Skip to main content
Control Inbound. Protect Outbound. Train People Better.See What's Launching

Email DLP Rules

Enforce Email DLP With Greater Accuracy

Email DLP Rules combines a custom policy engine with an AI Triage Agent that evaluates every match in context, automatically releasing benign messages and quarantining likely violations, with transparent reasoning behind every verdict.

The Challenge

Traditional Email DLP Can't Distinguish Violations From False Alarms

Pattern Matching Can't Read Business Context

Regex and keyword matching detect patterns, not meaning. When solutions flag a Social Security number and a nine-digit order number as identical, benign messages often get flagged as violations.

False Positives Overwhelm Security Teams

Every rule match lands in the same review queue. Analysts spend hours clearing benign messages while the real violations get lost in the noise.

Brittle Policies Are Difficult To Maintain

Legacy tools force teams to build and maintain sprawling exclusion logic, making policies harder to manage, update, and scale over time.

Narrow Or Noisy: There's No Middle Ground

Teams must choose between narrow rules that miss real violations and broad rules that flood the queue with noise. Often the controls get tuned down or switched off, not because the exposure went away, but because the review burden is too high.

Why Abnormal

Other Solutions Can Find Matches. Abnormal Determines Whether They're Real Violations

Traditional Email DLP treats every pattern match as a verdict. Abnormal adds the context to distinguish real violations from false alarms.

Contextual Triage On Every Match

When a rule matches, the AI Triage Agent weighs policy intent, sender-recipient context, and message content before auto-releasing benign matches and quarantining likely violations.

Plain-Language Exception Management

Refine exceptions in plain language instead of nested regex. Instructions like “ignore emails from our HR system domain” are easy to express, and nearly impossible to capture with pattern matching alone.

Transparent, Auditable Reasoning

Every verdict includes clear reasoning: what triggered the rule, how context shaped the decision, and why the message was released or held.

Protection for Outbound Emails

Define, Validate, and Enforce Outbound Policy With Confidence

Custom DLP Rule Builder

Combines regex, phrase matching, metadata conditions, Boolean logic, and editable exclusions into custom outbound policies, built from scratch or from prebuilt regex templates.

AI Triage Agent

Reviews every flagged match against rule intent, sender-recipient relationship, and message content, auto-releasing benign messages and quarantining likely violations.

Plain-Language Exception Management

Lets users add, edit, or remove rule exclusions by describing them in plain language, capturing business nuance without brittle detection logic.

Rule-Based Attachment Scanning & OCR

Extends rules to supported attachments, including PDFs, images, Word, and Excel, catching sensitive data and screenshots that text-only rule matching misses.

Rule Validation

Tests verdicts against sample emails, with full reasoning, before a rule goes live.

Outbound Log & SOC Release

Logs every match, verdict, and reasoning trail in one place, with RBAC-controlled release for messages held in Microsoft quarantine.

Every Match, Weighed And Tracked

The Triage Agent weighs every match against policy intent and message context, releasing benign matches and holding likely violations for review. The rule dashboard tracks that split over time, comparing auto-released versus quarantined, so teams can see exactly how much manual review the agent removed.

Validate Detection Logic Before Enabling a Rule

While building a rule, teams see exactly how the Triage Agent interpreted their policy through a plain-language rule intention and editable exclusions. They can then validate verdicts against real .eml examples, tuning rules before launch, not after.

Enforce Protection At Your Own Pace

Teams can launch rules in passive mode, logging matches without taking action, then move to Active enforcement when ready. Rules can also roll out progressively by department or workflow, putting the pace of enforcement in the customer's hands.

See Email DLP Rules in Action

See how contextual AI turns every DLP match into a clear, auditable verdict.