# Create primary DLP Gateway mail flow rule in Exchange On premise

## Introduction

This page covers the configuration of the primary mail flow rule for DLP Gateway in Exchange On-premise, which will be responsible for routing selected email traffic to Zivver.

## Getting started

1. Go to the Exchange Administrative Center (EAC).
2. Log into EAC as an administrator.
3. Click on **Mail flow** in the menu on the left.
4. Click on **Rules**.
5. Click on the _add_ button.
6. Click on **Create a new rule...**.
7. Enter `Zivver: Outbound DLP` for the name.
8. On the bottom of the window, click the **More options...** link.

## Set mail flow rule conditions

9. Under **\*Apply this rule if...** select **The sender...** and then **is external/internal**.
10. In the window that opens, select **Inside the organization**.
11. Click OK.
12. Add any other conditions you want to be satisfied for emails to be routed to Zivver DLP Gateway.

In case of a phased or partial roll-out of DLP Gateway, you can configure conditions based on sender characteristics, e.g., specific users, user groups, or email domains. Further information from Microsoft on mail flow rule conditions can be found in [Mail flow rule conditions and exceptions](https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/conditions-and-exceptions).

Any conditions you apply must apply to the entire message, not to any recipients of the message. Conditions applied on recipient level will lead to only the message to the recipient(s) matching the conditions being relayed to Zivver, resulting in split conversations.

## Set mail flow rule actions

13. Under **\*Do the following...** select **Modify the message properties...** and then **set a message header**.
14. Click the first **\*Enter text...** field.
15. Set the message header to `zivver-relay`.
16. Click OK.
17. Click the second **\*Enter text...** field.
18. Set the value to `smart`.
19. Click OK.
20. Click the add action button.
21. Under **And** select **Redirect the message to...** and then **these recipients**.
22. Look up the contact person that was created before. Then, select it.
23. Click add ->.
24. Click OK.

## Set mail flow rule exceptions

25. Under **Except if...** click the add exception button.
26. Select **The message headers ...** and then **matches these text patterns**.
27. Click the **\*Enter text...** field.
28. Set the message header to `skip-zivver-relay`.
29. Click OK.
30. Click the **\*Enter text patterns...** field.
31. Set the value to `true`.
32. Click the _add_ button.
33. Click OK.

If there are any further exclusions from DLP Gateway related to a phased or partial roll-out of DLP Gateway and/or specific to your organization, you can configure additional exceptions. Further information from Microsoft on mail flow rule exceptions can be found in [Mail flow rule conditions and exceptions](https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/conditions-and-exceptions).

## Set rule settings

34. Leave the **Audit this rule with severity level** on the default setting of **Not specified**.
35. Leave the **Choose a mode for this rule** on the default setting of **Enforce**.
36. Optional: Enable **Activate this rule on the following date** and select a date and time, if you want this mail flow rule be automatically activated from a specific date and time.
37. Leave **Deactivate this rule on the following date** disabled.
38. Enable the option **Stop processing more rules**.
39. Enable the option **Defer the message if rule processing doesn’t complete**.
40. Leave **Match sender address in message:** to the default setting of **Header**.
41. Enter the following text in the **Comments** section:
   
   ```plain
   Route outbound emails to Zivver for content classification, automatic information protection and human error prevention.
   ```

42. Carefully review all rule conditions, actions, exceptions and settings. Any errors in mail flow rule configuration may result in delivery issues of outbound emails.
43. When you are satisfied that the mail flow rule is configured correctly, click Save.
44. Under **ON**, deselect the checkbox to disable this mail flow rule. You will get instructions to enable this mail flow rule in a next chapter.

## Modify the priority of the mail flow rule, if needed

Make sure that the priority of all the existing rules is correct. If other rules must process a message first, make sure that the Primary DLP Gateway rule has a lower priority. Also, make sure that the other rules with a higher priority do not have the setting ‘Stop processing other rules’ enabled, unless you explicitly want messages that trigger this/these rule(s) not to be processed by DLP Gateway.

45. If you need to adjust the priority of the mail flow rule, find the mail flow rule you have created in the overview on the **Rules** page.
46. Click on the name of the rule and use the _arrow_upward_ or _arrow_downward_ buttons to move the mail flow rule up or down into the correct order of priority.
47. Alternatively, double click the name of the mail flow rule. In the window which opens, under **Priority**, enter the correct priority for the mail flow rule. Then click Save and wait for the setting to be saved.

## Next step

Go back to [Setup DLP Gateway](https://docs.zivver.com/en/admin/smtp/setup-dlp-gateway.html) and continue with Part 2.

Updated on 2026-06-18
