Set Up the Email DLP Host
Focus
Focus
Enterprise DLP

Set Up the Email DLP Host

Table of Contents

Set Up the Email DLP Host

Create a route from Gmail to the
Enterprise Data Loss Prevention (E-DLP)
Email DLP host.
Where Can I Use This?
What Do I Need?
  • SaaS Security
  • Enterprise Data Loss Prevention (E-DLP)
    license
  • SaaS Security
    license
    Or
  • Any of the following licenses
    • Prisma Access
      CASB license
    • Next-Generation CASB for Prisma Access and NGFW (CASB-X)
      license
    • Data Security
      license
Set up routing from Gmail to the
Enterprise Data Loss Prevention (E-DLP)
Email DLP Host is required allow Gmail to forward emails to
Enterprise DLP
for inspection and verdict rendering to prevent exfiltration of sensitive data.
  1. In the Dashboard, select
    Apps
    Google Workspace
    Gmail
    Hosts
    .
  2. Add Route
    to the Email DLP host.
  3. Configure the Email DLP host.
    1. Enter a descriptive
      Name
      .
    2. In
      Specify email server
      , verify
      Single host
      is selected.
    3. Enter the host name and port.
      Adding the Email DLP host name is required for positive identification of the Palo Alto Networks DLP cloud service. The CA issuer FQDN you add must match the email routing FQDN you added in the previous step.
      • United States
        mail.us-west1.email.dlp.paloaltonetworks.com
      • Europe
        mail.europe-west3.email.dlp.paloaltonetworks.com
      • APAC
        mail.asia-southeast1.email.dlp.paloaltonetworks.com
      • Port
        25
    4. For the
      Options
      , verify the following settings are enabled.
      • Require mail to be transmitted via a secure (TLS) connection
      • Require CA signed certificate
      • Validate certificate hostname
    5. Test TLS connection
      to verify Gmail can successfully connect to
      Enterprise DLP
      .
    6. Save
      .
  4. Back in the Hosts page, verify that the Email DLP host is displayed.
  5. After you successfully set up the Email DLP host on Gmail, you must create the Gmail transports rule to instruct Gmail to forward emails to
    Enterprise DLP
    and establish the actions Gmail takes based on the quarantine or block verdicts rendered by
    Enterprise DLP
    .
    A transport rule is not required for emails that match your Email DLP policy where the action is set to
    Monitor
    . In this case, the
    x-panw-action - monitor
    email header is added, a DLP incident is created, and the email continues to its intended recipient.

Recommended For You