Real-time Protection policies enable Netskope to scan outgoing emails for DLP violations. This protection is done as emails are received from Microsoft Exchange or Gmail and processed by the SMTP Proxy which allows data to be examined and protected in real time.
- In the Netskope UI, navigate to Policies > Real-time Protection.
- In the Real-time Protection page, click New Policy > Email Outbound.
- In the Real-time Protection Policy page, select the Users, User Groups, and Organizational Units under Source. Outgoing emails from the selected users, groups, and organizations will be scanned by DLP.
- Under Destination, select Email Outbound App and then select Microsoft Office 365 Exchange and Google Gmail as the Email Outbound.
- In the Destinations section, click Edit under Activities & Constraints and select Send. Additionally, you can specify user constraints on the right side of the Select Activities & Constraints dialog box. Click Save.
- Under Profile and Action, select the various DLP profiles from the list.
- Select an action to define the enforcement action to be performed when a DLP profile matches the content in the email.
When you select Allow, the action is allowed when it meets the profile.
When you select Alert, the action type is applied globally to all the selected DLP profiles and alerts are generated when any of the profiles match the email content.
When you select Add SMTP Header, Netskope SMTP Proxy adds the specified custom header to the email when the email content matches the policy definition.
As of R128, you can select Remove Recipients. For more information, see below.
Alternatively, you can set the type of action for each profile by clicking Set action for each profile. - In the Profile and Action section, click Add Traffic Action to specify additional actions to be taken if none of the selected profiles match the criteria for violation.
- Under Set Policy, provide a name for the policy and a policy description.
- In the Set Policy section, click Email Notification. In the Email Notification window, specify the notification frequency and who should receive the notifications. Optionally, you can also specify the From Email. Click Done.
- Click Save and in the Real-time Protection page click Apply Changes.
Removing Recipients through SMTP Proxy

The Netskope SMTP Proxy has the ability to remove specific recipients from an email while still allowing the email to go through to the rest of the recipients, so that the emails are delivered only to the allow-listed recipients. This ensures compliance while maintaining communication flow for permitted recipients.
Use Case:
Consider a situation where Alice <alice@example.com> sends an email to Bob <bob@example.com> and Carol <carol@example.com> with Bob and Carol as the recipients in the To: header. If a Constraint Profile has been set up to only allow emails to Carol, then Bob will not receive an email and the email will only go to Carol. Alice will also receive a notification stating her email failed to reach Bob as it was blocked by the SMTP Proxy. Carol will also see that Bob was an intended recipient.
If there are no recipients left after deleting the restricted recipients, the SMTP Proxy will return an SMTP error with code 558. The reply message depends on the email provider:
In case of Gmail, where there is always only one recipient in an email, the message will be as follows:
558 User is restricted and has been deleted from the recipient list due to policy.
In case of Microsoft Exchange, where there can be multiple recipients in the email, the message will be as follows:
558 Message rejected: No recipients remaining after deleting restricted users due to policy
Configuration:
Requirements:
-
This will only work with an Email Outbound App.
-
You must select a DLP under Profile & Action section.
-
You must set To User: in the Activity Constraints section.
When all three requirements are fulfilled, Remove Recipients will appear.
The notification must be configured to inform the sender that users have been removed as recipients.

SMTP Removed Recipients has been added to the Email Notification template in order to inform the user that their email has been modified by the SMTP Proxy.


