Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Before malicious emails reach employee inboxes: hardening Gmail inbound defenses on the admin console

Table of contents · 6 items

"Our accounting department received an email claiming to be from our CEO instructing them to urgently transfer funds to a specified bank account. Fortunately, they confirmed with the CEO directly and prevented any harm, but the message looked so convincing that they almost believed it. Is there any way to prevent emails like that from reaching employees in the first place?" We recently received this consultation from an IT administrator at a company with about thirty employees. At small and medium enterprises, incidents leading to financial loss or data breaches usually begin with a single fraudulent email landing in an employee's inbox.

When discussing email security, measures to prevent spoofing of your own domain via SPF, DKIM, and DMARC are often highlighted. This is outbound protection designed to prevent your domain from being forged and fake emails from reaching your business partners. However, alongside this sits inbound protection: preventing employees themselves from receiving dangerous emails. And all too often, these inbound settings remain in their default states within Google Workspace admin consoles. In this article, we explain how administrators can harden employee inboxes, written from the perspective of an organization commissioning IT security.

Preventing domain spoofing and blocking inbound threats are distinct defenses

First, we must distinguish between these two often conflated layers of defense. If this distinction remains vague, companies risk implementing only one side and assuming they are fully protected.

One layer is outbound defense. Setting up SPF, DKIM, and DMARC prevents spoofed emails claiming to be from your domain from reaching business partners and clients. This primarily serves to protect those outside your company. The other layer is inbound defense, which intercepts spam, phishing attempts, and malicious attachments sent to your employees from external sources before employees ever see them. This serves to protect the inside of your organization.

The wire transfer instruction impersonating the CEO mentioned earlier is an inbound security issue. No matter how tightly you configure outbound domain authentication, attackers sending emails from completely different domains or free email services while pretending to be the CEO can only be stopped by inbound settings. Outbound and inbound protections defend in opposite directions as distinct measures. Email vulnerabilities are properly addressed only when both are in place.

Google Workspace includes built-in inbound protection as standard

The good news is that these inbound defenses are already built into Google Workspace as standard features. Before purchasing expensive add-on tools, there are key settings in the Admin Console that should be turned on first.

A prime example is advanced phishing and malware protection. This suite of settings verifies links and external images in incoming mail, spots links concealed by URL shorteners, and detects spoofing attempts that mimic sender domains or employee names. When enabled, suspicious emails can be displayed with warnings or quarantined to spam. For situations like the CEO impersonation mentioned earlier, employee name spoofing detection is particularly effective.

Another layer is malicious attachment protection. Gmail includes a mechanism to open incoming attachments inside an isolated virtual environment (security sandbox) to verify whether they exhibit malicious behavior. Additionally, you can block the receipt of high-risk file formats such as executable files altogether. Furthermore, Enhanced Safe Browsing protection, which blocks access to dangerous websites at the perimeter, can be turned on organization-wide or for specific departments.

Inbound protectionWhat it blocks
Advanced phishing and spoofing protectionFake links, shortened URLs, and emails impersonating executives or business partners
Sandbox scanning for attachmentsMalicious files that infect devices when opened
Blocking high-risk file typesExecutable files and other formats you want to restrict from receipt
Enhanced Safe BrowsingDirecting users to dangerous websites

Most of these protections take effect across the entire company simply by toggling them on in the Admin Console. The problem is that not everything is set to maximum protection by default; activation and sensitivity adjustments are left to the administrator. In short, if you haven't configured them, the protections are not working.

Setting maximum security company-wide sweeps up legitimate emails too

Does that mean you should simply crank every security setting to the maximum? It is not quite that simple. Overly aggressive inbound filtering produces the side effect of intercepting legitimate business correspondence.

For example, quotation file formats sent by business partners or automated notifications from external services used daily might get marked as spam or quarantined due to overly strict rules. That leads to the opposite headache: critical emails failing to arrive. The volume of external communication also varies widely by department. Teams like sales and procurement that communicate constantly with external parties have different requirements than departments with little external contact.

Consequently, rather than applying maximum settings uniformly across the company, a practical approach is to lay a solid company-wide foundation first, then fine-tune sensitivity department by department. This departmental customization can be implemented smoothly by combining organizational units (OUs), as detailed in our article on separating department settings with organizational units. Finding the balance between strengthening defense and preventing business disruption is the core of effective design.

Case study: A company that intercepted a fraudulent bank detail change at the perimeter

Here is a specific example. A company with around forty employees (name withheld) contacted us: "An email impersonating a supplier modified the wire transfer account on an invoice. An employee noticed something odd this time, but we aren't confident we'll catch it next time." Upon investigation, we found that advanced phishing protection and attachment sandbox scanning were not enabled in their Admin Console. The protective features existed, but the switches had never been turned on.

We began by enabling advanced phishing and spoofing protection alongside attachment inspection company-wide, and blocked the receipt of high-risk file types. Next, we calibrated sensitivity for sales and purchasing departments with high external email volume to prevent legitimate mail from being blocked. In addition, to catch any fake emails that might slip through, we introduced an operational policy: always confirm bank account changes over the phone. What made the difference was not purchasing new software, but turning on existing built-in defenses tailored to how departments actually operate. Combining technological guardrails with human verification eliminated these close calls going forward.

Start by checking inbound toggles in the Admin Console

Protecting employee inboxes does not require evaluating new software products. The first step you should take is checking your current Google Workspace Admin Console to verify whether advanced phishing protection, attachment scanning, and high-risk file blocking are actually switched on. In many small and medium enterprises, the features exist but remain switched off.

From there, solidify your company-wide baseline, tune sensitivity for departments with heavy external contact, and layer on operational rules like verifying account changes by phone. This dual protection of technology and operational process stops damages originating from a single fraudulent email at the perimeter. When auditing your company's overall security posture, reviewing inbound defenses at the same time is strongly recommended.

If you are worried about emails impersonating business partners or executives, unsure whether phishing and attachment defenses are active, or concerned that overly strict settings will block legitimate emails, please feel free to reach out through GleamHub's free IT and Google Workspace consultation. From auditing current inbound configurations to building company-wide baselines, tuning department sensitivity, and drafting employee operational rules, we will help you protect your organization without disrupting business.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

The right way forward with Workspace for your company.

We organize data to migrate, sharing rules, and governance structures to map out the journey from implementation to daily operations.

  • Migration and initial setup
  • Sharing and permission organization
  • Governance structure
Consult on Workspace implementation and operations

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email