DLP Exceptions
The DLP engine supports defining Allow-Lists by Sender, Recipient, File MD5, and Strings.
The DLP engine stops scanning emails, messages, and files that match an Allow-List rule. The DLP verdict will automatically be clean for the Allow-List.
-
DLP Allow-List applies to both the incoming and outgoing DLP policy rules. For information about DLP policies, see Data Loss Prevention (DLP) Policy.
-
Emails, messages, and files in the DLP Allow-List are evaluated by other security engines, such as Anti-Malware and Anti-Phishing.
-
To add string-based DLP Allow-List, you need View All Sensitive Data role assigned under Specific Service Roles for Email Security.
-
When you add multiple strings, each string will be added as a separate exception. Allow-listed strings will not be flagged as a DLP violation.
Viewing DLP Exceptions
To view the configured Allow-List or Block-List rules:
-
Access the Email Security Administrator Portal.
-
Go to Security Settings > Exceptions > DLP.
-
In the drop-down from the top of the page, select the require exception type (Allow-List or Block-List).
The page shows a table with all file type exceptions and the defined criteria.