As detailed on the support thread here:
https://www-secure.symantec.com/connect/forums/inc...
DLP Network inidents can be sorted by Sender or Domain. However they cannot be sorted based on the Recipient field. This field is available for a filter with specific criteria, but cannot be used for listing and summarizing all incidents by recipient field.
Current workarounds are to sort by domain or top recipient domains and view manually.
Adding recipient as a summarization criteria would allow for more accurate and effective incident reviews. It would allow for simplified white/black-list composition and would give administrators a more capable tool than domain-based sorting.