<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="Email_Security_Gateway,Email_Security_Gateway_Anywhere,apemail" />
    <META name="version" content="v82" />
    <META name="book" content="Forcepoint TRITON AP-EMAIL Administrator Help" />
    <title>Handling encrypted messages</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="https://help.forcepoint.com/docs/Tech_Pubs/index.html">Technical Library</a> | <a class="extLinks" href="https://support.forcepoint.com/s/">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="traffic_shaping_explain_esg.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="first_5.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="email_help_library.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="first_4.aspx">Managing Messages</a> &gt; Handling encrypted messages</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N1H-Heading1"><a name="598686">Handling encrypted messages</a></div>
      <div class="IN-TopicInfo"><a name="632418">Administrator Help | </a>TRITON AP-EMAIL | Version 8.2.x</div>
      <div class="B-Body"><a name="598687">An email content policy configured in the Data module may specify that a message should be encrypted for delivery. If you want to encrypt specific outbound messages, you must create an email DLP policy that includes an encryption action plan in the Data module (</a><span class="B-Bold">Main &gt; Policy Management &gt; DLP Policies</span>). </div>
      <div class="B-Body"><a name="640105">The following types of message encryption are supported:</a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="#598178" title="Handling encrypted messages" name="620866">Mandatory Transport Layer Security (TLS) encryption</a></span></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="#1149914" title="Handling encrypted messages" name="1149874">Advanced email encryption</a></span></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="#605174" title="Handling encrypted messages" name="620837">Third-party encryption application</a></span></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="LEM-LinkEmphasis"><a href="#1149957" title="Handling encrypted messages" name="1149882">Secure Message Delivery</a></span></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B-Body"><a name="620984">Use the </a><span class="B-Bold">Settings &gt; Inbound/Outbound &gt; Encryption</span> page to specify the type of encryption you want to use.</div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="598178">Mandatory Transport Layer Security (TLS) encryption</a></div>
      <div class="B-Body"><a name="621621">TLS is an Internet protocol that provides security for all email transmissions</a>&mdash;inbound, outbound, and internal. The client and server negotiate a secure "handshake" connection for the transmission to occur, provided both the client and the server support the same version of TLS. </div>
      <div class="B-Body"><a name="621680">In the Email </a>module, if you select only TLS for message encryption and the client and server cannot negotiate a secure TLS connection, the message is sent to a delayed message queue for a later delivery attempt. Select <span class="B-Bold">Transport Layer Security (TLS)</span> in the <span class="B-Bold">Encryption method</span> drop-down list and the <span class="B-Bold">Use TLS only (no backup encryption method; message is queued for later delivery attempt)</span> option to use only TLS for message encryption.</div>
      <div class="B-Body"><a name="621605">If you select TLS for message encryption, you can designate </a>one of the other encryption options as a backup method, in case the TLS connection fails. Specifying a backup option allows you a second opportunity for message encryption in the event of an unsuccessful TLS connection. If both the TLS and backup connections fail, the message is sent to a delayed message queue for a later connection attempt. </div>
      <div class="B-Body"><a name="1131091">Select the </a><span class="B-Bold">Transport Layer Security (TLS)</span> option in the <span class="B-Bold">Encryption method</span> drop-down list to enable TLS encryption. Then mark 1 of the following options to enable a backup encryption method:</div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="B-Bold"><a name="1149907">Use Advanced Email Encryption as backup encryption method. </a></span>This option is available only if your subscription includes the Email Hybrid Module.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt; vertical-align: baseline">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap; color: #000000; font-style: normal; font-variant: normal; font-weight: bold; text-transform: none">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner" style="color: #000000; font-style: normal; font-variant: normal; font-weight: bold; text-transform: none"><span class="B-Bold"><a name="1149908">Use third-party application as backup encryption method</a></span></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt; vertical-align: baseline">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap; color: #000000; font-style: normal; font-variant: normal; font-weight: bold; text-transform: none">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner" style="color: #000000; font-style: normal; font-variant: normal; font-weight: bold; text-transform: none"><a name="1149909">Use Secure Message Delivery as backup encryption method</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="1149914">Advanced email encryption</a></div>
