Skip to content
  • There are no suggestions because the search field is empty.

Set up DLP Observe and Report

DLP Observe and Report scans your mail for sensitive data patterns you don't have a rule for yet, and surfaces them as suggestions, without quarantining a message. Use it to find gaps in your DLP coverage.

How DLP Observe and Report works

DLP Observe and Report looks for keyword matching and utilizes an AI scan that classifies findings into six categories: PHI, PII, Financial, Credentials, Proprietary, and Legal, each with a severity rating. Both look for patterns that aren't covered by existing rules, with evidence showing exactly what matched and where in the message. Marketing and bulk list mail is excluded before the AI scan runs, which keeps false positives low.

DLP Observe and Report never quarantines, holds, or delays a message. It only records a match and notifies admins.

Turn on DLP Observe and Report

  1. Log in to your Paubox dashboard
  2. Navigate to Paubox Email Suite > DLP > Settings
  3. Turn on Behavioral Observation

Behavioral Observation runs independently of your DLP mode. You can turn it on whether your DLP mode is set to Off or Enforce. DLP Observe and Report requires Paubox DLP, available with PES Premium.

 

Review findings in the Observations tab

Matches appear in Paubox Email Suite > DLP > Observations, an admin-only tab showing activity from the last 30 days. Findings are grouped into suggestion cards by category and policy, with a match count, unique sender count, and an evidence preview.

Each card gives you two options:

  • Create rule opens DLP AI Chat with the observation's details already filled in as a starting prompt. Depending on what needs to be caught, DLP AI Chat drafts either a keyword rule or an AI rule for you to review and save. Once you save it, the rule is linked back to that observation and the card clears from the tab. 
  • Dismiss hides the card for you. It reappears if new matching messages push the count back up.

Categories already covered by an active AI rule are filtered out automatically, so the Observations tab only surfaces patterns you haven't addressed yet.

 

Email reports

While Observe and Report is on, Paubox sends two scheduled reports.

An hourly report lists each match from that hour, grouped by direction, with the sender, recipient, matched policy, and a preview of the matched evidence.

A daily digest rolls up the day's matches by category, with a View Observations button linking back to the dashboard.

Both reports go out even when nothing was found, confirming there's nothing to review.

Only admins and users granted the DLP notifications permission receive these reports. Evidence previews are truncated to the matched portion of the message, and long addresses are shortened. Full values and policy settings are available in the Paubox dashboard.