Skip to main content

Policy & rule hierarchy

Policy hierarchy

Policies are applied in the following order:

  1. User

  2. Domain

  3. Organization

Example: A policy applied to joe.bloggs@example.com is evaluated before any domain-specific policy or the organization’s default policy.

Note

A user cannot have more than one policy.

For more information, see Policy templates.

Rule category hierarchy

Rule categories are applied in the following order:

  1. Edge Custom Rule

  2. Edge Allow Rule

  3. Edge Block Rule

  4. Custom Rule

  5. Allow Rule

  6. Block Rule

Example: An edge custom rule is evaluated before all other rule categories.

Custom rule execution hierarchy

Custom rules are evaluated in the following order. Within each scope, additional ordering applies based on the rule type.

Applied to: 

  1. User

  2. Domain

  3. Organization

Rule type: 

  1. Edge Custom Allow Rule: Sending email address

  2. Edge Custom Allow Rule: Sending domain name

  3. Edge Custom Block Rule: Sending email address

  4. Edge Custom Block Rule: Sending domain name

  5. Custom Allow Rule: Sending email address

  6. Custom Allow Rule: Sending domain name

  7. Custom Block Rule: Sending email address

  8. Custom Block Rule: Sending domain name

Example: An edge custom rule created for the user erich.zann@meshsecurity.io to deliver email from skinner@example.com is evaluated before other custom rules.

Allow / block rule execution hierarchy

Allow and block rules are evaluated in the following order. Within each scope, additional ordering applies based on the rule type.

Applied to: 

  1. User

  2. Domain

  3. Organization

Rule type: 

  1. Edge Allow Rule: Sending email address

  2. Edge Allow Rule: Sending domain name

  3. Edge Block Rule: Sending email address

  4. Edge Block Rule: Sending domain name

  5. Allow Rule: Sending email address

  6. Allow Rule: Sending domain name

  7. Block Rule: Sending email address

  8. Block Rule: Sending domain name

Example: An allow rule created for the user hans.moleman@meshsecurity.io to deliver email from john@example.com is evaluated before other allow or block rules, but after edge and custom rules.

Order of execution summary

The following tables illustrate the order of execution.

The filter processes the rules in this order: Table 1 > Table 2 > Table 3 > Table 4.

If no matching rule is found, the filter proceeds to the next check.

If a matching rule is found and executed, processing stops and subsequent rules are not evaluated.

For more information, see Rules.

Table 1 

Custom Rule 

Edge Slider Enabled 

Action 

Allow Email Address 

Allow Domain Name 

Block Email Address 

Block Domain Name 

User

1st

2nd

3rd

4th

Domain

5th

6th

7th

8th

Organisation

9th

10th

11th

12th

Table 2 

Allow / Block rule 

Edge Slider Enabled 

Action 

Allow Email Address 

Allow Domain Name 

Block Email Address 

Block Domain Name 

User

13th

14th

15th

16th

Domain

17th

18th

19th

20th

Organisation

21st

22nd

23rd

24th

Table 3 

Custom Rule 

Edge Slider Disabled 

Action 

Allow Email Address 

Allow Domain Name 

Block Email Address 

Block Domain Name 

User

25th

26th

27th

28th

Domain

29th

30th

31st

32nd

Organisation

33rd

34th

35th

36th

Table 4 

Allow / Block rule 

Edge Slider Disabled 

Action 

Allow Email Address 

Allow Domain Name 

Block Email Address 

Block Domain Name 

User

37th

38th

39th

40th

Domain

41st

42nd

43rd

44th

Organisation

45th

46th

47th

48th