Skip to main content

[ADVANCED] How to enable DLP (Data Loss Prevention)?

This option in only available with Protect Advanced

Aveline avatar
Written by Aveline
Updated this week

What is the DLP feature?

The DLP (Data Loss Prevention) feature makes it possible to detect and block the sending of outbound emails containing sensitive data (e.g. passwords, social security numbers, IBANs, etc.), in order to reduce the risk of information leaks.

What are the prerequisites to enable DLP?

Before enabling DLP, you must:

  • Have Protect Out enabled and in use

  • Have the Protect Advanced offer
    (The DLP feature is not available on the Protect Essential offer)

How to enable DLP?

You can enable DLP from the Protect interface, in General Settings.

Once enabled, analyses automatically start on outbound emails passing through the Mailinblack Protect solution.

What operating modes are available?

DLP offers two modes:

  • Apply automatic detection of sensitive data in outbound emails

  • Apply custom detection of sensitive data in outbound emails

1. Automatic detection

This mode is recommended if you want simple and fast protection.

  • Automatic detection of common sensitive data

Examples:

  • Social security number

  • Password

  • IBAN

  • No technical configuration required

👉 Ideal if you are not familiar with technical expressions and want standard blocking on outbound emails.

2. Custom detection

This mode allows tailored detection according to your needs.

  • Import of a CSV file (a template is provided)

File content:

  • 1 keyword per line, or

  • 1 regular expression (regex) per line

As long as there is one element per line, the format is valid.

In this context:

  • The file is visible and downloadable from the interface

  • It can be re-imported to allow modification (adding new words or expressions)

  • It is possible to delete the file if necessary

What happens once DLP is enabled?

Outbound emails are analyzed on:

  • The subject

  • The email body

In case sensitive data is detected:

  • The email is blocked and quarantined in Outbound Emails

  • It is tagged “Sensitive data”

Is the user informed if their email is blocked?

The user receives a notification email indicating the reason for the block (e.g. “password detected”).

The content is never displayed (the password or the specific data is not revealed).

Can managers be notified when an outbound email is blocked?

Managers can enable alerts to be informed by email when an outbound email is blocked due to sensitive data.

To enable the alert:

Go to Protect → Settings → Alerts, then check “Blocked Sensitive data”.

Can DLP be enabled only for certain users?

It is possible to create rules to enable DLP for a specific user group from
Settings → Rules → Edit or add a rule.

This allows a gradual or targeted deployment according to your internal needs.

Did this answer your question?