The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage domain name exceptions

Prev Next

Before you begin

Make sure that you have write access to the root admin domain.

You might want to exclude certain domains from DNS-based analysis for callback detection. Include all such domains in the domain name exceptions list in the Manager. You can also use the domain name exceptions list to exclude C&C server domains by the callback detectors.

Task

  1. Create a .csv file, which contains all domains to be included in the domain name exception list.
    Make sure that each domain name is separated by a comma.
    Sample .csv file


    The domain names, which you include in the domain name exceptions can contain any number of levels. However, for levels above the second level, the domain name in the DNS response must exactly match to be exempted.

    • For example, if the domain name exceptions contain .org, all domain names for which the top-level domain is .org are exempted.
    • If the domain name exceptions contain ntp.org, all domain names ending with ntp.org are exempted. For example, 1.pool.ntp.org is exempted.
    • If the domain name exceptions contain pool.ntp.org, the domain name in the DNS response must exactly be pool.ntp.org to be exempted. That is, 1.pol.ntp.org is not exempted.
    • If the domain name exceptions contain ntp.org and 1.pool.ntp.org, 2.pool.ntp.org is also exempted. If you have ntp.org in the domain name exceptions, you need not include 1.pool.ntp.org in the domain name exceptions.
    • As a best practice, make sure that you add all your organization's public and internal domain names to the exceptions list. If Trellix is an example, you add trellix.com and nai.org to the exception list. Add the first last two domain labels for such exceptions. That is, instead of www.trellix.com, add trellix.com. This ensures that Sensor resources are not spent on analyzing DNS traffic of known domains.
    • At a point in time, you can store up to 700 domain name exceptions in your Manager.
  2. In the Manager, select Policy → <Admin Domain Name> → Intrusion Prevention → Exceptions → Domain Names.
  3. To manage Callback Detection Exclusions:
    1. To import the domain names from the .csv file, click Other Actions → Import on the Callback Detection Exclusions tab.
    2. Import from CSV window appears. Browse the .csv file and click Import in the Import from CSV window.
      Import Domain Names from a CSV file


      The domain names are displayed in the Domain Names page.
      • Domain Name — Name of the domain imported
      • Last updated — Automatically populates the Date and Time when a domain name was imported and the user who imported it
      • Comment — Enter a comment for the required record names. Double-click the Comment column for a record and type in the comment.
      • You cannot include the comments in the .csv file when the domain names are imported. You can manually enter them in the Domain Names page.
      Imported domain names


    3. To add a single domain to the exclusion list, click
    4. To locate records in the Domain Names page, enter a string in the Search box.
      All records containing the entered string in any of the columns are listed.
      Search records


    5. To edit any record, double click the domain.
      You can edit the domain in the Domain Details pane. Click Save.
      Edit record


    6. To delete records, select the domain name and click .
      To delete all the records, click Other Actions → Delete All.
      Delete records


    7. To export the current list of domain name exceptions to a .csv file, click Other Actions → Export All and save the file.
      Only the domain names are exported and not the comments.

      You can also save all the existing domains. Click Save as CSV to save the existing list.

  4. To manage IPS Inspection Exclusions:
    1. To import the domain names from the .csv file, click Other Actions → Import on the IPS Inspection Exclusions tab.
    2. Import from CSV window appears. Browse the .csv file and click Import in the Import from CSV window.
      Import Domain Names from a CSV file


      The domain names are displayed in the Domain Names page.
      • Domain Name — Name of the domain imported
      • Last updated — Automatically populates the Date and Time when a domain name was imported and the user who imported it
      • Comment — Enter a comment for the required record names. Double-click the Comment column for a record and type in the comment. The comment is automatically saved when you click outside the column.
      • You cannot include the comments in the .csv file to be included when the domain names are imported. You can only manually enter them in the Domain Names page.
      Imported domain names


    3. To add a single domain to the exclusion list, click
    4. To locate records in the Domain Names page, enter a string in the Search box.
      All records containing the entered string in any of the columns are listed.
      Search records


    5. To edit any record, double click the domain.
      You can edit the domain in the Domain Details pane.

      Note

      You cannot edit the Domain Name for a default domain. You can either enable or disable a default domain name by selecting the domain and selecting the Enabled or Disabled option in the State drop-down list in Domain Details pane.

    6. To delete records, select the domain name and click .
      To delete all custom records, click Other Actions → Delete All Custom.
      Delete records


    7. To export the current list of custom domain name exceptions to a .csv file, click Other Actions → Export All Custom and save the file.
      Only the domain names are exported and not the comments.

      You can also save all the existing domains. Click Save as CSV to save the existing list.