

Overview
Self Addressed Email Detection helps identify outbound emails that may have been sent by a user to their own personal or lookalike external email accounts. This provides additional visibility into potential insider risk scenarios, such as users attempting to move sensitive data outside the organization.
Use this feature to
- investigate potential insider data exfiltration via personal email
- prioritize incidents where sender and recipient identities closely match
- add context to existing DLP alerts without creating additional noise
The feature works alongside existing DLP policies and adds context to incidents by analyzing similarities between sender and recipient identities.
How it works
For each outbound email, the service compares the sender with all recipients using available email information like email addresses, display name etc.
A similarity score is calculated for each recipient based on how closely the recipient resembles the sender.
- if multiple recipients exist, the highest similarity score is considered
- if the score crosses a predefined threshold, the email is identified as self addressed
In addition
- compares sender with recipients across To, Cc, and Bcc
- identifies lookalike or similar identities using similarity scoring across different formats and languages
- does not expand group email addresses into individual users
DLP Incident details
This information appears in the DLP incident details when an email triggers a policy.
You will see
- Self addressed email detection
Indicates whether the email was identified as self addressed - Similarity details
Shows recipient email addresses along with similarity scores
Up to five recipients with the highest similarity scores are shown
This helps investigators quickly understand whether the user may have sent data to a personal or similar identity.

