Email Data Loss Prevention (DLP)

Overview

Sublime Email Data Loss Prevention (DLP) scans outgoing email for sensitive data and blocks risky messages before they reach the recipient. It runs on the same platform that protects your inbound mail, so your team investigates, tunes, and reports on data loss in the tool they're already using.

Sublime catches personally identifiable information (PII), protected health information (PHI), payment card industry (PCI) data, credentials and secrets, financial records, and intellectual property.

How it works

  1. Scan: Sublime analyzes each outbound message: the subject, the body, and every attachment, including files nested inside archives and text inside images.
  2. Detect: DLP Rules evaluate the message for sensitive data and policy violations. Sublime installs and maintains a managed set of DLP detections and you add your own.
  3. Review: ASA (Autonomous Security Analyst) investigates each match and explains its verdict. Set it up for passive monitoring or active remediation.
  4. Remediate: Sublime blocks, alerts on, or sends the message based on the actions you choose. Senders of blocked messages get a notification and a way to request a release. No false positives disrupting business.

Detection methods

Sublime combines several analysis methods, and DLP Rules decide how to use them.

  • Entity recognition:
    • A machine learning model extracts sensitive entities. Each match carries a confidence level which keeps look-alike numbers from triggering a block.
  • Natural language understanding:
    • Sublime's Natural Language Understanding (NLU) models classify the topic of a message, like Financial Communications or Legal and Compliance. Custom DLP Rules combine a topic with other conditions, for example flagging legal correspondence sent to a personal email domain.
  • Deep file inspection:
    • Sublime recursively unpacks archives and embedded files, then scans the text of each file. Optical character recognition (OCR) extracts text from images, scanned documents, and screenshots, so sensitive data in a photo of a form gets the same scrutiny as text in the body.
  • Microsoft Purview sensitivity labels:
    • DLP Rules read the Purview sensitivity label on a message, so the classification your organization already applies drives enforcement in Sublime. For example, block messages labeled Confidential that are addressed outside your organization. Available for Microsoft365 customers.

Custom DLP Rules

Write your own DLP Rules in MQL (Message Query Language), the same language behind Sublime's Detection Rules. Custom rules cover what's specific to your business: project code names, customer lists, contract templates, source code, restricted file types, or unapproved recipient domains. Every analysis method above is available to custom rules, and you scope each rule to the senders, recipients, or groups it applies to.

Review and remediation

ASA review

ASA investigates each DLP Rule match the way an analyst would. It reviews the message and the DLP Rules it matched, then writes up a verdict with the reasoning behind it. Automations act on ASA's verdict based on your preferences, for example releasing a message ASA finds benign or keeping a confirmed violation blocked.

Remediation options

  • Block delivery: Hold the message before it reaches the recipient.
  • Encrypt with Purview: Encrypt the message using Purview so recipients receive sensitive data safely.
  • Monitor: Run DLP detections with no remediations to see what's leaving your organization, with no impact on mail flow.
  • Alert: Send matches to your team by email, Slack, or webhook, alongside or instead of blocking.

Sender notifications and release requests

When Sublime blocks a message, notify the sender with an email that explains the block and links to a release request. Admins review requests and Sublime delivers the messages they approve. Senders receive a follow up email with the result of their request.

Classification and reporting

Analysts classify policy breaches as Violation, on outbound and inbound messages alike. DLP reporting shows what Sublime flagged, blocked, and released over time, which gives you a record to bring to compliance reviews and audits.

Get started

Sublime DLP works with Microsoft 365 and Google Workspace, with no MX record changes. Turn it on for any set of mailboxes, from one to your entire tenant.

Your Sublime account team provides complimentary guided onboarding. Together you set up mail flow, pilot DLP on a small group of mailboxes in monitor mode, and turn on blocking and expand coverage when you're ready.

To get started, contact your Sublime account team.