SafeToOpenEmail Security Docs

SafeToOpen Browser Security

Platform coverage and user freedom

Outlook and Gmail on desktop, web and mobile, what other clients cannot do, and what a user can still change

Guide 6 of 7 · April 2026

The honest map. “Enforced” means the administrator decides and the user cannot change it.

ClientInstallLicensingCan the user remove it?Why
Outlook on Windows and Mac (Microsoft 365)Enforced (Integrated apps, Fixed)Automatic on first openNoAdd-ins deployed from the admin center are pinned by Microsoft and sign in with the mailbox identity.
Outlook on the webEnforcedAutomaticNoSame deployment.
Outlook mobile (iOS, Android)EnforcedAutomaticNoSame deployment; the add-in appears in the message actions menu. Some features that need the full pane are reduced.
Classic Outlook with Exchange Server on-premisesNot supportedThe add-in relies on Microsoft 365 single sign-on and Exchange Online APIs; there is no admin deployment path for on-premises Exchange.
Gmail on the web (Google Workspace)Enforced (domain install)Automatic on first openNoDomain-installed Marketplace add-ons cannot be removed by users.
Gmail apps (Android, iOS)EnforcedAutomaticNoWorkspace add-ons run in the mobile apps.
Personal Gmail (@gmail.com)User installs from the MarketplaceAutomatic once the address is on PeopleYesNo admin console; the person is a member like any other but can uninstall.
Apple Mail, Thunderbird, other IMAP clientsNot availableThese clients have no add-in framework the product can run in. Cover those mailboxes with mail-flow rules or use Outlook or Gmail.
Shared mailboxes and delegates (Outlook)EnforcedCounts as the delegate’s seatNoThe signed-in user is the delegate; the shared mailbox itself is not a member.

What the user can and cannot change#

Note Rule of thumb: Outlook on Microsoft 365 and Gmail on Google Workspace are fully unattended and locked, on every device. Everything else is either self-installed or not covered. Do not sell beyond that.