SafeSend Email Security for Outlook review: A great solution for security-conscious SMBs

An invaluable last line of defence against Outlook email disasters that’s easy to deploy and manage

IT Pro Recommended
Price
£24 exc VAT per user, per year (50-99 users)
  • Heaps of protection features
  • Swift and simple deployment
  • Handy centralised management
  • Configuration can be a little time-consuming

We’ve all experienced that sinking feeling after accidentally sending an email to the wrong recipient. If it’s an internal message, you may still be able to recall it – but if it’s gone to someone outside of your company there may be nothing you can do. At best, it’s an embarrassment; at worst, if your message contained confidential or personal information, you could be looking at a hefty fine.

SafeSend Email Security is a small add-in for Outlook that’s designed to eliminate that risk. It achieves this partly by requiring users to review all external email recipients and confirm that they’re correct before the message can be released. 

There’s a lot more than this to the software, however. It also provides extensive data loss prevention (DLP) services, allowing you to scan email subjects, message contents and attachments for specific keywords and patterns. If a match is found, the software can request confirmation before sending or even block transmission altogether.

Deployment is a cinch. The add-in can either be installed manually or distributed and managed centrally using a group policy. It works with all versions of Outlook from 2007 upwards, and there’s also a web version for Outlook 365 and OWA. We had no problems using a GPO to distribute the MSI package to the Windows clients in our lab: once they had logged into the domain and been authenticated, the add-in was silently deployed without the need for any user interaction.

Training requirements are minimal. Users just need to be advised that the first time they load Outlook, SafeSend will pop up a message to confirm their internal email domain. Once this is done, any attempt to send a message outside of the organisation will bring up a confirmation prompt.

That might sound a little intrusive, but the dialog is clean and simple, showing all the email’s recipients (including those in the “Cc:” field) with a tickbox next to each one. If something’s not right, you can remove any unwanted recipients before sending, or reopen the message for further editing.

Central management is just as easy. SafeSend provides ADMX/ADML files for deployment on your domain controller; with these copied across to the PolicyDefinations folder on our Active Directory server, we were able to create a customised SafeSend GPO for all authenticated users.

This process can be a little time-consuming, but that’s only because the SafeSend GPO has over 150 options to configure. Some of these are simple controls, such as preventing users from removing SafeSend, adding extra safe domains and deciding whether to enable the “Select All” tickbox. More advanced options let you do things such as limiting the number of message recipients, detecting bulk emails and adding custom footer messages.

In addition, you can, of course, customise SafeSend’s DLP policies. These are extremely versatile as you can create multiple rules to detect specific strings, credit card numbers and even regular expressions. To ensure nothing slips through the net, SafeSend scans not only the text of outgoing emails but also attachments in various formats, including PDFs, Office attachments and ZIP archives.

If a user’s email triggers one of your DLP rules, they’ll be presented with details of the sensitive content and the detection rules that it triggered. You can set a custom action for each rule, so for some types of data you could require explicit confirmation from the sender, while other content might be completely blocked.

SafeSend also gives you the option of adding X-headers to emails. These can be used to trigger encryption using a separate security product such as Mimecast and Proofpoint – or you can use X-headers in conjunction with Exchange transport rules to verify that users have SafeSend installed. 

We found SafeSend simple to roll out and refreshingly easy to manage. In these days when an accidental data breach can expose you to steep fines, every SMB ought to be concerned about email security – and this add-in is a great solution.

Featured Resources

Preparing for AI-enabled cyber attacks

MIT technology review insights

Download now

Cloud storage performance analysis

Storage performance and value of the IONOS cloud Compute Engine

Download now

The Forrester Wave: Top security analytics platforms

The 11 providers that matter most and how they stack up

Download now

Harness data to reinvent your organisation

Build a data strategy for the next wave of cloud innovation

Download now

Recommended

DuckDuckGo launches email privacy service
email providers

DuckDuckGo launches email privacy service

20 Jul 2021
Google targets phishing with full BIMI email logo authentication support
email delivery

Google targets phishing with full BIMI email logo authentication support

12 Jul 2021
The most secure email services of 2021
email providers

The most secure email services of 2021

12 Mar 2021
CloudHQ fully integrates Gmail with Google Sheets
email delivery

CloudHQ fully integrates Gmail with Google Sheets

9 Feb 2021

Most Popular

UK gov considers blocking Nvidia's takeover of Arm
Acquisition

UK gov considers blocking Nvidia's takeover of Arm

4 Aug 2021
RMIT to be first Australian university to implement AWS supercomputing facility
high-performance computing (HPC)

RMIT to be first Australian university to implement AWS supercomputing facility

28 Jul 2021
Preparing for AI-enabled cyber attacks
Whitepaper

Preparing for AI-enabled cyber attacks

22 Jul 2021