Skip to content
Avanet

Sophos Email Data Control: Configure DLP Rules Safely

Sophos Email calls its protection against data loss in email traffic Data Control. A rule defines which data Sophos searches for in the subject, body, and attachments, which direction and external addresses it applies to, and which action follows a match. This is separate from endpoint DLP: Data Control inspects email, whereas Data Loss Prevention Rules (DLP) control other data transfers on endpoints.

Safe quick path: Start with a small pilot scope, choose a Sophos template or a few suitable CCLs, use Log or Quarantine as the initial action, and place the rule above broader rules. Test it with a positive sample, a similar negative sample, and a permitted business transaction. Enable the final action only after Data Control summary and Message History show the expected matches and non-matches.

Prepare the scope, responsibilities, and rollback

Before configuration, the responsible data owner determines what must be protected and what may happen when the rule matches. The admin translates that decision into a technical rule. Record at least the following in the change:

  • direction Inbound or Outbound;
  • internal users, groups or domains and, where applicable, external addresses or domains;
  • data pattern to detect, permitted business transaction, and responsible owner;
  • desired action, notification recipient and escalation path;
  • one controlled positive and one controlled negative test sample;
  • previous policy status, rule position and rollback criterion.

A Data Control policy can contain up to 25 rules. Sophos evaluates them from top to bottom and applies the first matching rule. A narrow exception therefore belongs above the general protection rule; a specific blocking rule belongs above a broader logging rule. Continue processing is a deliberate exception to this model: if the chosen action supports the option and you enable it, Sophos continues with the next rule after applying the action. Use it only when tests have clearly confirmed the combined effect of the actions.

Policies and rules have separate external scopes. The policy defines the basic external address scope; the rule narrows it further with External senders for inbound traffic or External recipients for outbound traffic. Include all, Include list, and Exclude list refer to SMTP envelope addresses, not the visible From and To headers. An imported file must be CSV or TXT, contain one entry per line, and must not take the list beyond 100 entries. Replace all existing entries with this import replaces the existing list in full.

Never build an exception from only a display name or the visible From header. A domain exception can cover every recipient or sender in that domain and therefore permit more traffic than intended. For recurring legitimate processes, a pilot group or precisely scoped envelope address is safer. Give the exception an owner, an expiry or review date, and its own positive and negative tests.

If multiple Sophos Email policies apply to the same users, their assignment must also be correct. Assign Sophos Email Security policies precisely explains scope and priority at policy level.

Create a Data Control policy and rule

  1. Open in Sophos Fusion (formerly Sophos Central) My Products > Email Security > Policies.
  2. Add Policy, then select Data Control and Continue.
  3. Enter a unique name, for example DLP-Outbound-Finance-Pilot.
  4. Under Internal, add only the pilot users, group, or domain. Set External only if the entire policy must be limited to specific external destinations.
  5. Open Settings and select Inbound or Outbound for the rule.
  6. Click on Add rule, enter name and description and select the appropriate Rule type.
  7. Add the detection lists under Add items, then select the required locations under Search in: Subject, Body, Attachment Name, and/or Attachment Content.
  8. Set additional conditions for header, source or size under Message Attributes if necessary.
  9. Narrow the rule with External senders or External recipients.
  10. Under Choose action, select the pilot action and notifications. Activate Continue processing only for an intentionally tested control chain.
  11. Turn on Filter messages with this rule and select Save.

A newly created policy does not yet contain any rules. A cloned policy initially has the status Policy Bypassed, contains no users, groups, or domains, and has a higher priority than the original by default. Before selecting Policy is enforced, check its assignment, rules, and priority. In EMS mode, Data Control can be configured, but actions are only reported as an expected result and are not applied to messages.

Select the appropriate recognition type

Templates for typical sensitive data

The templates Financial information (FI), Confidential information (CI), Health information (HI) and Personally identifiable information (PII) use content control lists selected by Sophos. For example, FI targets account or credit card data, HI targets medical or patient data and PII targets national ID or passport numbers. As a starting point, use Use Sophos list and select only the required search locations.

Use custom list first loads the CCLs recommended for the template. You can then add or remove CCLs and change match thresholds. This is not harmless fine-tuning: removing recommended CCLs may reduce coverage, while adding unsuitable CCLs may increase false positives. Any adjustment therefore requires realistic, anonymised data patterns approved by the owner and a fresh set of positive and negative tests.

Custom CCL rule

A custom Content control lists (CCLs) rule is suitable when a specific regional or industry identifier must be detected. Filter the selection by Region and data type, read the explanation beside the information icon, and do not select every list indiscriminately. The RECOMMENDED filter shows regional recommendations; without a region filter, do not simply enable every displayed CCL. Obsolete lists may appear only without a filter or under Deprecated. Existing rules continue to show them, but a review should replace them with supported alternatives.

