Zoho Mail has launched Incoming and Outgoing Rules designed to enhance enterprise email governance and security, addressing risks before emails reach users. The feature aims to prevent incidents like phishing attacks and accidental data leaks by controlling email flow at the organizational level, according to zoho.com.
The new rules allow administrators to set policies that filter and manage both incoming and outgoing emails based on customizable criteria. For example, they can block suspicious attachments or restrict emails sent to multiple external recipients, reducing exposure to threats such as fraudulent invoices or unintended data sharing. This proactive approach shifts security focus from reactive measures like spam filters to preventive controls.
Email remains the largest attack surface for enterprises, often under-governed despite its critical role in communication. Zoho's solution addresses this gap by enforcing policies before emails land in inboxes, contrasting with traditional security methods that rely on user vigilance and post-delivery filtering. This development aligns with growing industry emphasis on preemptive cybersecurity measures in SaaS platforms.
Zoho published details about Incoming and Outgoing Rules on August 4, 2026, highlighting scenarios such as a CFO receiving a fraudulent invoice email and a sales executive accidentally exposing pricing information to multiple external recipients. The company’s blog post provides guidance on configuring these rules to mitigate such risks effectively.