Skip to main content

Configuring DLP Policies

Data Loss Prevention (DLP) monitors outbound email for sensitive information and can block, quarantine, or flag emails that match defined rules. This helps prevent accidental or intentional leakage of confidential data.

How DLP works

When an email is sent, DLP scans the subject, body, and attachments against your configured policies. If a match is found, the configured action is taken — the email can be blocked, quarantined for review, or delivered with an alert generated.

Accessing DLP settings

  1. Log in to https://cyberprotect.bamboozle.me.
  2. Click Email Archiving in the left sidebar.
  3. Click DLP Policies.

[SCREENSHOT: DLP Policies main screen]

Creating a DLP policy

  1. Click Create policy.
  2. Give the policy a descriptive name such as "Block credit card numbers" or "Flag passport numbers".
  3. Configure the policy conditions:

Conditions

Conditions define what the policy looks for in emails:

Condition typeExamples
Sensitive data typesCredit card numbers, passport numbers, UAE Emirates ID, IBAN
KeywordsSpecific words or phrases such as "confidential" or "do not distribute"
Regex patternCustom regular expression for specific data formats
Attachment typeBlock emails containing specific file types such as .exe or encrypted archives
Recipient domainFlag emails sent to specific external domains

[SCREENSHOT: DLP policy condition configuration screen]

Actions

Actions define what happens when a condition is matched:

ActionDescription
BlockThe email is not delivered and the sender receives a bounce notification
QuarantineThe email is held for administrator review before delivery
Deliver with alertThe email is delivered normally but an alert is generated in the console
Notify administratorAn email notification is sent to the administrator
Notify senderThe sender receives an email warning that their message triggered a DLP policy

[SCREENSHOT: DLP policy action selection screen]

  1. Set the Scope — which mailboxes or groups the policy applies to.
  2. Set the Priority — if multiple policies match an email, the one with the highest priority takes effect.
  3. Toggle the policy to Active.
  4. Click Save.

Built-in sensitive data types

Bamboozle DLP includes built-in detection for common sensitive data types including:

  • Credit and debit card numbers (Visa, Mastercard, Amex, etc.)
  • UAE Emirates ID numbers
  • Passport numbers
  • IBAN and bank account numbers
  • Tax identification numbers
  • Social security numbers
  • Medical record identifiers

Select any of these from the condition dropdown — no configuration required as the detection patterns are pre-built.

[SCREENSHOT: Sensitive data type selection dropdown]

Reviewing quarantined email

When a policy with the Quarantine action matches an email, it appears in the DLP quarantine queue for administrator review.

  1. Click Email Archiving then DLP Quarantine.
  2. Review each quarantined email — you can see the full content and which policy triggered it.
  3. For each email, choose:
    • Release — deliver the email to the recipient
    • Release and whitelist — deliver and add sender or content to a whitelist so future similar emails are not quarantined
    • Delete — delete the email without delivering it

[SCREENSHOT: DLP quarantine queue with review options]

Whitelisting trusted senders or content

If a DLP policy is regularly catching legitimate emails from a specific sender or containing specific content, add a whitelist entry:

  1. Go to DLP Policies then Whitelist.
  2. Click Add entry.
  3. Define the whitelist condition — sender email, sender domain, or specific content pattern.
  4. Click Save.

[SCREENSHOT: DLP whitelist configuration screen]

DLP reporting

To see a summary of DLP activity:

  1. Click Monitoring then Reports.
  2. Create a new report or look for the DLP summary widget.
  3. The report shows how many emails were scanned, how many matched policies, and how many were blocked or quarantined.

[SCREENSHOT: DLP summary report]

Next steps

Was this page helpful?