Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

Additional Information – Policies

Prev Next

Encrypt Message Content

When this policy is enabled, the “Encrypt Message Content” method will be enabled by default when composing new emails via the Trustifi add-in or web app.

When this policy is enabled in “strict” mode, the “Encrypt Message Content” method will be enabled and users cannot disable it. In “strict” mode, all emails sent using the email relay will have content encryption enabled by default.

Allow Override in Add-ins”: When “Encrypt Message Content” is configured in Strict mode, enabling “Allow Override in Add-ins” allows users to temporarily disable encryption for individual emails directly from the Outlook or Gmail add-in.

Require Authentication

When this policy is enabled, the “Require Authentication” method will be enabled by default when composing new emails via the Trustifi add-in or web app.

When this policy is enabled in “strict” mode, the “Require Authentication” method will be enabled and users cannot disable it. In “strict” mode, all emails sent using the email relay will have multi-factor authentication enabled by default.

Authentication methods allowed

This policy allows admins to select which of the 4 possible authentication methods should be allowed to use in encrypted emails with MFA: (1) phone, (2) password, (3) email, (4) SSO. Note: The “Email” method is used as a default in cases where the recipient does not have a registered phone number. If this method is disabled then in those cases, the email will fail to send, and the sender will be notified.

Allow recipients to switch authentication from SSO to email

When this policy is enabled, users can switch their authentication method from SSO to email.

Notify Sender about Blocked Recipients

When this policy is enabled, senders are notified when a recipient has been blocked from accessing an encrypted email. Recipients may be blocked after exceeding the allowed number of authentication attempts or when the email is configured to allow access only once.

Click Notification Options to configure the notification behavior:

  • Allow sender to request release – Allows senders to submit a release request for blocked recipients.

  • Send the release request to – Specify one or more email addresses that will receive sender release requests. If left blank, the request is sent according to the default release request configuration.

  • Release request email title – Customize the subject line of release request emails using supported dynamic fields such as {{SENDER_EMAIL}}, {{EMAIL_SUBJECT}}, and {{COMPANY_NAME}}. If left empty, the default Trustifi subject line is used.

Attachments Encryption Policy

This policy dictates whether attachments should be automatically encrypted based on sensitive content found in files. There are 3 options to select from:

  • Encrypt from sensitivity threshold: Attachments will be encrypted if the content found within matches a score equal to or above the selected score.

  • Always encrypt attachments: Attachments in sent emails will always be encrypted

  • Never encrypt attachments: Attachments in sent emails will never be automatically encrypted unless a DLP rule is triggered

Allow Admin Policies Only

When this policy is enabled, all users under the plan will not be able to manually apply any protection methods (e.g. “Encrypt Message Content”) or change any advanced settings in the Trustifi add-ins or the web portal. Only plan-wide policies enabled by the admin team will apply to sent emails.

Simplified Compose View

When this policy is enabled, A streamlined compose experience in Outlook and Gmail is displayed, displaying only the secure email option. Users can switch between Basic and Advanced modes at any time.

Allow Updating Messages

Allows senders to update the content and attachments of encrypted emails after they’ve been sent.

Allow Recalling Messages

Allows users to recall emails sent to internal recipients. This policy also allows to control the maximum time after sending (in hours) during which users are allowed to recall emails.
Note: The “Message Recall” function in Trustifi is only supported for Office 365 users.

Allow Downloading Encrypted Emails as EML

When this policy is enabled, recipients will be able to download encrypted emails as EML files.

When this policy is enabled in “strict” mode, downloading EML will be allowed for all outgoing emails

When this policy is disabled in “strict” mode, downloading EML will not be allowed for all outgoing emails

Send Encrypted Replies as Regular Emails

When this policy is enabled, replies to encrypted emails will be received as regular, unencrypted emails

Strip S/MIME and PGP signatures

When this policy is enabled, if S/MIME or PGP signatures are detected, they will be removed from the email so that the email content can be encrypted or modified.

When this policy is disabled, emails with S/MIME or PGP signatures will be sent directly without encrypting or modifying the email content.

Require authentication on replies

When this policy is enabled, all encrypted replies will require the recipient to undergo multi-factor authentication.

When this policy is enabled in “strict” mode users cannot disable it.

Block outbound emails to blocklisted recipients

Outbound emails sent to addresses or domains in your inbound global blocklist will be automatically blocked. You can manage your global blocklist by navigating to Global Blocklist (Inbound Management > Allow/Block Lists > Sender Lists).

Block outbound emails for attachments types

Emails containing the selected attachment types will be automatically blocked. You may choose any or all of the following:

  • Macros

  • Scripts

  • Executables

Block Inappropriate Content

Emails containing inappropriate content such as nudity, violence, and drug use (in text or picture form) will be blocked and quarantined. These emails can then be reviewed and released by an admin.

When enabled, this policy can be applied to all users or selectively exclude specific users. If no exclusions are defined, the policy applies to everyone.

Block Malicious Content

Emails containing malicious content such as links and attachments will be blocked and quarantined (This feature cannot be disabled).
These emails can then be reviewed and released by an admin.

Notify Sender About Blocked Emails

When this policy is enabled, senders will be notified when their outbound emails are blocked or quarantined for any reason.

By clicking on the “Notification Options” link, a pop-up will open where the admin can define whether the sender should have the option to "request release" for the email, and to which address the request will be sent.

Retention Policy

Admins can decide how long their users’ emails and attachments will be retained in Trustifi’s secure servers. Once an email or attachment has passed the configured retention period, it will be permanently deleted.
The maximum retention period is 7 years (84 months or 2520 days).

Email expiration

To enable a default time of email expiration, click on the toggle next to “Email expires in” and set a number value in the “days” field.

This will set a default expiration time for all outgoing emails under your Trustifi plan. You can set this policy as “strict.”

After an encrypted email has reached its expiration time, it will no longer be available to the recipient and will be deleted from the sender’s email history.

Attachment expiration

To set an expiration time for attachments sent by your users, click on the toggle next to “Attachments Expiration” and set a number value in the “days” field.

You can set this policy as “strict.”

Once an attachment reaches its expiration time, it will no longer be available to the recipient and will be deleted from the sender’s storage.

When enabled, all links in sent emails will have tracking enabled so the sender can see if and when an email’s recipient has clicked on any of the links inside.

Email Open Tracking HTML

Adds a tracking pixel to monitor when recipients open and read standard emails.

Allow printing

Recipients will be able to print the content of the encrypted email