Skip to main content

Data Loss Prevention (DLP)

Swif's Data Loss Prevention (DLP) feature monitors outgoing emails in real time and blocks messages that violate your organization's data security policies — before they ever leave your outbox.

Overview

DLP protects sensitive information from being sent through web-based email applications. When enabled, Swif's browser extension inspects outgoing email content at send time. If a policy violation is detected, the email is blocked instantly — it will not be sent and will not appear in your Sent folder.

DLP operates entirely within the browser. There is no need to install additional software or configure email server rules.

Enabling Beta Features

Before you can enable Data Loss Prevention (DLP), you must first subscribe to beta features at the organization level. By default, beta features are opted-out for all new and existing organizations.

For Admins:

  1. Navigate to Organization Settings in the Swif dashboard.

  2. Locate the Beta Features section.

  3. Toggle the Beta Features switch to ON.

  4. Once enabled, a "Beta" badge will appear next to supported features (like DLP) in the navigation menu, and the feature pages will become visible.

Note: While the feature flag is organization-wide, specific DLP rules are still configured at the team level under Organization Settings > Team.

Requirements

  • Swif Browser Extension: Must be installed and active on managed devices. Learn more at deploy browser extensions.

  • Beta Access: Ensure the Beta Features toggle is enabled in Organization Settings to view the DLP Events dashboard.

Supported Applications

Application

Platform

Mechanism

Real-Time Block

Attachment Scanning

Gmail (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Not yet

Outlook (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Not yet

Note: DLP currently covers the web versions of Gmail and Outlook accessed through a supported browser with the Swif extension installed. Native desktop mail clients are not covered at this time.

How It Works

  1. Compose as normal — Write your email in Gmail or Outlook web as you normally would, including any attachments.

  2. Click Send — DLP inspection occurs at the moment you press Send. It does not scan while you type or draft.

  3. Policy evaluation — The content of your email body is evaluated against your organization's DLP policies.

  4. Outcome:

    • No violation detected → The email is sent normally.

    • 🚫 Violation detected → The send is blocked. A notification appears in the email app informing you that the message was not sent due to a policy violation. The blocked email does not appear in your Sent folder.

  5. Resume working — After a block, you can edit the email to remove the flagged content and try sending again. Normal email functionality is unaffected.


Configure DLP rules

DLP rules are managed at the team level by your organization administrator. This granular control allows you to apply specific security policies to different employee groups and applications.

Prerequisite:
Before configuring rules, ensure that Beta Features are enabled in your Organization Settings. As a beta feature, the Data Loss Prevention tab will only be visible in Team Settings when this toggle is ON.

For Admins:

  1. Navigate to Team Settings in the Swif dashboard.

  2. Locate and click the Data Loss Prevention tab.

  3. If no rules have been created yet, click Create Rule to begin.

  4. In the rule creation modal, configure the following:

    • Rule Name: Enter a descriptive name for the policy (e.g., "Engineering Sensitive Data Policy").

    • Employee Group: Select the specific group of users this rule should apply to.

    • Supported Applications: Select one or more applications (e.g., Gmail, Outlook) where the rule will be enforced.

  5. Click Save. A success notification will confirm the rule is active and being synced to managed devices.

Managing Existing Rules:

  • Edit or Delete: Click the "..." (More Actions) menu next to any existing rule to modify its configuration or remove it.

  • Multiple Rules: You can define multiple rules for the same team or employee group. Swif will evaluate all applicable rules simultaneously at the moment an email is sent.

Important Details:

  • Admin-Only Access: Only administrators can view or modify DLP configurations; these settings are hidden from standard users.

  • Privacy & Security: Swif stores rule metadata (such as Rule ID and Group Name) to provide context in the DLP Events Dashboard, but it never stores the actual body text of your emails.

  • Immediate Enforcement: Once a rule is saved, the Swif browser extension automatically enforces the policy across all supported web email platforms for the targeted users.


Monitoring & Reporting

Administrators can monitor DLP activity and policy enforcement in real time through the DLP Events Dashboard. This centralized view provides visibility into blocked actions, event trends, and detailed logs across the organization.

  • Summary Metrics: View high-level statistics on total events and blocked actions.

  • Event Trends: Track policy violations over time to identify spikes or patterns.

  • Detailed Logs: Review specific triggers, including the application, action taken, and the final decision (Blocked, Allowed, or Flagged).

  • Privacy First: To maintain security, Swif does not store or display the raw body text of emails in the dashboard.

For a comprehensive guide on how to use these reporting features, see our article on Monitoring Data Loss Prevention (DLP) Events.

What Gets Inspected

Content Type

Inspected?

Email body text

✅ Yes

Attachments (files added to the email)

Not yet

Subject line

✅ Yes

Recipients

Policy-dependent

DLP also supports server-side detection through connected integrations, providing an additional layer of coverage beyond the real-time browser block.

Supported Platforms

OS

Supported

macOS

✅ (via Chrome/Edge extension)

Windows

✅ (via Chrome/Edge extension)

Linux

✅ (via Chrome/Edge extension)

Frequently Asked Questions

Q: Will DLP slow down my email sending?
A: No. Policy evaluation happens in milliseconds at send time. You will not notice any delay for compliant emails.

Q: What happens if my email is blocked?
A: You'll see a notification directly in Gmail or Outlook explaining the block. Your email draft is preserved — you can edit it and try again.

Q: Does DLP read my emails while I'm typing?
A: No. DLP only inspects the email at the moment you click Send. It does not monitor drafts, keystrokes, or content in real time while composing.

Q: Are native desktop clients (Apple Mail, Outlook desktop app) supported?
A: Not currently. DLP covers Gmail and Outlook web apps only, accessed through a browser with the Swif extension installed.

Q: Is DLP enabled by default?
A: No. DLP is off by default and must be explicitly enabled by your team administrator in Team Settings.

Q: Does DLP work if I'm offline?
A: DLP requires an active browser extension connection. If the extension is disabled or not present, DLP enforcement will not apply.

Q: Can I see why my email was blocked?
A: The block notification will indicate that a DLP policy was triggered. Contact your administrator for details on your organization's specific policy rules.

For questions about your organization's DLP policies, contact your Swif administrator.

Did this answer your question?