The expensive mistakegoes out,not in.
A transposed letter in the recipient domain, an account list in the attachment, a taken-over account sending invoices overnight. In most organisations the inbound path is protected and the outbound one is not. MailGuard checks both directions in the same gateway.
Four ways something leaves that should have stayed
None of them requires bad intent. Three are simply mistakes.
The domain with the typo
Auto-complete suggests an address that looks confusingly like a known one. Two transposed letters are enough and the attachment sits with a stranger.
Sensitive data in the attachment
A spreadsheet with account numbers, a scan of an ID card, a key in plain text. Nobody sees that in an attachment, and even less so inside an encrypted file.
The taken-over account
Whoever holds an employee's credentials sends from their mailbox. SPF, DKIM and DMARC all pass cleanly, because the mail really does come from you.
The attachment blocked at the far end
A macro in an Office file or an executable archive lands in the recipient's filter. You only find out when someone calls to say they never received anything.
Checked before the message leaves the building
The same chain as inbound, only in the other direction — and with actions that suit the outbound path.
Recipient check against confusion
A recipient domain that resembles one of your own or a known partner domain, and that has never been used before, is reported or blocked. Plain transposition of two neighbouring characters is caught as well — the most common typo there is.
Data loss prevention with rule sets
Account numbers, credit cards, ID and social security numbers, technical secrets. Detected in text, in attachments and, through text recognition, in images. New organisations start with a ready rule set in monitoring mode.
Attachments and links on the way out
Attachment categories your organisation does not want to release, and reputation checking for links. A listed link on the way out is not a matter of judgement; the categories are the organisation's own decision.
What outbound protection does
Ten actions are available. Blocking is only one of them.
Report instead of block
Every rule set can run in monitoring mode. That way you see for a week what would have applied before you switch to enforcing. New organisations start exactly like that.
Redact instead of reject
Instead of rejecting the message, the affected data can be removed or made unreadable — inside a PDF too, including the file's metadata.
Encrypt instead of forbid
When a rule matches, the message can go out encrypted instead of not at all. The sender needs to know nothing and click nothing.
Detection in difficult cases too
Encrypted archives, files with the wrong extension, text in images, patterns across several conditions, and a match against your own documents and data sets.
Sender counter and block threshold
An account that suddenly sends a hundred messages stands out. The hourly limit and the outbound block threshold are set by the organisation.
Make mailbox forwardings visible
A forwarding attached directly to the mailbox appears in no rule and is invisible in Outlook. The daily run reads it out and reports suspicious destinations.
In comparison
Why the outbound direction needs different tools than the inbound one.
Conbool MailGuard | Common gateways | |
|---|---|---|
| Misdirected mail to look-alike domains | Detected, including plain letter transposition. | Rare. Usually only a warning for external recipients. |
| Data loss prevention out of the box | Ready rule set at setup, in monitoring mode. | Present but empty. Whoever enters nothing has nothing. |
| Detection in images | Text recognition in attachments, with caps on time and size. | Extra charge, or not at all. |
| Response on a match | Ten actions, among them redact, encrypt, redirect. | Usually block or quarantine. |
| Link reputation on the way out | On by default. A listed link is not a matter of judgement. | Frequently inbound only. |
| Detecting taken-over accounts | Sender counter, inbox rules and mailbox forwardings. | Often counts sending volume only. |
Statements about the usual route follow the publicly documented prerequisites of common signature services that source people data from Entra ID.
Frequently asked questions
Does outbound protection block straight away?
What happens to a message that violates a rule?
Does the check also find data in images and in encrypted archives?
How does the recipient check tell a genuinely new customer from a typo?
Does the sender see that their message was checked?
Does this apply to automatic replies as well?
Related solutions
One week in monitoring mode shows what leaves
The rule set is ready at setup and prevents nothing at first. You see the numbers before you decide.