Mail review
This topic describes how to set up mail review rules.
This feature is not available in the free edition. For differences between versions, see version description.
What is mail review?
Employee emails can contain confidential business data and trade secrets. To prevent accidental leaks and enhance data security, you can set up mail review. This feature holds emails from specific accounts or departments that match predefined conditions. An approver must then approve these emails before they are delivered.
Only an employee account can be an approver. Email groups cannot be used for this role.
You can specify approvers, or use the sender's direct supervisor or department supervisor. An email is automatically approved if the sender is their own supervisor.
When an email is held for review, the sender receives a notification such as "Your email is under review: xxx", where xxx is the email subject.
Procedure
1. Log in to Alibaba Mail with the postmaster account. By default, you are on the Domain Management page. Click Security Management > mail rules > Create Rule.

2. Configure the rule conditions under When all of the following conditions are met. For details, see mail rules.
3. Configure the rule action under Perform the following actions.
Select Mail review.

Parameter | Description |
Name | The name of the mail review rule. |
Status | The status of the mail review rule. Options include: Enabled: The rule is active. Disabled: The rule is inactive. |
Rule scope | Specifies the accounts or departments to which the rule applies. You can select from the following options: All Users: Applies the rule to all accounts in your domain. Specified Departments and Accounts: Applies the rule to specific departments or accounts. Click Add to specify them. If you select Include sub-departments, the rule also applies to all members of sub-departments. Set Exceptions: Excludes specific accounts or sub-departments from the rule when the scope is set to specific departments or all users. |
Email direction | The direction of emails to review. Options include: Sent to internal: The rule applies to emails sent to recipients within your domain. Sent to external: The rule applies to emails sent to recipients outside your domain. |
Rule content | The conditions that trigger the mail review. Emails that match the rule require approval before being sent. 1. Apply to all emails: All outgoing emails are held for review. 2. Sent to internal: Emails sent by specified accounts or department members to recipients within the same domain require approval if they meet the conditions. Sent to external: Emails sent by specified accounts or department members to recipients outside the domain require approval if they meet the conditions. 3. Recipient contains email address/domain: The email is held for review if the recipient list contains a specified email address or domain name. 4. Recipient only contains email address/domain: The email is held for review if the recipient list contains only the specified email addresses or domain names and no other addresses. 5. Recipient address count threshold: The email is held for review if the number of recipients is within the specified range. 6. Recipient domain count threshold: The email is held for review if the number of recipient domains is within the specified range. 7. Email size threshold: The email is held for review if its size is within the specified range. 8. Match keywords. Enter keywords. Press Enter to separate multiple keywords. Match subject: The email is held for review if a keyword is found in the subject. Match body: The email is held for review if a keyword is found in the body. Match attachment name: The email is held for review if a keyword is found in an attachment name. 9. All emails with attachments: All emails that contain an attachment are held for review. |
Actions | 1. Manual Approval: Specify an approver's account. Emails that match the rule are sent to the approver for review. 2. Automatically reject and send reason: Enter a rejection reason. The system automatically rejects matching emails and sends the reason to the sender. |
Approver | 1. Set specified approvers: Enter the email addresses of the approvers for this rule. Note that email groups are not supported. 2. Set sender's supervisor as approver: Designates the sender's supervisor in the email system as the approver.
Emails that match the rule are sent to the approver's mailbox for review before they can be sent. If the system cannot identify an approver for the sender, the email is automatically bounced. |
Approval period | Sets the time limit for an email to be approved. Configure an action for emails that are not approved within the time limit: - Send automatically: If the email is not approved within the time limit, it is sent automatically. - Reject automatically: If the email is not approved within the time limit, the system rejects it and sends a notification to the sender. The approval period can be set from 0 to 72 hours. The default is 0 hours, which means the email is automatically approved and sent. |
You can use a wildcard character in domain names, for example, *.top.