When you set up your HES Outbound Filtering, the recipients will not be able to receive the notification e-mail to their gmail account once a file is shared.
This happens when the "message from:" is drive-shares-noreply@google.com and the "envelope from:" is *@doclist.bounces.google.com since Mail forwarding to an external address will not work when an outbound mail was scanned by HES as stated in KB 1054008.
You will get the following bounced message from G Suite E-mail log Search:
- Bounced
- Google tried to deliver your message, but it was rejected by the server for the recipient domain <a href="http://relay.hes.trendmicro.com" target="_blank">relay.hes.trendmicro.com</a> [54.219.191.109]. The error that the other server returned was: 554 5.7.1 : Recipient address rejected: NO-DOMAIN.
Since safelisting of the sender drive-shares-noreply@google.com is a potential risk to other HES users, it is not possible to allow the sender domain from: *@doclist.bounces.google.com to HES relay service.
Creating a custom compliance template from G Suite for this type of google drive notification will resolve the issue of the bounced messages and able to receive the notification e-mail, to do this:
- On Your Google Admin console (at admin.google.com), go to Apps > G Suite > G-mail > Advanced Settings.
- Scroll to the Content compliance setting in the Compliance section, hover over the setting then click Configure. If the setting is already configured, hover over the setting then click Edit or Add another.
-
For each new setting, enter a unique description then modify the following:
-
Under Email messages to affect, select the following:
- Outbound
- Internal - Sending
Click image to enlarge
-
Add expressions that describe the content you want to search for in each message:
- Select If ANY of the following match the message.
- Under Expressions select Advanced Content Match.
- Under Location select Sender header.
- Match type select contains text then type drive-shares-noreply@google.com
- Click Save.
Click image to enlarge
-
-
If the above expressions match, do the following:
- Select Modify message.
- Under Route, tick the Change Route checkbox then select Normal Routing.
Click image to enlarge
- Save all the changes.