When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like https://[email protected]/, curl could wrongly get and use the password for another user set in the .netrc file for that host if such a one exists and there is no match for the specified user.
DLP does not use .netrc for credentials. CURLOPT_NETRC is never set. Symantec DLP authenticates via client certificate (mTLS via SSL_CTX_use_certificate()), not username/password.