      <div class="B-Body"><a name="1149918">If you want the email hybrid service to perform message encryption on outbound messages, select the </a><span class="B-Bold">Advanced Email Encryption</span> option in the <span class="B-Bold">Encryption method</span> drop-down list. Advanced email encryption is available only if your subscription includes the Email Hybrid Module and the Email Encryption Module, and the email hybrid service is registered and enabled. </div>
      <div class="B-Body"><a name="1149919">You can also specify advanced email encryption as a backup encryption method if mandatory TLS encryption is selected. See </a><span class="LEM-LinkEmphasis"><a href="#598178" title="Handling encrypted messages">Mandatory Transport Layer Security (TLS) encryption</a></span> for details. </div>
      <div class="B-Body"><a name="1149923">When an email DLP policy identifies an outbound message for encryption, the message is sent to the email hybrid service via a TLS connection. If the secure connection is not made, the message is placed in a delayed message queue for a later delivery attempt. </a></div>
      <div class="B-Body"><a name="1149924">The SMTP server addresses used to route email to the email hybrid service for encryption are configured in the Email Hybrid Module registration process. Use the Delivery Route page under </a><span class="B-Bold">Settings&nbsp;&gt; Hybrid Service&nbsp;&gt; Hybrid Configuration </span>to add outbound SMTP server addresses (see <span class="LEM-LinkEmphasis"><a href="hybrid_delivery_routes_esg.aspx" title="Define delivery routes">Define delivery routes</a></span>). </div>
      <div class="B-Body"><a name="1149928">If the email hybrid service detects spam or a virus in an encrypted outbound message, the mail is returned to the message sender.</a></div>
      <div class="B-Body"><a name="1149929">The email hybrid service attempts to decrypt inbound encrypted mail, and adds an x-header to the message to indicate whether the decryption operation succeeded. Message analysis is performed regardless of whether message decryption is successful.</a></div>
      <div class="B-Body"><a name="1149930">The hybrid service does not encrypt inbound or internal mail. A DLP policy must be modified to designate only outbound messages for encryption when the email hybrid service is used. </a></div>
      <div class="B-Body"><a name="1149932">Find more information about advanced email encryption in </a><span class="URL-URL"><a href="https://help.forcepoint.com/docs/email/v82/esg_encryption/first.aspx" target="external_window">Forcepoint Email Encryption</a></span> in the Technical Library.</div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="605174">Third-party encryption application</a></div>
      <div class="B-Body"><a name="605196">The email protection system supports the use of third-party software for email encryption. The third-party application used must support the use of x-headers for communication with the email system. </a></div>
      <div class="B-Body"><a name="621940">You can also specify third-party application encryption as a backup encryption method if mandatory TLS encryption is selected. See </a><span class="LEM-LinkEmphasis"><a href="#598178" title="Handling encrypted messages">Mandatory Transport Layer Security (TLS) encryption</a></span> for details. </div>
      <div class="B-Body"><a name="621081">The email protection system can be configured to add an x-header to a message that triggers a DLP encryption policy. Other x-headers indicate encryption success or failure. These x-headers facilitate communication between the email system and the encryption software. You must ensure that the x-header settings made in the Encryption page match the corresponding settings in the third-party software configuration. </a></div>
      <div class="B-Body"><a name="617258">X-header settings are entered on the </a><span class="B-Bold">Settings &gt; Inbound/Outbound &gt; Encryption </span>page. Select <span class="B-Bold">Third-party application</span> in the <span class="B-Bold">Encryption method</span> drop-down list to configure the use of external encryption software. Use the following steps to configure third-party application encryption:</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605284">Add encryption servers (up to 32) to the Encryption Server List:</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="SA-StepAlpha_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="SA-StepAlpha_inner" style="width: 18pt; white-space: nowrap">a.	</div>
            </td>
            <td width="100%">
              <div class="SA-StepAlpha_inner"><a name="605294">Enter each server's IP address or hostname and port number. </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="SA-StepAlpha_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="SA-StepAlpha_inner" style="width: 18pt; white-space: nowrap">b.	</div>
            </td>
            <td width="100%">
              <div class="SA-StepAlpha_inner"><a name="615817">If you want to use the MX lookup feature, mark the </a><span class="B-Bold">Enable MX lookup</span> check box.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="SA-StepAlpha_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="SA-StepAlpha_inner" style="width: 18pt; white-space: nowrap">c.	</div>
