The Netskope Outlook plugin extends Email DLP to the user’s desktop. When a user sends an email from Microsoft Classic Outlook on Windows, the Netskope Endpoint DLP Client submits the message to the Netskope SMTP Proxy for policy evaluation before the message leaves the device. The SMTP Proxy evaluates your Email DLP policies and returns a verdict, and the plugin enforces that verdict in Outlook: the message is allowed, logged as alert, held for user confirmation, or blocked. Because the verdict is returned before Outlook sends the message, users receive feedback in real time, and blocked content never leaves the endpoint.
The plugin uses your existing Email DLP policies and DLP profiles. No separate policy engine or rule set is required. In addition, this feature requires Endpoint DLP subscription to leverage the Netskope client capabilities.
How It Works
-
The user clicks Send in Outlook.
-
The Netskope Client intercepts the message and submits the sender, all recipients (To, Cc, and Bcc), the message headers, and the message body to the Netskope SMTP Proxy over an encrypted HTTPS connection.
-
The SMTP Proxy confirms that the sender’s domain is configured for your tenant, runs DLP inspection on the full message, and evaluates your Email DLP policies.
-
The SMTP Proxy records an event in Skope IT and returns the verdict to the plugin.
-
The plugin applies the verdict:
-
Allow: Outlook sends the message.
-
Alert: Outlook sends the message. The event is logged for administrators.
-
User Alert: The user sees a notification describing the policy match and can choose to proceed or cancel.
-
Block: The send is stopped and the user sees a notification. The message does not leave the device.
-
-
If the message is allowed, Outlook sends it through your normal mail flow.
Prerequisites
-
Netskope Client with the Endpoint DLP module installed and running on the user’s Windows device.
-
Microsoft Outlook, classic desktop version, on Windows.
-
Your tenant is provisioned for the Netskope SMTP Proxy, and each sending domain is configured under Settings > Security Cloud Platform > SMTP. Messages from a sender domain that is not configured for your tenant are not evaluated.
-
The Endpoint DLP Outlook plugin has been enabled for your tenant from Endpoint Client settings.
Configure the Endpoint DLP Outlook Plugin
-
In the Netskope UI, go to Settings > Security Cloud Platform > Netskope Client Configuration, and open the Client Configuration that applies to the users’ devices.
-
Under Endpoint DLP, Enable Email Scan Plugin and save the configuration.
-
Go to Policies > Real-time Protection and create or edit an Email DLP policy.
-
Under Destination, select Email Outbound > Endpoint Email Scan Plugin > Microsoft Outlook.
-
Select the DLP profile to apply.
-
Under Action, select the plugin action: Allow, Alert, User Alert, or Block. A policy can carry a plugin action that differs from its SMTP Proxy inline action.
-
Save and apply the policy.
View Plugin Events
Events generated by the plugin appear in Skope IT with the Access Method SMTP Plugin. Events generated by the SMTP Proxy inline path show the Access Method SMTP Proxy. DLP incidents raised by plugin traffic appear in Incidents > DLP in the same way as incidents from the inline path.

