Prerequisites
You must have already setup a Forensics Profile.
After, create a policy for an Email Outbound App:
- In the Netskope Admin Console, click Policies > Real-time Protection.
- Click New Policy > Email Outbound and select your SMTP configuration and Send for Activities.
- Select your desired DLP Profile and set Action to Alert
- Create a Policy Name, Enable, and Save.

You can view all the DLP incidents related to SMTP Proxy from the DLP violations in emails in your Netskope tenant.
In the Netskope UI, navigate to Incidents > DLP and click on the incident to view the incident details.
Note
In the Incident Detail page, the “Acting User” and “From User” fields have the same value.

Upon clicking an incident, you will see the Activity, Violation, Action Taken, and other relevant information such as the Sensitivity Label Instance, and Sensitivity Label.