            </td>
            <td width="100%">
              <div class="SA-StepAlpha_inner"><a name="605307">Click the arrow to the right of the Add Encryption Server box to add the server to the Encryption Server List. </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="605323">If you want to delete a server from the list, select it and click </a><span class="B-Bold">Remove</span>.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605341">In the </a><span class="B-Bold">Encrypted IP address group</span> drop-down list, specify an IP address group if decryption is enabled or if encrypted email is configured to route back to the email software. Default is Encryption Gateway.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605366">If you want users to present credentials to view encrypted mail, mark the </a><span class="B-Bold">Require authentication</span> check box and supply the desired user name and password in the appropriate fields. Authentication must be supported and configured on your encryption server to use this function. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605383">In the </a><span class="B-Bold">Encryption X-Header</span> field, specify an x-header to be added to a message that should be encrypted. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">5.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605393">In the </a><span class="B-Bold">Encryption Success X-Header</span> field, specify an x-header to be added to a message that has been successfully encrypted. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">6.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605400">In the </a><span class="B-Bold">Encryption Failure X-Header</span> field, specify an x-header to be added to a message for which encryption has failed. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">7.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="605407">Select any desired encryption failure options:</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149942">Mark the </a><span class="B-Bold">Isolate messages to queue</span> check box if you want to enable that option. Select a queue for isolated messages from the drop-down list (default is the virus queue).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="605447">Mark the </a><span class="B-Bold">Send notification to original sender</span> check box if you want to enable that option. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I2-IndentedText2"><a name="605454">In the Notification Details section, enter the notification message subject and content in the appropriate fields. Mark the </a><span class="B-Bold">Attach original message</span> check box if you want the original message included as an attachment to the notification message.</div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="605467">Select </a><span class="B-Bold">Deliver message</span> (default) if you want the message that failed the encryption operation delivered.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1037171">Select </a><span class="B-Bold">Drop message</span> if you do not want the message that failed the encryption operation delivered.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">8.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="1149948">Mark the </a><span class="B-Bold">Enable decryption</span> check box if you want to decrypt encrypted messages. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">9.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="1149949">Select any desired decryption options:</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149950">In the </a><span class="B-Bold">Content type</span> field, enter the message content types to decrypt, separated by semicolons. Maximum length is 49 characters. Default entries include multipart/signed, multipart/encrypted, and application/pkcs7-mime.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149951">In the </a><span class="B-Bold">X-Header</span> field, specify a message x-header that identifies a message to decrypt. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149952">In the </a><span class="B-Bold">Decryption X-Header</span> field, specify an x-header to be added to a message that should be decrypted. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149953">In the </a><span class="B-Bold">Decryption Success X-Header</span> field, specify an x-header to be added to a message that has been successfully decrypted. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149954">In the </a><span class="B-Bold">Decryption Failure X-Header </span>field, specify an x-header to be added to a message for which decryption has failed. This x-header value must also be set and enabled on your encryption server. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="1149955">If you want to forward a message that has failed decryption to a specific queue, mark the </a><span class="B-Bold">On decryption failure</span> check box, and select a queue for these messages from the drop-down list (default is the virus queue).            </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="1149957">Secure Message Delivery</a></div>
