Policy & rule hierarchy
Policy hierarchy
Policies are applied in the following order:
User
Domain
Organization
Example: A policy applied to joe.bloggs@example.com is evaluated before any domain-specific policy or the organization’s default policy.
Note
A user cannot have more than one policy.
For more information, see Policy templates.
Rule category hierarchy
Rule categories are applied in the following order:
Edge Custom Rule
Edge Allow Rule
Edge Block Rule
Custom Rule
Allow Rule
Block Rule
Example: An edge custom rule is evaluated before all other rule categories.
Custom rule execution hierarchy
Custom rules are evaluated in the following order. Within each scope, additional ordering applies based on the rule type.
Applied to:
User
Domain
Organization
Rule type:
Edge Custom Allow Rule: Sending email address
Edge Custom Allow Rule: Sending domain name
Edge Custom Block Rule: Sending email address
Edge Custom Block Rule: Sending domain name
Custom Allow Rule: Sending email address
Custom Allow Rule: Sending domain name
Custom Block Rule: Sending email address
Custom Block Rule: Sending domain name
Example: An edge custom rule created for the user erich.zann@meshsecurity.io to deliver email from skinner@example.com is evaluated before other custom rules.
Allow / block rule execution hierarchy
Allow and block rules are evaluated in the following order. Within each scope, additional ordering applies based on the rule type.
Applied to:
User
Domain
Organization
Rule type:
Edge Allow Rule: Sending email address
Edge Allow Rule: Sending domain name
Edge Block Rule: Sending email address
Edge Block Rule: Sending domain name
Allow Rule: Sending email address
Allow Rule: Sending domain name
Block Rule: Sending email address
Block Rule: Sending domain name
Example: An allow rule created for the user hans.moleman@meshsecurity.io to deliver email from john@example.com is evaluated before other allow or block rules, but after edge and custom rules.
Order of execution summary
The following tables illustrate the order of execution.
The filter processes the rules in this order: Table 1 > Table 2 > Table 3 > Table 4.
If no matching rule is found, the filter proceeds to the next check.
If a matching rule is found and executed, processing stops and subsequent rules are not evaluated.
For more information, see Rules.
Table 1 Custom Rule | Edge Slider Enabled | |||
|---|---|---|---|---|
Action | Allow Email Address | Allow Domain Name | Block Email Address | Block Domain Name |
User | 1st | 2nd | 3rd | 4th |
Domain | 5th | 6th | 7th | 8th |
Organisation | 9th | 10th | 11th | 12th |
Table 2 Allow / Block rule | Edge Slider Enabled | |||
|---|---|---|---|---|
Action | Allow Email Address | Allow Domain Name | Block Email Address | Block Domain Name |
User | 13th | 14th | 15th | 16th |
Domain | 17th | 18th | 19th | 20th |
Organisation | 21st | 22nd | 23rd | 24th |
Table 3 Custom Rule | Edge Slider Disabled | |||
|---|---|---|---|---|
Action | Allow Email Address | Allow Domain Name | Block Email Address | Block Domain Name |
User | 25th | 26th | 27th | 28th |
Domain | 29th | 30th | 31st | 32nd |
Organisation | 33rd | 34th | 35th | 36th |
Table 4 Allow / Block rule | Edge Slider Disabled | |||
|---|---|---|---|---|
Action | Allow Email Address | Allow Domain Name | Block Email Address | Block Domain Name |
User | 37th | 38th | 39th | 40th |
Domain | 41st | 42nd | 43rd | 44th |
Organisation | 45th | 46th | 47th | 48th |