Hi,
usual issue i have with using L7 filters is that we are not always aware of new smtp/proxy servers added by people in chareg of company infrastructure so you can also :
- ask network admin to forward you only outbound traffic (if this is what you want to cover with your DLP).
- An other way to detect inbound traffic is that for most companies it comes from your company email domain (like @mycompany.com) and email coming from internet use other domain thant this one. so you can add a rule in your policies.unfortunately it means you will have to set this rule in all your policies, and all email will be processed by each policies.
regards