For Number of matches:

  • A higher value makes the individual CCL more stringent and typically reduces false positives, but can overlook real hits.
  • A lower value makes them more sensitive and typically reduces false negatives, but can hit more legitimate emails.
  • Trigger this rule by number of CCL matches additionally decides how many selected CCLs must apply; alternatively, All the CCLs must match requires each selected CCL.

These two thresholds solve different questions. For example, a CCL may require two card numbers internally, while the rule requires only one of three selected CCLs. Standard values are only changed if test cases prove the technical necessity.

Keywords and Regular Expressions

Keywords (KW) searches for words, phrases, Unicode characters, or regular expressions in the selected search locations. Regular expressions must be no more than 50 characters long, must follow the Boost library’s Perl syntax, and must not contain parenthesised groups for performance reasons.

Keyword and regex matching only works for UTF-8 encoded message content. If an obvious hit is missing, you check the actual content transfer and character encoding instead of making the expression immediately wider. For structured ID, account or card data, a matching CCL is usually more robust than a general word like confidential.

File types and contents

Attachment file types (AFT) can filter by file extensions or by detected file groups or True File Type. In a custom AFT rule, both cannot be combined. If you need both methods, you create two separate rules and test their order.

For file extensions, use leading dots and commas without spaces, for example:

.doc,.docx,.pdf,.zip

The entry must not exceed 1,000 characters. Renaming a file can evade an extension rule; a file-group rule checks the detected type. The Sophos list combines documented extension blocks with True File Type detection for formats including executables, macro-enabled Office files, obfuscated scripts, and WebAssembly.

Attachment Content does not mean that every visible element of each file is evaluated equally. Sophos extracts different content and metadata depending on the format: for PDF, for example, text streams and document metadata, for Word also headers, footers, text fields, table cells and non-visible comments, for Excel sheet names and text and number cells. A scanned image in a PDF without extractable text is therefore not a reliable CCL test. For acceptance, you use supported, text-based sample files and check separately whether metadata unintentionally generates a hit.

Connect message attributes meaningfully

Message Attributes (MA) filters to Header, Source or Size. Header conditions can check a regular expression, partial string, exact value or the existence or absence of a header. For multiple attributes, Match for: Any or All determines whether one or all of them must apply. If you combine Message Attributes with another rule type, both types must match.

Attachment size conditions use the MIME-encoded size of each individual attachment, not their combined size or the raw file size. Base64 can add approximately 37%; a 20 MB binary file can therefore exceed 28 MB when encoded. Sophos Email processes messages up to 50 MB. Test thresholds with real MIME messages rather than deriving them from the file size shown in Explorer.

Select an action appropriate to the risk

The available actions depend on direction and rule type. For a pilot, Log or Quarantine are usually more controllable than Delete. The main impacts are:

  • Quarantine: withholds the message for verification.
  • Encrypt: encrypts outbound matches. By default, the method from the user’s Secure Message policy applies; the rule can override it. The policy remains necessary for other defaults, such as the language of the registration message.
  • Strip attachments: quarantines the original and delivers a copy without the attachment.
  • Modify Address: CC/BCC adds to the original recipients; setting To replaces the original recipients. Envelope only does not change the MIME headers.
  • Redirect message: forwards the original message as an attachment to the redirect address.
  • Reroute message: routes to IP/FQDN and port, but only applies to Gateway. In Mailflow mode, routing is configured in Microsoft 365.
  • Bounce: informs the sender of the non-delivery and is not available for inbound.
  • Modify Header: adds a header, replaces the first value or removes all matching headers.
  • Delete: deletes the message; use this action only after approved testing and a documented incident process.
  • Log, Tag a subject line, and notifications record or mark a match, but do not prevent data loss on their own.

Notify others allows up to five mailboxes or distribution lists from the account’s own email domains. Notifications must not themselves distribute unnecessary sensitive content. Data Control events do not appear in quarantine summaries; event notifications go directly to administrators.

Set encryption headers exactly and test them under control

A matching Data Control rule can use Modify Header to add or change an encryption header. Exactly the following headers and values are supported for this configuration; do not alter their spelling or the case of the values:

HeaderAllowed values
X-SophosEmailEncrypt-NoAuthtrue, false
X-SophosEmailEncrypt-VerificationCodetrue, false
X-SophosEmailEncrypt-ExpiryPeriodtoday, fiveDays, oneWeek, twoWeeks
X-SophosEmailEncrypt-SendNotificationtrue, false
X-SophosEmailEncrypt-ReadNotificationtrue, false

This feature may not yet be available to every customer. X-SophosEmailEncrypt-NoAuth and X-SophosEmailEncrypt-VerificationCode require the Portal Encryption Add-on; that add-on boundary does not apply generally to the other three headers. An encryption action is also ready for production only after the licence, Secure Message policy, selected method, and recipient workflow have been tested. Operate Sophos Email Portal and Push Encryption explains the effects of the values and the Portal/Push workflow; that operational procedure is not duplicated here.

