You want to log the connecting IP address of a sender for SIEM analysis or audit purposes by adding a custom header to inbound emails.
Email Security.cloud
While the standard 'X-Originating-IP' header is added by default with brackets (e.g., 'X-Originating-IP: [192.0.2.1]'), you can create a Data Protection policy to log the transaction, which will include the IP in the service logs.
1. Log in to the Email Security.cloud portal and navigate to Services > Data Protection.
9. Click Save and Activate the Data Protection Policy.
Note: Data Protection policies can log the event, but they cannot currently "strip" brackets from the system-generated 'X-Originating-IP' header or dynamically insert a "plain" IP into a new header. For SIEM integration, it is recommended to parse the brackets out during the SIEM ingestion phase.