      <div class="B-Body"><a name="1149961">Secure Message Delivery is an on-premises encryption method that lets you configure delivery options for a secure portal in which your organization's customers may view, send, and manage encrypted email. For example, you may wish to include sensitive personal financial information in a message to a client. The portal provides a secure location for the transmission of this data.</a></div>
      <div class="B-Body"><a name="1149968">Users within your organization who send and receive secure messages handle these messages via their local email clients, not the secure portal.</a></div>
      <div class="B-Body"><a name="1149969">Secure messages are stored in a default secure-encryption queue (</a><span class="B-Bold">Main &gt; Message Management &gt; Message Queues</span>). You can search for and delete messages in the secure-encryption queue view. Message details may not be viewed. The maximum queue size and number of days a message is retained are configured on the Edit Queue page. </div>
      <div class="B-Body"><a name="1149970">Select </a><span class="B-Bold">Secure Message Delivery</span> from the <span class="B-Bold">Encryption method</span> drop-down list to display secure messaging options, including a template for the notification that users receive to alert them to encrypted mail. </div>
      <div class="B-Body"><a name="1149971">You can also specify Secure Message Delivery as a backup encryption method if mandatory TLS encryption is selected. See </a><span class="LEM-LinkEmphasis"><a href="#598178" title="Handling encrypted messages">Mandatory Transport Layer Security (TLS) encryption</a></span> for details. </div>
      <div class="B-Body"><a name="1149975">Use the following steps to configure Secure Message Delivery encryption:</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="1149976">Enter the IP address or hostname for the appliance that hosts the secure message delivery portal (maximum length for hostname is 64 characters). </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="1149977">Entering a hostname rather than an IP address is recommended in order to avoid potential Microsoft Outlook warning messages generated in an end user's inbox by the notification message.</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="1149980">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="1149982">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="1149983">The entry in this field should be mapped to the E1 interface (for a V10000 G2/G3 appliance) or the P1 interface (for a V5000 G2 appliance). Ensure that the interface you use is visible from outside your internal network.  </a></div>
          </td>
        </tr>
      </table>
      <div class="I-IndentedText"><a name="1149984">If you have an appliance cluster, enter the IP address or hostname for 1 cluster appliance (primary or secondary). The cluster load balancing function directs traffic appropriately. </a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="1149987">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="1149989">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="1149990">Secure messaging uses the same port configured for the Personal Email Manager portal (</a><span class="B-Bold">Settings &gt; Personal Email &gt; Notification Message</span>). </div>
          </td>
        </tr>
      </table>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="1149991">Specify the actions that your customers are allowed to perform in the secure portal, along with the types of recipients to whom these users can send secure messages:</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1149992">Enforce strong password policy. </a></span>With this policy in force, an end-user password must meet the following requirements:</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B3-Bullet3_outer" style="margin-left: 36pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B3-Bullet3_inner" style="width: 18pt; white-space: nowrap">
                <img src="b3.png" alt="*" border="0" width="7" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B3-Bullet3_inner"><a name="1149993">Between 8 and 15 characters</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B3-Bullet3_outer" style="margin-left: 36pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B3-Bullet3_inner" style="width: 18pt; white-space: nowrap">
                <img src="b3.png" alt="*" border="0" width="7" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B3-Bullet3_inner"><a name="1149994">At least 1 uppercase letter</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B3-Bullet3_outer" style="margin-left: 36pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B3-Bullet3_inner" style="width: 18pt; white-space: nowrap">
                <img src="b3.png" alt="*" border="0" width="7" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B3-Bullet3_inner"><a name="1149995">At least 1 lowercase letter</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B3-Bullet3_outer" style="margin-left: 36pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B3-Bullet3_inner" style="width: 18pt; white-space: nowrap">
                <img src="b3.png" alt="*" border="0" width="7" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B3-Bullet3_inner"><a name="1149996">At least 1 number</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B3-Bullet3_outer" style="margin-left: 36pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B3-Bullet3_inner" style="width: 18pt; white-space: nowrap">
