You can add two types of information leakage prevention rules.
If you have enabled enterprise projects, ensure that you have all operation permissions for the project where your WAF instance locates. Then, you can select the project from the Enterprise Project drop-down list and configure protection policies for the domain names in the project.
You have added your website to a policy.
Information leakage prevention rules prevent sensitive information (such as ID numbers, phone numbers, and email addresses) from being disclosed. This type of rule can also block specified HTTP status codes.
To verify that WAF is protecting your domain name www.example.com against an information leakage prevention rule:
The email address, phone number, and identity number on the returned page are masked.