Hello there!

Need Help? We are right here!

miniOrange Support Chat - Get Help and Support
miniOrange Email Support
Success Checkmark - Form Submitted Successfully

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to uemsupport@xecurify.com

Search Results:

×

Configure miniOrange Email DLP for Gmail and Google Workspace


In today's digital age, securing sensitive information is crucial for any organization. With the increasing reliance on email communication, especially through platforms like Gmail and Google Workspace (G Suite), protecting against unauthorized data transmission is more important than ever. miniOrange Email DLP (Data Loss Prevention) offers a robust solution to monitor outbound emails, manage quarantined emails, and establish rules to detect and prevent unauthorized data transmission. By integrating miniOrange Email DLP with Gmail and Google Workspace, organizations ensure comprehensive email security, safeguard valuable data, and maintain regulatory compliance.

Prerequisites

    There are a couple of things you need to check before you start with the setup:

  • You need Administrator access for Google Admin Console.
  • Access to the Server / Instance where miniOrange Email DLP is installed.

Step 1: Generate your DKIM and Authentication keys

  • Sign in to the miniOrange UEM dashboard and open the Email Provider Configuration page. Enter the required details, then generate your DKIM and Authentication keys. Save both keys somewhere safe — you will need them later.

  • miniOrange Email DLP setup with Gmail and Google Workspace | Admin Dashboard Endpoint

Step 2: Configure the Outbound Gateway in Gmail

Complete the following steps to configure the outbound gateway route and apply it to Gmail routing.

    2.1 Add an Outbound route email

    • Sign in to your Google Admin console.
    • In the Admin console, navigate to the left menu panel, go to Apps > Google Workspace > Gmail.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Admin Console Configuration

    • In the Gmail tab navigate to Hosts and click on Add Route.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Hosts Tab

    • For Name, enter a route name for the outbound gateway. For Enter hostname or IP, enter the outbound gateway IP address.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Add Mail Routes

    • Ensure the TLS option is enabled, click Test TLS connection, then click Save.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Enable TLS Option

    2.2 Set up the outbound gateway routing

      You can set up an outbound gateway using the Routing setting or the Outbound gateway setting.

    • In the Admin console, go to Apps › Google Workspace › Gmail › Routing. Make sure your top-level organizational unit is selected, then click Configure (or Add another rule).

    • miniOrange Email DLP setup with Gmail and Google Workspace | Set Routing

    • Enter a name or description for the routing setting and check the Outbound under the messages to affect.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Set Email Effect

    • For the selected message types, enable Add X-Gm-Original-To header and Add custom headers.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Change Route

    • Under Add custom headers, click Add. Set Key X-MODLP-AUTH and Value is the Authentication key that you generated from the dashboard in Step 1.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Add Authentication Header

    • Under Route, click Change route, select Normal routing, then choose your outbound gateway route from the list.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Normal Routing

    • Select the TLS encryption option, then click Show options.

    • miniOrange Email DLP setup with Gmail and Google Workspace | TLS Options

    • Under Show options, select Option B. You can apply the setting to a specific sender, to groups, or by pattern-match sender — choose whichever suits your needs.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Option B

    • For example, to apply it to a single sender, select Single email address from the dropdown, add the email address, then click Save.

    • miniOrange Email DLP setup with Gmail and Google Workspace | Single Email Address

      Note : You have successfully configured Google Workspace for your miniOrange Email DLP system.

    2.3 Add SPF & DKIM records in your DNS console

    • Sign in to your DNS console, go to your TXT records, and find your existing SPF record. Update it by adding include:spf.endpointdefence.com .

    • miniOrange Email DLP setup with Gmail and Google Workspace | SPF Record

    • Create a new TXT record. Set the key to minidlp._domainkey and the value to the DKIM record you generated from the miniOrange UEM dashboard, then click Save.

    • miniOrange Email DLP setup with Gmail and Google Workspace | DKIM Record

      Note : You have successfully configured the TXT records in your DNS console. You are now ready to create email policies.

Step 3. Configure Email Policy using DLP Solution.

  • Sign in to your DLP dashboard.
  • : Email DLP for Email Security | Add Email Policy

  • On the dashboard, navigate to Email DLP tab and click on the Add Policy button to open the policy form.
  • : Email DLP for Email Security | Add Email Policy

  • Now under the General tab, provide a meaningful Policy Name.

  • : Email Security | Add Policy Name

  • Then select an Action for the policy from the dropdown.
    • Block: If the email violates the policy, it will be blocked, and a report will be generated.
    • Log: If the email violates the policy, it will be sent, but the incident will be logged in the reports.
    • Quarantine: If the email violates the policy, it will be quarantined for review and the reviewer will be notified over email.
    • Redact: If the email violates the policy, sensitive content will be automatically redacted before the email is sent.

    : Email DLP for Email Security | Select Action

  • Now choose the appropriate Risk level.

  • :Email DLP for Email Security | Select risk level

  • Click on Next to proceed to the Restriction tab where Domain and attachment-based restrictions can be set.
  • Select the type of Domain Restriction you want to apply.
    • No Restriction: No restrictions will be applied.
    • Allow Domains (Whitelisting): Emails can only be sent to whitelisted domains, while all others are blocked.
    • Block Domains (Blacklisting): Emails to blacklisted domains will be blocked, with all other domains allowed.
    • Email Size Restriction: You can set a maximum size limit for emails to be sent.

    : Email DLP for Email Security  | Select Type of Domain restriction

  • For example, if we select the Allow Domains option, we need to specify a domain list to which all the emails will be sent.

  • : Email DLP for Email Security  | Allow Domains

  • In the next step, you can set restrictions on file uploads based on their attachements.
    • To allow all file types, select the No Restriction option.
    • If you want to permit only specific file types, choose Allow Attachements and then select the desired attachement from the list.
    • Alternatively, if you wish to block certain file types, select Block Attachements and choose the attachement to be restricted.

    : Email DLP for Email Security  | Set Restrictions

  • For example, we have selected the Allow Attachments option to allow specified file types to be sent as email attachments.

  • : Email DLP for Email Security  | File Attachments

  • Proceed to the Classification tab and configure the label triggers by selecting the predefined labels. This enables the system to classify email data automatically based on the selected labels.

  • : Email DLP for Email Security | Configure Label Triggers

  • Next, navigate to the Content Scan Scope section to specify which parts of the email should be scanned and classified.
    • Email Body: Classifies sensitive data present in the email body.
    • Email Subject: Classifies sensitive data present in the email subject.
    • Attachments: Classifies sensitive data contained within email attachments.

    : Email DLP for Email Security | Configure Content Scan Scope

  • For example, we have applied classifications to all the three options.
  • Note: Classifications can be created under the Data Classifications > Classifications option.


    : Email DLP for Email Security  | Selected Classification types

  • In the next step, you'll associate groups with the policy. Start by searching for the User Groups and selecting it. If you want to apply the same policy to multiple groups, you can select additional groups as well.
  • : Email DLP for Email Security  | Associate Groups

  • In the Notification tab enable the Create Alert for this Policy toggle and then specify the email addresses to which you want to notify policy breaches.
  • Note: You can enter multiple email addresses by pressing the Enter key after each one.


    : Email DLP for Email Security  | Associate Notification

  • Finally, click on the Add button to save the policy.
  • You have successfully configured the miniOrange Email DLP dashboard and implemented your email policies.

If you are facing any issues that you are not able to resolve please feel to reach out us uemsupport@xecurify.com


Want To Schedule A Demo?

Request a Demo