Encryption and decryption policy

Encryption policy

To enable encryption on a mail policy route, you change the default delivery action for messages matched with the policy route so that the policy route applies encryption endpoints to the relevant recipients.

If encryption is enabled

If encryption is enabled on a route, you can override the route setting using a content rule with a disposal action to deliver messages in the clear.

  1. Navigate to Policy > Manage Policy Definition > Content Rules. The Manage Content Rules page is displayed.

  2. In the Content Rules panel, select a content rule and click Edit.

  3. In the Disposal Action area, click Click here to change these settings.
  4. In the Disposal Action list, click Deliver the message.
  5. Change as specified on the route to in the clear.
  6. Click Save.
  7. Apply the configuration.

If encryption is not enabled

If encryption is not enabled on a route, you can override the route setting using a content rule with a disposal action to deliver messages applying encryption endpoint policy.

  1. Navigate to Policy > Manage Policy Definition > Content Rules. The Manage Content Rules page is displayed.

  2. In the Content Rules panel, select a content rule and click Edit.

  3. In the Disposal Action area, click Click here to change these settings.
  4. In the Disposal Action list, click Deliver the message.
  5. Change as specified on the route to applying encryption endpoint policy.
  6. Click Save.
  7. Apply the configuration.
 

If you change any configuration or policy settings, you must Apply Configuration for the new settings to take effect. You can do this either from the Changes Made panel, or System > ConfigurationApply Configuration. See Apply new configuration for more information.

If you use Peer Gateways (i.e. when multiple Gateways are peered), any configuration changes from a local Gateway can then be applied to all the peers at the same time. See Configure Peer Gateways for more information.

Decryption policy

Secure Email Gateway will not decrypt email messages, content-check them, or validate their digital signatures unless these features have been enabled on a policy route.

This enables you to control which routes to use to decrypt incoming email.

See also...