Skip to main content
Outbound Protection and Encryption

Outbound Mail Protection

INKY's Outbound Mail Protection (OMP) detects sensitive information in outgoing email and applies policy-driven actions before messages leave your organization.

Written By Matt Sywulak

Last updated 2 days ago

How It Works

When users send email, INKY intercepts and analyzes it for sensitive content like credit cards, Social Security numbers, medical records, or custom patterns. If detected, OMP triggers workflow actions based on your rules.

Flow: User sends email → INKY analyzes → Rule matches → Action triggers → Approval required or encryption applied → Message delivers

Key Actions

  • Self-Approval - Sender confirms they meant to send sensitive data

  • Other Approval - Manager or designated approver reviews before delivery

  • Encrypt - Automatically encrypts message and sends via secure portal

What OMP Detects

  • Financial: Credit cards, bank accounts, SWIFT codes, routing numbers

  • Identity: Driver's licenses, Social Security numbers, passport numbers

  • Medical: ICD-10 codes, health information

  • IT: IP addresses, certificates, private keys

  • Cryptocurrency: Bitcoin and other wallet addresses

  • Custom patterns: Define your own detection rules

Admins can configure per-data-type exclusions in workflow rules to fine-tune what triggers actions. See Configure Workflow Rules for details.

Organization-level rules

Organization outbound rules, which teams inherit from their organization, are in beta. See Organization outbound rules and inheritance.

Creating and duplicating rules

  • A new rule is saved disabled. It doesn't take effect the moment you save it, so enable it once you've finished reviewing it.

  • Duplicate copies the selected rule, names the copy "<rule name> copy", and leaves it disabled for the same reason.

Approver Relationships

OMP uses flexible sender-to-approver mapping:

  • Specific email addresses

  • M365 groups

  • Entire domains

  • Registered domains (includes subdomains)

  • Default fallback approvers

If no approver matches, the sender becomes their own approver.

Inherited approvers

Approvers set at an organization are inherited by the teams beneath it and appear in the team's approvers list.

  • They're grouped under an Inherited from section header naming the organization.

  • They're read-only on the team. Edit and Remove carry a tooltip explaining that the approver is configured at a parent team level and can't be modified there.

  • To change an inherited approver, change it on the team where it was set.

Where an outbound setting comes from

Outbound settings held as policy show whether their value is inherited or set on your team, so you can tell the two apart at a glance.

  • Account-takeover risk mapping and burst detection thresholds both carry this indicator.

  • Account takeover settings are part of Outbound Mail Protection and inherit the same way the rest of the outbound policy does.

  • The indicators appear only for teams where organization rules are in use.

User Experience

For Senders: Email Assistant notification explains why approval is needed, who's reviewing it, and current status.

For Approvers: Email Assistant provides approve/deny links directly in the notification. Full message details available in Workflow Portal.