Outbound Data Loss Prevention (DLP)
Outbound Data Loss Prevention ensures the protection of sensitive information in outbound emails with Cloudflare Data Loss Prevention (DLP). Outbound Data Loss Prevention integrates with your inbox, and it proactively monitors your email to prevent unauthorized data leaks.
To begin using outbound DLP, install the Cloudflare add-in in Microsoft 365:
- In Zero Trust ↗, go to Email Security > Outbound DLP.
- In Protect sensitive data in outbound emails, select Get started.
- Select Download add-in to download the Cloudflare add-in.
- Configure Microsoft 365 to use the Cloudflare add-in:
- In the Microsoft 365 Apps admin center ↗, go to Microsoft 365 Admin Center > Settings > Integrated Apps.
- Select Upload custom apps. For the application type, choose Office Add-in.
- Select Upload manifest file (.xml) from device.
- Upload the Cloudflare add-in file.
- Verify and complete the wizard.
 
- Confirm the Cloudflare add-in was configured in Microsoft 365.
After configuring the Cloudflare add-in in Microsoft 365, you can select Add a policy to create an outbound DLP policy.
An outbound policy allows you to control outbound email flow.
To create an outbound DLP policy:
- 
In Zero Trust ↗, go to Email Security > Outbound DLP. 
- 
Select Add a policy. 
- 
Name your policy. 
- 
Build an expression to match specific email traffic. For example, you can create a policy that blocks outbound emails containing identifying numbers: Selector Operator Value Logic Action Recipient email not in example.comAnd Block Matched DLP profile in Social Security, Insurance, Tax, and Identifier Numbers 
- 
(Optional) Choose whether to use the default block message or a custom message. 
- 
Select Create policy. 
After creating your policy, you can modify or reorder your policies in Email Security > Outbound DLP.
| Selector | Description | 
|---|---|
| Recipient email | The intended recipient of an outbound email. | 
| Email sender | The user in your organization sending an email. | 
| Matched DLP profile | The DLP profile that content of an email matches upon scan. |