dtwo Policy Store

Policies tagged "email"

ms365 · ingress

Block Agent Email to External Recipients

Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.

ms365guard-external-sendingressemaildlpsoc2hipaagdpr-ccpa

zapier · ingress

Block External Sends Hidden in Zapier Instructions

Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…

zapierguard-external-sendingressemailsoc2gdpr-ccpa

ms365 · ingress

Block Mail-Rule and Webhook Persistence

Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…

ms365guard-mailbox-persistenceingressbecemailfinserv-commssoc2

gmail · ingress

Deny Agent Email Sends to External Recipients

Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.

gmailguard-external-sendingressemailsoc2hipaagdpr-ccpa

onboarding · ingress

Deny Email PII

This policy stops a request if it contains an email address. If there's no email address, the request goes through as normal.

onboardingpiiemaildlpingress

onboarding · ingress

Detect Email PII (Allow with Reason)

A watch-only starter policy.

onboardingpiiemailobservabilityingress

gmail · egress

Mask Card Numbers in Email Content Read by Agents

Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.

gmailmask-pan-egressegressemailcardholder-datadlpsoc2pci-dssgdpr-ccpa

onboarding · egress

Redact Email PII

This policy automatically masks email addresses in what a tool sends back, replacing each one with [REDACTED] before your agent ever sees it.

onboardingpiiemaildlpredactionegress