For acceptance, scope an outbound pilot rule only to test senders and recipients. With Modify Header, first add exactly one header with an allowed value, or replace its existing value. Then send a harmless Portal test message and, where the header is relevant to that workflow, a harmless Push test message. Data Control summary and Message History must show the expected rule and the Modify Header action; also verify the expected result of the selected value for the recipient or sender. Only then test the next value or expand the scope. A rule match alone does not prove that encryption, expiry, or notification took effect as intended.

Practical example: Financial data sent externally

For an accounting pilot group, outbound messages containing genuine financial patterns and addressed to external recipients should initially be quarantined:

  1. Policy DLP-Outbound-Finance-Pilot, Internal: only the pilot group, direction Outbound.
  2. Rule type Financial information (FI) with Use Sophos list.
  3. Search in: Body and Attachment Content. Leave Attachment Name disabled if filenames are not a relevant signal.
  4. External recipients: Include all or a limited test domain. Place an approved partner address in a narrow exception above the rule only if the data owner has approved that process.
  5. Action Quarantine, notification to the responsible DLP team; no Continue processing.
  6. Positive test with an approved test pattern in a text-based DOCX or PDF file. Negative test with similarly formatted but invalid numbers. Business test with a normal document that contains no sensitive pattern.

If the normal document format produces false positives, do not immediately exclude the entire partner domain. First determine which CCL triggered, whether metadata or message text caused the match, and whether evidence supports changing the default match count. An exception is the last corrective measure, not the first.

Validate, roll out and operate

For each test, record UTC time, direction, envelope sender and recipient, subject, message ID, sample file, expected rule, and expected action. After sending, check Data Control summary and the details in Message History. The rule is only passed if:

  1. the positive test shows the expected data control category, rule and action;
  2. the similar negative test and the normal business transaction do not match;
  3. a defined exception applies only to its exact scope;
  4. other incoming and outgoing messages continue to be processed by the intended policy;
  5. Notifications go only to the approved recipients.

Then expand the scope gradually and monitor false positives, false negatives, quarantine volumes, and exceptions. Review CCLs, match thresholds, and exceptions regularly. This is particularly important for entries under Deprecated and temporary partner exceptions.

In Microsoft 365 Mailflow mode, a Microsoft Purview DLP rule can generate duplicate notifications as a message passes through the services in both directions. This is not caused by Sophos Data Control rule order. Troubleshoot Sophos Email Mailflow with Microsoft 365 systematically explains how to create a narrowly scoped Microsoft exception and check for genuine routing loops.

Finding errors by symptom

An expected rule does not trigger

  1. Check policy assignment, Inbound/Outbound and envelope addresses.
  2. Check whether a rule placed higher matches first or the rule is not enabled with Filter messages with this rule.
  3. In the case of combined MA and content types, check whether both types really match; for multiple attributes Any/All.
  4. Check the search location: a hit in Attachment Content does not occur if only Attachment Name was selected.
  5. For keywords or regex, check UTF-8 encoding, 50-character limit, and forbidden groups.
  6. For attachments, confirm that the file type contains extractable content. Then resend a small, well-defined test case.

Too many legitimate messages match

First identify the rule, category, and action in Message History. Change only one variable at a time: remove unsuitable search locations, correct the CCL selection, or increase the match count after conclusive tests. A broad Exclude list or an immediate switch to delivery hides the symptom but does not correct the detection.

A file-type or size rule behaves unexpectedly

For AFT, determine whether the rule uses extensions or True File Type; the two methods require separate rules. For Size, compare the MIME size of the individual attachment instead of the raw file and allow for Base64 overhead. If the entire message reaches 50 MB, the processing limit is also present.

Encryption, redirection or notification missing

Check whether the action is available for the direction and Rule type. For Encrypt, also check user assignment, the Secure Message policy, the licence, and the selected method. Reroute message does not work in Mailflow mode. A notification destination must belong to an account domain; replace a deleted destination mailbox or disable the notification.

Safe rollback

If unexpected matches occur, do not disable Data Control as a whole. Set the new rule to Log, disable Filter messages with this rule for that rule, or restore the previously documented scope, order, and action. The appropriate option depends on the risk: if data loss may be possible, keep quarantine active until the owner decides; for a logging-only pilot, the pilot rule can be disabled.

Then resend a normal message and a controlled positive test, and confirm in Message History that the previous rule applies again. Remove newly created exceptions and temporary notification destinations, and restore policy priority and Continue processing to the baseline. For escalation, collect message IDs, UTC times, direction, envelope addresses, policy and rule names, rule order, category, action, encoding, and an anonymised test file. Do not place uncontrolled sensitive source data in a support ticket.