Step 5: Create a Compliance Rule

  1. From the left navigation panel, click Apps > Google Workspace > Gmail.
  2. Scroll-down and click Compliance.

    By default, the system shows these rules in Content compliance:

    • [portal identifier]_monitor_ei

    • [portal identifier]_monitor_ii

    • [portal identifier]_monitor_eo

    • [portal identifier]_inline_ei

    To find the portal identifier, see Portal Identifier of Avanan Tenant.

  3. Update the settings for [portal identifier]_monitor_eo rule.
    1. For [portal identifier]_monitor_eo rule, click Edit.
    2. Scroll-down to the end of the Edit setting pop-up and click Show options.
    3. Under Envelope filter, select the Only affect specific envelope senders checkbox.

    4. From the list, select Group membership (only sent mail).
    5. Click Select groups and select avanan_monitor_outgoing_policy.
    6. Click Save.
  4. Create the [portal identifier]_inline_eo rule with these settings.
    1. From the Content compliance rules, click Add Another Rule.

    2. Enter the Content compliance rule name as [portal identifier]_inline_eo.

      To find the portal identifier, see Portal Identifier of Avanan Tenant.

    3. Under Email messages to affect, do these:
      1. Select Outbound checkbox.
      2. In Add expressions that describe the content you want to search for in each message, select If ALL of the following match the message.
      3. Click Add.

      4. In the Add setting pop-up, select Metadata match.
      5. Under Attribute, select Source IP.
      6. Under Match type, select Source IP is not within the following range.
      7. Enter all the IP addresses relevant to your data region.

        For the list of supported IP addresses, see IP Addresses Supported Per Region.

      8. Click Save.
    4. Under If the above expressions match, do the following, do these:

      1. Select Modify message.
      2. Under Headers, do these:
        1. Select Add X-Gm-Original-To header checkbox.
        2. Select Add X-Gm-Spam and X-Gm-Phishy headers checkbox.
        3. Select Add custom headers checkbox and add custom headers with these values.

          Header Key

          Header Value

          X-CLOUD-SEC-AV-Sent

          true

          X-CLOUD-SEC-AV-Info

          [portal],google_mail,sent,inline

          To add a custom header:

          1. Click Add.
          2. In Header key, enter the header key.
          3. In Header value, enter the header value.
          4. Click Save.
      3. Under Route, do these:

        1. Select the Change route checkbox.
        2. Select the Also reroute spam checkbox.
        3. In the list, select CLOUD-SEC-AV DLP Service.
    5. Scroll-down to the end of the page and click Show options.
    6. Under Account types to affect, select Users and Groups checkbox.
    7. Under Envelope filter, do these:

      1. Select the Only affect specific envelope senders checkbox.
      2. From the list, select Group membership (only sent mail).
      3. Click Select groups and select avanan_inline_outgoing_policy.
      4. Click Save.