Most companies filter inbound mail hard: spam, phishing, malware. What they send out, they rarely check as closely. Yet that is exactly where most reportable GDPR incidents of recent years came from:
- an HR file attached by mistake,
- a reply-all with a customer list sent to the wrong people,
- a developer mailing an API key to a vendor.
Outbound DLP starts right there.
What DLP Actually Does
A modern outbound DLP system checks every outgoing email from a logged-in user before it goes to Postfix. It tests the mail against a set of rules you can configure:
- Structured detectors: credit card numbers (with Luhn check), IBANs (mod-97), tax IDs, and US SSNs. They check the format, unlike a blind regex that flags every 13-digit number as a card number.
- Secrets detectors: AWS access keys, GCP service account JSON, GitHub PATs, OpenAI keys, and generic high-entropy strings. These are the most common sources of leaked credentials.
- Classification markers: keywords like "confidential", "strictly confidential", or "internal distribution". You can set them per domain and business unit.
- Attachment checks: Office files, PDF text, and ZIP contents run through the same pipeline, not just the mail body.
The Big Problem: False Positives
Simple DLP tools block so many valid emails that IT turns off the quarantine after three weeks. SecTepe.Comm keeps false positives low in two ways:
- An action per rule instead of one global block: each rule can "log only", "warn user", "quarantine", or "block". An IBAN from an accounting domain is logged. A PEM private key line from the marketing mailbox is hard-blocked.
- Masked snippets instead of full hits: admins see only the masked match (for example
4111-XXXX-XXXX-1111). They can investigate in a compliant way, without opening a new path for data leaks.
Multi-Domain & Per-Domain Policies
Outbound DLP only shows its full value when you can set it up differently per domain. A holding with five subsidiaries wants other classification rules for its tax firm than for its sales unit. The SecTepe.Comm domain registry allows exactly this level of detail, down to exceptions per sender and per recipient.
Four-Eyes Release: The Missing Safety Net
Even the best DLP rules sometimes hold back a lawyer's PDF that has to go out. Instead of "the admin decides alone", you can use a four-eyes approval flow. High-risk verdicts include a DLP hit, a sandbox threat, or a policy violation. Such mails are only released if a second operator approves them in the UI. This also serves as ISO 27001 evidence for "segregation of duties", with no Excel lists or Slack pings.
What DLP Does Not Replace
A DLP system does not replace awareness, clear classification policies, or good secrets handling. For example, use a vault instead of PEM files in emails. DLP is the last technical line of defense that catches human errors. What you learn from the matches is also useful feedback for awareness training and for changing processes.
Conclusion
Outbound DLP belongs in every serious mail security plan. What counts is not that "DLP is on". What counts is:
- how precise the rules are,
- how cleanly the actions escalate (warn → quarantine → block),
- how smooth the release process is.
SecTepe.Comm delivers the rule set, the UI, and the four-eyes safety net. It is all part of the same platform that already filters your inbound mail.