Target Audience
- Customers using Email DLP
- Customers relaying emails from Email DLP to other mail servers (MTA)
Notes
- The routing configuration that can provide this function is as follows.
- Emails processed with Secure Download, automatic ZIP encryption, and forced conversion of external addresses in Email DLP will be relayed to the subsequent MTA.
- Since the settings in your environment may affect email transmission, pre-verification is required.
If you are in the process of implementation, please contact your implementation representative, or if you are using Email DLP, please contact HENNGE One Technical Support. - When the routing function is activated, all emails passing through Email DLP will be routed and delivered to the specified mail server.
- Please refer to the following article for external services that have been verified by HENNGE.
However, please conduct pre-verification in your environment before transitioning to production.
External Services Integrated with HENNGE One - Please refer to the following article for the login procedure to the Email DLP administration console.
[Email DLP] How to Log in to the Administration Console - The scope of support for this feature extends from Email DLP up to the point of email delivery to an external service.
Any processing, behavior, or resulting issues after the email has been delivered to the external service are outside the scope of our company's support.
Getting Started
1. Contact for Usage Request
Please contact Technical Support (or your implementation support representative if you are in the process of implementation) with the following information.
・Desired start date for usage
・Mail service to be specified as the routing destination
・Number of emails sent externally on business days (if available)
After HENNGE confirms the information you provided, the routing function will be activated from the administration console.
2. Operation Verification with Some Users
Use the routing settings of Exchange Online or Google Workspace to forward only test emails to Email DLP for operation verification.
※ For customers currently using Email DLP
The routing function of Email DLP delivers all emails passing through to the specified MTA.
Therefore, routing tests limited to some emails cannot be performed.
Additionally, for customers currently using Email DLP, a test environment will be provided for operation verification.
※ To use the test environment, you need to prepare a test environment for Exchange Online/Google Workspace and a verification environment for the mail service specified as the routing destination.
3. Deployment to All Users
Once there are no issues with the operation verification and deployment to all users is decided, please inform HENNGE of the schedule.
Change the routing settings of Exchange Online/Google Workspace to forward all emails to Email DLP.
※ For customers currently using Email DLP
If there are no issues confirmed in the test environment, HENNGE will change the settings so that the routing function can be configured in the Email DLP in use.
Once you configure the routing settings, all emails will be immediately delivered to the specified MTA.
Procedure
-
Adding SPF (Recommended)
Add an SPF record for Email DLP to your customer's domain DNS.
In addition to the default SPF record “include:spf.mta.hdems.com”, we recommend registering “include:spf-outbound.mo.hdems.com” as well.include:spf-outbound.mo.hdems.com*SPF is a mechanism where the receiving MTA evaluates the legitimacy of the route against the preceding sending MTA.
When using routing, evaluation occurs between the MTA designated for routing and the final receiving MTA, so it is typically unnecessary.
However, we recommend adding it because the configuration of the MTA designated for routing may sometimes evaluate the route originating from Email DLP. - Access [Tenant Settings] - [Routing] from the left menu of the Email DLP administration console.
-
Press [Settings] on the [Routing] screen.
-
Enter the destination information on the [Destination Settings] screen and press [Next].
-
Enter the recipient email address on the [Connectivity Test] screen and press [Send Test Email].
※ By turning on [Specify a sender address for testing], you can specify the sender's address.
※ If the test email cannot be received, specify a domain that the destination mail server allows connection to as the sender in [Use any address] and resend.
※ If the test email sent using [Use any address] cannot be received, check the reception log of the destination mail server.
If investigation is necessary, please contact your HENNGE representative. -
Once the [Test Email Sent] screen is displayed, confirm that the test email has been received at the destination.
After checking the email, check the checkbox and press [Proceed to Confirm Settings].
※ The email will not be recorded in the history of the Email DLP administration console, so please confirm it in the recipient's mailbox.Email Subject
[HENNGE Email DLP] メールルーティングテスト / Mail Routing Test
Email Body
※返信は不要です / No Reply Required 【日本語】 このテストメールは、ルーティング機能のご利用に際し、 HENNGE Email DLPシステムから、SMTPサーバー経由でのメール送信が可能かどうかを確認するために送信されました。 テストメールの受信を確認後、管理画面に戻り設定をすすめてください。 【English】 This test email has been sent to verify whether email transmission via SMTP server is possible from the HENNGE Email DLP system when using the routing function. After confirming receipt of this test email, please return to the management screen and proceed with the configuration.
- On the [Confirm Settings] screen, check the contents and press [Save].
※ If you do not want to activate routing immediately, leave the [Routing Status] inactive. -
Return to the [Routing] screen, and if the current settings are displayed, the process is complete.
※ The [Active / Inactive] setting for routing can be changed from this screen.
※ If the status is [Active], emails passing through Email DLP will be delivered to the specified mail server. - (Optional) If you wish to conduct a test after activating routing, send an email via Email DLP to an external address and check the history on both Email DLP and the external mail server to confirm that the email has been delivered.
■ FAQ
Q: The destination MTA also performs SPF validation, and emails routed from Email DLP fail SPF validation.
A: In addition to the default SPF record “include:spf.mta.hdems.com”, please add “include:spf-outbound.mo.hdems.com” to your records.
Add SPF Record