Outbound Mail Protection
INKY's Outbound Mail Protection (OMP) detects sensitive information in outgoing email and applies policy-driven actions before messages leave your organization.
Written By Matt Sywulak
Last updated 2 days ago
How It Works
When users send email, INKY intercepts and analyzes it for sensitive content like credit cards, Social Security numbers, medical records, or custom patterns. If detected, OMP triggers workflow actions based on your rules.
Flow: User sends email → INKY analyzes → Rule matches → Action triggers → Approval required or encryption applied → Message delivers
Key Actions
Self-Approval - Sender confirms they meant to send sensitive data
Other Approval - Manager or designated approver reviews before delivery
Encrypt - Automatically encrypts message and sends via secure portal
What OMP Detects
Financial: Credit cards, bank accounts, SWIFT codes, routing numbers
Identity: Driver's licenses, Social Security numbers, passport numbers
Medical: ICD-10 codes, health information
IT: IP addresses, certificates, private keys
Cryptocurrency: Bitcoin and other wallet addresses
Custom patterns: Define your own detection rules
Admins can configure per-data-type exclusions in workflow rules to fine-tune what triggers actions. See Configure Workflow Rules for details.
Organization-level rules
Organization outbound rules, which teams inherit from their organization, are in beta. See Organization outbound rules and inheritance.
Creating and duplicating rules
A new rule is saved disabled. It doesn't take effect the moment you save it, so enable it once you've finished reviewing it.
Duplicate copies the selected rule, names the copy "<rule name> copy", and leaves it disabled for the same reason.
Approver Relationships
OMP uses flexible sender-to-approver mapping:
Specific email addresses
M365 groups
Entire domains
Registered domains (includes subdomains)
Default fallback approvers
If no approver matches, the sender becomes their own approver.
Inherited approvers
Approvers set at an organization are inherited by the teams beneath it and appear in the team's approvers list.
They're grouped under an Inherited from section header naming the organization.
They're read-only on the team. Edit and Remove carry a tooltip explaining that the approver is configured at a parent team level and can't be modified there.
To change an inherited approver, change it on the team where it was set.
Where an outbound setting comes from
Outbound settings held as policy show whether their value is inherited or set on your team, so you can tell the two apart at a glance.
Account-takeover risk mapping and burst detection thresholds both carry this indicator.
Account takeover settings are part of Outbound Mail Protection and inherit the same way the rest of the outbound policy does.
The indicators appear only for teams where organization rules are in use.
User Experience
For Senders: Email Assistant notification explains why approval is needed, who's reviewing it, and current status.
For Approvers: Email Assistant provides approve/deny links directly in the notification. Full message details available in Workflow Portal.
More in Outbound Protection and Encryption
Set Up Workflow ApproversEmail Encryption SetupCustomize Encryption PortalConfigure Notification SettingsStill need help? Ask the team