Configure email approval rules to review outgoing emails before they are delivered.
The Free Edition does not support this feature. For more information about the differences between editions, see Edition comparison.
What is email approval?
Emails sent by employees may contain confidential information, such as business data and trade secrets. If employees are unaware of confidentiality boundaries, they might inadvertently disclose sensitive information in emails. To strengthen data security, your company can set up an email approval flow. An approver can review emails within a specified scope. If an email from a specified account or department member meets the preset conditions, it must be approved before it is sent to the recipient's mailbox.
-
Only employee accounts can be set as approvers. Email groups are not supported.
-
You can set a specific approver. You can also set the sender's direct supervisor or department head as the approver. If the sender is the department head or their own supervisor, the email is automatically approved.
-
The person being reviewed will receive an email notification with a subject line such as 'Your email is under review: xxx', where xxx is the original subject.
Procedure
1. Log on to Alibaba Mail with the postmaster account. By default, you are directed to the Domain Management page. Click Security Management > Mail Rule > Create Rule.

2. Configure the rule condition: When all of the following conditions are met. For more information, see Mail rules.
3. Configure the rule action: Perform the following actions
Select Email Approval .

|
Configuration |
Description |
|
Name |
The name of the email approval rule. |
|
Status |
The status of the email approval rule. Valid values: Enable: The email approval rule is executed. Disable: The email approval rule is not executed. |
|
Rule scope |
The accounts or departments subject to this email approval rule. You can select: All Members: Reviews emails sent from all accounts in the domain. Specified Departments and Accounts: Reviews emails sent from specified departments or accounts. Click Add Object to add them. If you check "Include sub-departments when adding a department", members of sub-departments are also subject to this rule. Set Exceptions: If the scope is set to certain departments or all members, you can add exceptions for accounts or sub-departments that do not need to be subject to the rule. |
|
Email direction |
The direction of emails to audit. Valid values: Send to Internal: If an email sent by a specified account or department member to a recipient within your domain meets the conditions, it requires approval. Send to External: If an email sent by a specified account or department member to a recipient outside your domain meets the conditions, it requires approval. |
|
Rule content |
The content of the approval rule. Emails that match this rule require approval before they can be sent. 1. Apply to all emails: All outgoing emails are reviewed. 2. Send to Internal: If an email sent by a specified account or department member to a recipient within your domain meets the conditions, it requires approval. Send to External: If an email sent by a specified account or department member to a recipient outside your domain meets the conditions, it requires approval. 3. Recipient contains email address/domain name: Emails sent to recipients that include a specified email address or domain name require approval. 4. Recipient only contains email address/domain name: Emails sent only to a specified email address or domain name, with no other recipients, require approval. 5. Recipient address count threshold: If the number of recipients for a single email is within the set range, the email requires approval. 6. Recipient domain count threshold: If the number of recipient domains for a single email is within the set range, the email requires approval. 7. Email size threshold: If the email size is within the set range, the email requires approval. 8. Match keywords. Enter keywords. Press Enter to add multiple keywords. Match subject: Emails with a subject that contains the keyword require approval. Match body: Emails with a body that contains the keyword require approval. Match attachment name: Emails with an attachment name that contains the keyword require approval. 9. All emails with attachments: All emails that contain attachments require approval. |
|
Procedure |
1. Manual Review: Enter the approver's account. All emails that require approval must be reviewed by the approver before they can be sent. 2. Automatically reject and send feedback: Enter a reason for the feedback. Emails that hit the approval rule are rejected, and a bounce email with the reason is sent to the sender. |
|
Email approver |
1. Set a specific approver: Enter the approver's email address to set an approver for this rule. Note that email groups are not supported for this email address. 2. Set the sender's supervisor as the approver: Sets the sender's supervisor in the mail system as the approver.
Emails that match the approval rule are sent to the approver's mailbox for review before delivery. If the system cannot detect the approver for the sender, a bounce email is automatically sent. |
|
Approval duration |
Set the maximum review time for an email. Set a timeout action for emails not approved within the specified time: -Auto Send: Emails that are not approved within the time limit are sent directly. -Auto Reject: Emails that are not approved within the time limit are rejected, and a bounce notification is sent to the sender. The approval time can be set from 0 to 72 hours. The default is 0, which means emails are automatically approved. |
Domain names support wildcard characters, such as *.top.