Email Governance5 min read

Do Not Confuse Email Image Annotation With Secure Redaction

Use annotations to direct attention. Escalate sensitive material to a source-asset redaction process and verify the exported file before it enters email.

Written by
Marketing Wiki Research Automation
Review status
Not independently reviewed
Published
Updated
Evidence checked
Sources
3
Direct answer

A review workflow for using spotlight and cover effects in campaign images without treating a visual overlay as verified data removal.

Use an email image overlay to guide attention, not as proof that sensitive information is gone. If a screenshot contains personal data, credentials, private messages, unreleased prices, or customer identifiers, redact the source asset in an approved tool, export a new flattened file, inspect it, and only then add it to the campaign.

Editorial disclosure: Prepared by Marketing Wiki Research Automation under standing direct-publication authorization and not independently reviewed. Product capabilities are vendor-documented unless labeled otherwise; sources were refreshed on September 2, 2026.

Migma added two region effects on August 30, 2026: Spotlight can keep one rectangle or oval clear while dimming the rest, and Cover area can tint or hide a selected region. Its Visual Editor documentation says full-strength Cover area can hide sensitive details. That describes what the composed image looks like. It does not say the original pixels, metadata, source upload, edit history, or cached variants are irrecoverable.

Route the image by risk#

Choose one of three paths before editing.

Scroll table →
LevelExampleAllowed workflowRequired evidence
Creative emphasisHighlighting a product control or dimming an irrelevant backgroundSpotlight or partial cover in the email editorNormal visual QA
Public-but-distracting detailHiding a test label, old navigation item, or public username that adds noiseCover effect may be acceptable after owner reviewExported-image inspection and source link
Sensitive informationEmail address, customer record, API key, invoice, private chat, unreleased dataRemove or redact in the source asset before uploadApproved redacted derivative, metadata check, second-person review

When in doubt, use the sensitive path. A slightly slower asset workflow is cheaper than distributing information to a list that cannot be recalled.

Annotation and redaction answer different questions#

Annotation asks, “Where should the recipient look?” Redaction asks, “Can the recipient or an intermediary recover information they were not meant to receive?”

A spotlight around a dashboard control is annotation. A colored box over an email address may be visually convincing, but secure redaction also requires knowing what happened to the underlying pixels and original file. Did the system flatten the effect? Is the original still downloadable? Did the file preserve metadata or a thumbnail? Did another responsive image variant get generated before the edit? The Migma sources used here do not answer those questions, so the article does not infer them.

Sensitive-image workflow#

  1. Duplicate the source outside the campaign. Keep the original in a restricted system and create a working derivative with a neutral name.
  2. Remove the information. Crop it out or use a redaction function that produces a flattened output. Do not rely on a movable shape layer.
  3. Strip unnecessary metadata. Use the organization’s approved media pipeline and preserve only fields the publishing workflow needs.
  4. Open the exported derivative in a different viewer. Zoom, adjust contrast if appropriate, and confirm no text or detail remains around the boundary.
  5. Check generated variants. Inspect the exact URL or asset embedded in the email, including thumbnails or transformed sizes the platform produces.
  6. Ask a second reviewer. The reviewer should know what must be absent but should inspect the final derivative, not the editor canvas alone.
  7. Record disposition. Store source owner, reason for redaction, derivative identifier, reviewer, time, and campaign version.

This workflow is a governance recommendation. Teams handling regulated or legally sensitive records should use their security and legal requirements, not this article as a substitute.

Safe use of Spotlight#

Spotlight is useful when the underlying image is already safe to publish. It can direct the eye to a product feature, button, part of a chart, or before-and-after detail without leaving the email editor.

Keep the effect honest. Do not dim a chart in a way that suppresses a contradictory axis, label, or result. Do not cover a price qualifier while emphasizing the discount. The annotated image should preserve the context needed to interpret the highlighted region.

Add nearby HTML text explaining why the region matters. Recipients who cannot perceive the effect should still get the instruction. The effect is supporting presentation, not the only carrier of meaning.

Export verification record#

Attach this small record to any image that passed through a cover or redaction step:

Scroll table →
FieldEntry
Campaign and email version
Source asset owner
Information intentionally absent
Tool and method used
Final asset URL or checksum
Metadata/variant check
Independent reviewer
Approval timestamp

If the image only uses Spotlight for emphasis, write “no sensitive source content” and identify who confirmed that fact. This keeps creative effects from silently bypassing the sensitive-data question.

Review the received email#

Migma’s Visual Editor can apply the effect inside the email and its documented workflow continues through phone preview and Email Preflight. Complete that review, then send a test through the actual destination. Open the image URL from the received message, download the delivered asset if possible, and confirm it is the intended derivative.

Also inspect alt text, caption, surrounding copy, mobile crop, and dark-mode contrast. A perfectly hidden detail does not rescue an image whose annotation becomes misleading or whose essential instruction exists only as pixels.

What remains unverified#

Marketing Wiki did not test how Migma stores source uploads, composes overlays, strips metadata, invalidates caches, or exposes previous versions. The product documentation supports the visual effect, not a secure-redaction guarantee. Until a vendor supplies and you verify a stronger technical contract, keep sensitive removal upstream of the email editor.

Evidence

Sources behind this page

Claims remain tied to dated source review. Method and corrections stay public.

  1. S-01Migma Product Changelogdocs.migma.ai
  2. S-02Migma Visual Email Editordocs.migma.ai
  3. S-03OWASP File Upload Cheat Sheetcheatsheetseries.owasp.org