Cloudflare brings DLP scanning into Outlook composition
Cloudflare has extended its email security portfolio with DLP Assist, an add-in for Microsoft Outlook that scans messages in real time as users draft them. The tool is designed to catch potential data loss prevention violations—such as Social Security numbers or credit card data—before an email leaves the organization, and it integrates with downstream controls to block, encrypt, or flag sensitive content.
The application is now available to Cloudflare Email Security customers and targets a gap in the DLP market: many organizations want Outlook-specific protection but find legacy options cumbersome or expensive. DLP Assist is meant to be installed in minutes without touching outbound email connectors or raising IP reputation concerns. It relies entirely on the Microsoft ecosystem, making it viable for teams with limited IT resources.
How the scanning pipeline works
DLP Assist runs as a background process within the Outlook desktop clients (Mac and Windows) and Outlook Web Access. It passively monitors new text and attachments as a user composes a message. The application invokes Outlook APIs to track changes across the subject, body, and attachments, and maintains a secure connection to a Cloudflare Worker.
Raw email and attachment data flows from the Worker to Cloudflare's DLP engine, which performs the analysis. The engine uses optical character recognition (OCR) to extract and scan text from images and attachments, and also evaluates raw text. Most attachment types are supported, though video and audio files are not processed.
DLP profile configuration data is stored on all of Cloudflare's servers, alongside the analysis engine itself, so policy checks can run without routing requests across the network. The client ID assigned during installation lets Cloudflare map traffic to the correct DLP profiles. The architecture is designed for low-latency scanning, with users always near a Worker and failover available if one becomes unavailable.
Actions on violation
When a violation is identified, the application first displays a ribbon notification at the top of the email. Administrators can customize this message, and in practice many use it to link users to documentation about what can be sent externally.
DLP Assist also injects a header into the message's EML file marking the violation. If the user removes the offending content, the header disappears automatically. If the violation remains, the application calls an Outlook API to show a final warning, offering another chance to edit before sending.
Messages sent with the violation intact carry headers that the outbound mail transfer agent (MTA) can act on. For organizations using Microsoft as their outbound MTA, DLP Assist pairs with Microsoft Purview to block, encrypt, or require approval before delivery. For example, an organization with Purview configured to block will display a notification to the user.
Violation data can also be exported through Cloudflare's Logpush feature for integration into SIEM or SOAR platforms, or stored in bucket storage such as Cloudflare R2. Block data is visible in the outbound gateway for reporting purposes.
Deployment and setup
To get started, administrators navigate to the Zero Trust dashboard, select the Email Security tab, and open the Outbound DLP tab. Installation requires downloading a manifest file that provides Microsoft with instructions for deploying the application within Outlook. The manifest is uploaded via Integrated Apps in the Microsoft 365 Admin Center, under Upload Custom Apps.
Cloudflare notes that the add-in is best suited for OWA and the desktop clients. A stable mobile experience is not yet available due to Microsoft limitations.
Roadmap
Cloudflare says it will continue improving DLP detection, with AI-based methodologies announced during Security Week 2025 that automatically fine-tune confidence levels using machine learning models. These enhancements will initially target Gateway violations, with email scanning to follow. Additional DLP and Email Security features are planned throughout 2025.



