The setting "All recipient must match (Email only)" is confusing and difficult to understand.
Symantec Data Loss Prevention (DLP) Network Prevent for Email
Symantec Data Loss Prevention (DLP) Cloud Prevent for MS Office 365
Here we explain a number of test cases which demonstrate how the setting works.
| Email Test | Incident | |||
| 1 | Recipient1@example.com | Recipient2@example.com | Recipient3@example.com | Yes |
| 2 | Recipient1@example.com | Recipient2@example.com | Yes | |
| 3 | Recipient1@example.com | Yes |
| Email Test | Incident | ||||
| 1 | Recipient1@example.com | Recipient2@example.com | Recipient3@example.com | External@example.com | No |
| 2 | Recipient1@example.com | Recipient2@example.com | External@example.com | No | |
| 3 | Recipient1@example.com | External@example.com | No |
With regards to the other setting “At least (#) recipient must match” the outcome is different as we could enable that option with the value of # = 1 and have the following results:
| Email Test | Incident | ||||
| 1 | Recipient1@example.com | Recipient2@example.com | Recipient3@example.com | External@example.com | Yes |
| 2 | Recipient1@example.com | Recipient2@example.com | External@example.com | Yes | |
| 3 | Recipient1@example.com | External@example.com | Yes | ||
| 4 | External@example.com | No |
So the email would, in that case, need to contain at least 1 of the 3 recipients Recipient1@example.com, Recipient2@example.com, Recipient3@example.com but can also include any other email recipients outside of those listed in the rule which will trigger an incident whereas the “All recipient must match” cannot.