Data Protection 'Tag with Header' action behavior for outbound email in Email Security.cloud
search cancel

Data Protection 'Tag with Header' action behavior for outbound email in Email Security.cloud

book

Article ID: 454100

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

The "Tag with Header" action within Data Protection policies in Email Security.cloud functions exclusively for inbound email traffic. This article explains the design rationale behind this limitation.

Environment

Email Security Cloud

Cause

Headers like X-ContentInfo and X-Content-Flag from outbound content-control incidents are intentionally stripped to prevent leaking internal policy enforcement details. If these headers remain on outbound mail, external recipients would see evidence that a message matched internal rules, such as "swearwords" filtering or specific data loss prevention policy triggers.

This design protects internal diagnostic and policy enforcement information from being exposed to external parties.

Resolution

*   Understand that the "Tag with Header" action is fully supported for inbound email traffic only.
*   Acknowledge that for outbound emails, the removal of headers by the Email Security.cloud service is intended and by design.
*   Do not expect headers to persist on outbound messages when using the "Tag with Header" Data Protection action.

Additional Information

Please refer below techdoc for more information about actions in Email Data Protection :

https://techdocs.broadcom.com/us/en/symantec-security-software/email-security/email-security-cloud/1-0/about-custom-and-managed-lists-in-email-data-protection/about-actions-and-email-data-protection-policies.html#v117495058