Detect and block NDR messages (not From address) using Data Protection
search cancel

Detect and block NDR messages (not From address) using Data Protection

book

Article ID: 172292

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

This article will demonstrate how to create a policy in Data Protection that will allow you to block non-delivery report (NDR) messages for all users or for a specific group of users.

Resolution

Access the Clientnet portal > Services > Data Protection

New Policy
Name policy: Block NDR messages
Apply to: Inbound email only
Execute if: All rules are met
Action: Block And Delete (or other if you feel that this action is too aggressive)

Add rule 1
Execute if: ALL conditions are met

Add a condition: Content Regular Expression Lists
Create a new Regular Expression List
Name: Body from Regex list
Add list items:

^(from:.+?(?:\n.+?)?(?<=[ <("])MAILER-DAEMON@.+)$
^(from:.+?(?:\n.+?)?(?<=[ <("])noreply@.+)$
^(from:.+?(?:\n.+?)?(?<=[ <("])postmaster@.+)$
^(from:.+?(?:\n.+?)?(?<=[ <("])postmaster_smtp@.+)$

Email contains: a number of matches for the regexes in the selected lists
At least: 1
Count only unique matches: No
Case sensitive: No
Look in: Header
Matched text: Log matched text


Add condition: Content Keyword List
Create a new Keyword List
Name: NDR Subject list
Add list items:

[Postmaster] Email Delivery Failure
Delivery Notification: Delivery has failed
Delivery Notification: Delivery has timed out and failed
Delivery Status Notification
Delivery Delayed
Delivery Failure
Failure Notice
Impossibile_recapitare
Mail delivery failed: returning message to sender
Mail Delivery Failure
Olevererbart
Returned mail
Returned email
Undeliverable
Undeliverable Mail
Undelivered Mail Returned to Sender
Unzustellbar
Не удается доставить
배달되지 않음

Email contains a number of matches for the keywords in the selected lists
At least 1
Count only unique matches: No
Case sensitive: No
Look in: Subject
Matched text: Log matched text


Add condition: Recipient Group (Note: This condition is optional. You can use it if you would like to restrict this policy only to a limited group of users)
Browse for a Group
Choose group
Email recipient: is in any of the selected groups