DLP (Data Loss Prevention): Overview
What is DLP?
Paubox Data Loss Prevention (DLP) scans outgoing email from your organization to prevent sensitive data from leaking externally, whether accidentally or maliciously. With DLP, you can customize your scanning criteria to look for sensitive keywords in inbound or outbound messages. Any emails that include sensitive information will be placed into quarantine and can be released or blocked by the administrator. DLP is available with Email Suite Premium.
DLP access
DLP can be managed by any user with the DLP admin permissions set up. Learn more about user roles and permissions here.
Common ways to use DLP rules
Admins can configure rules to target various types of sensitive data. Common use cases include:
-
Identifying PHI by creating rules related to patient names, medical record numbers, or Social Security numbers
-
Blocking specific domains or email addresses (e.g., @gmail.com or @yahoo.com) or unauthorized third-party vendors
-
Monitoring URL extensions by flagging emails containing links to specific types of links
-
Filtering by contact information like phone numbers or physical addresses
-
Internal policy enforcements such as case codes or project codenames
Creating DLP rules
DLP rules help you safeguard sensitive information by automatically scanning emails for specific keywords. If a match is found, the email can be quarantined for further review.
To create a rule:
- In the Paubox dashboard, navigate to Data Loss Prevention in the side menu
- Click on Add Rule
Describe what you want to catch in plain English to DLP AI Chat, and it drafts a rule for you to review and save. DLP AI Chat decides whether your request needs a keyword rule (a literal match) or an AI rule (evaluating intent, for cases a literal match can't cover), and both types work together in your Rules list.
What happens if an email is caught by DLP?
- Outbound emails
- The email is placed in quarantine
- The sender is notified
- Admins and users with DLP notifications permissions are alerted
- Inbound emails
- The email is placed in quarantine
- Admins and users with DLP notifications permissions are alerted
Admins can review quarantined emails and choose to release or block them.
Quarantined messages include a plain-English explanation of why they were caught, and the quarantine dashboard shows which rule matched.
DLP Notifyees
A DLP Notifyee is a designated user who receives alerts whenever an email is caught by DLP. To assign a Notifyee, update roles and permissions in the Users settings.
FAQs
Will DLP scan attachments?
Yes, if your rule is set to scan the Full email or the Body of the email.
Can I exempt certain senders from outbound DLP scanning?
No, exemptions for outbound DLP scanning are not supported.
Can all Admins see DLP rules?
No, only Admins with the DLP Admin permission can view and manage DLP rules.