3. Select Admin.

  1. In the left menu, expand Apps and then expand Google Workspace.

  2. Click Gmail.

  1. Scroll down and click Compliance.

  1. Scroll down to the Content Compliance section and click ADD ANOTHER RULE. (If you have not created any Compliance rule previously, the button might be displayed as CONFIGURE).

  1. Enter a name for the compliance rule.

  2. Select Outbound and Internal - Sending checkboxes in the Email messages to affect section.

If you select only the Outbound check box, only those emails that are routed out of your organization to external domains are scanned. If you wish to scan internal emails which are sent between employees of your organization, you must select the Internal - Sending check box.

  1. Select the If ANY of the following match the message option.

Steps 11 to 16 help you create a Compliance rule to block emails.

  1. Click ADD.

  1. In the Add setting dialog box, select the Advanced Content match option.

  1. In the Location drop-down menu, select Full headers.

  1. In the Match type drop-down menu select Not Contains text.

  1. In the Content field enter x-nightfall-scanned. x-nightfall-scanned is a header that is added to emails that Nightfall scans. This condition ensures that all unscanned emails go through the scanning process.

  2. Click SAVE.

The condition expression is created as follows. This ensures all emails that are not yet scanned by Nightfall need to be scanned.

You must now configure rules to route the email towards Nightfall for scanning.

17. In stage 3, select Modify message.

  1. Under the Headers section, select the Add X-Gm-Original-To header check box.

  2. Under the Envelope recipient section, select the Change envelope recipient check box.

  1. In the Replace recipient field, enter dlp@secure.nightfall.ai. This is the email address to which emails must be routed for scanning.

  1. Click SAVE.

Last updated