# Create primary DLP Gateway mail flow rule in Exchange Online

## Introduction

This page covers the configuration of the primary mail flow rule for DLP Gateway in Exchange Online, which will be responsible for routing selected email traffic to Zivver.

## Getting started

1. Go to the [Exchange Admin Center](https://admin.exchange.microsoft.com/).
2. Click on **Mail flow** in the menu on the left.
3. Click on **Rules**.
4. Click on _add_ **Add a rule**.
5. Click on **Create a new rule**.
6. Enter `Zivver: Outbound DLP` for the name.

## Set mail flow rule conditions

7. Under **Apply this rule if ** select **The sender**.
8. Under **Select one** select **is external/internal**.
9. In the side pane that opens, select **Inside the organization**.
10. Click Save.
11. Add any other conditions you want to be satisfied for emails to be routed to Zivver DLP Gateway.

Info

In case of a phased or partial roll-out of DLP Gateway, you can configure conditions based on sender characteristics, e.g., specific users, user groups, or email domains. Further information from Microsoft on mail flow rule conditions can be found in [Mail flow rule conditions and exceptions](https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/conditions-and-exceptions).

Note

Any conditions you apply must apply to the entire message, not to any recipients of the message. Conditions applied on recipient level will lead to only the message to the recipient(s) matching the conditions being relayed to Zivver, resulting in split conversations.

## Set mail flow rule actions

12. Under **Do the following ** select **Modify the message properties**.
13. Under **Select one** select **set a message header**.
14. Click the first **Enter text** field.
15. Set the message header to `zivver-relay`.
16. Click Save.
17. Click the second **Enter text** field.
18. Set the value to `smart`.
19. Click Save.
20. Click the _add_ button to the right of **set a message header**.
21. Under **And** select **Redirect the message to**.
22. Under **Select one** select **the following connector**.
23. Select the `Zivver Send Connector` connector.
24. Click Save.

## Set mail flow rule exceptions

25. Under **Except if** select **The message headers…**.
26. Under **Select one** select **matches these text patterns**.
27. Click the **Enter text** field.
28. Set the message header to `skip-zivver-relay`.
29. Click Save.
30. Click the **Enter words** field.
31. Set the value to `true`.
32. Click Add.
33. Click Save.
34. Click Next.

Tip

If there are any further exclusions from DLP Gateway related to a phased or partial roll-out of DLP Gateway and/or specific to your organization, you can configure additional exceptions. Further information from Microsoft on mail flow rule exceptions can be found in [Mail flow rule conditions and exceptions](https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/conditions-and-exceptions).

## Set rule settings

35. Leave the **Rule mode** on the default setting of **Enforce**.
36. Leave the **Severity** on the default setting of **Not specified**.
37. Optional: Enable **Activate this rule on** and select a date and time, if you want this mail flow rule be automatically activated from a specific date and time.
38. Leave **Deactivate this rule on** disabled.
39. Enable the option **Stop processing more rules**.
40. Enable the option **Defer the message if rule processing doesn’t complete**.
41. Leave **Match sender address in message** to the default setting of **Header**.
42. Enter the following text in the **Comments** section:

```plaintext
Route outbound emails to Zivver for content classification, automatic information protection and human error prevention.
```

43. Click Next.

## Review and finish

44. Carefully review all rule conditions, actions, exceptions and settings. Any errors in mail flow rule configuration may result in delivery issues of outbound emails.
45. When you are satisfied that the mail flow rule is configured correctly, click Finish.

## Modify the priority of the mail flow rule, if needed

Warning

Make sure that the priority of all the existing rules is correct. If other rules must process a message first, make sure that the Primary DLP Gateway rule has a lower priority. Also, make sure that the other rules with a higher priority do not have the setting ‘Stop processing other rules’ enabled, unless you explicitly want messages that trigger this/these rule(s) not to be processed by DLP Gateway.

46. If you need to adjust the priority of the mail flow rule, find the mail flow rule you have created in the overview on the **Rules** page
47. Check the checkbox to the left of **Disabled** and use the _expand_less_ **Move up** or _expand_more_ **Move down** buttons to move the mail flow rule up or down into the correct order of priority.
48. Alternatively, click the name of the mail flow rule. In the side pane which opens, select _settings_ **Edit rule settings**. Then, under **Priority **, enter the correct priority for the mail flow rule. Then click Save and wait for the setting to be saved.

## Next step

Go back to [Setup DLP Gateway](https://docs.zivver.com/en/admin/smtp/setup-dlp-gateway.html) and continue with Part 2.

Updated on 2026-06-18