                <img src="b3.png" alt="*" border="0" width="7" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B3-Bullet3_inner"><a name="1149997">At least 1 special character; supported characters include: </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I3-IndentedText3"><a name="1149998">! " # $ &amp; ' ( ) * + , -  . / : ; &lt; = &gt; ? @ [ \ ] ^ _ ` { | } ~</a></div>
      <div class="I2-IndentedText2"><a name="1149999">End users are prompted to create strong passwords in the Secure Messaging portal. </a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150000">Maximum message size.</a></span> Customer message size includes any attachments. Default value is 50 MB; maximum value is 100 MB.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150001">Reply all to secure messages received in the portal</a></span>. Customer may reply to all message recipients. However, if the <span class="B-Bold">Internal domain email addresses only</span> option is selected for Allowed Recipients, user may reply only to recipients inside your organization.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I2-IndentedText2"><a name="1150002">The recipient list cannot be modified for this type of message.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150003">Forward secure messages received in the portal</a></span>. Customer may forward to allowed recipients any secure message received.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150004">Compose new secure messages within the portal</a></span>. Customer may compose and send a new secure message to allowed recipients.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150005">Attach files to secure messages sent from the portal.</a></span> Customer may send an attachment in a secure message</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="1150006">These options are all selected by default.</a></div>
      <div class="I-IndentedText"><a name="1150007">The Allowed Recipients box offers options for the types of recipients to whom your customer may reply, forward, or send new secure messages. For security purposes, the recipient list must include at least 1 email address within your organization.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150008">Internal domain email addresses only</a></span>. Only email addresses within your organization's protected domains may be specified as recipients. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><span class="B-Bold"><a name="1150009">Internal and external domain email addresses (at least one internal email address required)</a></span>. Email addresses outside your organization's protected domains may be specified as recipients, but at least 1 address within your domains must be entered (default selection). </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I2-IndentedText2"><a name="1150013">See </a><span class="LEM-LinkEmphasis"><a href="managing_domain_and_ip_groups_explain_esg.aspx#640845" title="Managing domain and IP address groups">Protected Domain group</a></span> for more information about determining your protected domains.</div>
      <div class="B-Body"><a name="1150014">The Secure Email End-User Notification area contains a message template for the email that users receive when secure messages sent to them have been delivered to the portal for viewing. Use the default template, or customize it to suit your needs. You must include the $URL$ field in your notification, because that creates the link your customer clicks to access the secure email portal. </a></div>
      <div class="B-Body"><a name="1150015">Enter 1 sender address for the notification in the </a><span class="B-Bold">Sender</span> field, and specify an email subject in the <span class="B-Bold">Subject</span> field. The sender address must belong to your internal protected domain. Because you do not want responses to the notification, ensure that the sender address is configured to drop any direct replies to the notification.</div>
      <div class="B-Body"><a name="1150016">After you have configured your notification message, click </a><span class="B-Bold">Preview Message</span> to view it.</div>
      <div class="B-Body"><a name="1150017">The portal can be displayed in 1 of 9 languages, which the user selects during the registration process. The </a><span class="URL-URL"><a href="https://help.forcepoint.com/docs/email/v82/esg_smd_user_help/first.aspx" target="external_window">Forcepoint Secure Messaging User Help</a></span> is available in the Technical Library, also in 9 languages. It describes the user registration process and how to use the secure message portal. </div>
      <div class="B-Body"><a name="633952">&nbsp;</a></div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="traffic_shaping_explain_esg.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="first_5.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="email_help_library.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="first_4.aspx">Managing Messages</a> &gt; Handling encrypted messages</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2016 Forcepoint LLC. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:esg82help:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>