SecureMyEmail logoSecureMyEmail

Google Workspace security guide

Enable phishing protections in Google Workspace

A practical guide for Australian businesses. Configure Gmail Safety, Enhanced Safe Browsing and Security Sandbox to protect users from phishing, spoofing and unsafe attachments.

Google Workspace phishing protection with Gmail Safety and Enhanced Safe Browsing

Recommended method: use Gmail’s Safety, Spam and Malware settings

Google Workspace does not use Microsoft’s Safe Links or Safe Attachments. The comparable protections are Gmail’s Advanced phishing and malware protection, Link and external-image scanning, Spoofing and authentication protection, Enhanced malware and phishing protection, and Security Sandbox where supported by your licence.

Before you begin

Confirm that:

  • You have a Super Administrator account or the Gmail Settings administrator privilege.
  • Your domain’s SPF, DKIM and DMARC records are correctly configured.
  • Legitimate scanners, websites, accounting platforms and third-party email systems are documented.
  • You have created an admin quarantine if you intend to quarantine suspicious messages.
  • You can test the settings on a pilot organisational unit or group before applying them to everyone.
1

Open Gmail safety settings

  • Sign in to the Google Admin console.
  • Select Menu → Apps.
  • Select Google Workspace → Gmail.
  • Select Safety.
  • Select the organisational unit on the left.

For initial testing, select a pilot organisational unit. After testing, repeat the process for the top-level organisational unit to protect everyone.

2

Enable attachment protection

  • On the Safety page, locate Attachments.
  • Turn on Protect against encrypted attachments from untrusted senders and select an action: Recommended starting point: Keep email in inbox and show warning. Stronger protection: Move email to spam. Most restrictive: Quarantine.
  • Turn on Protect against attachments with scripts from untrusted senders and select an action: Select Move email to spam or Quarantine.
  • Turn on Protect against anomalous attachment types in emails and select an action: Select Move email to spam or Quarantine. Leave the uncommon file-type allowlist empty unless a verified business application requires an exception.
  • Turn on Apply future recommended settings automatically.
  • Select Save.

Google already scans messages for malware, but these controls apply additional actions to suspicious files and attachments from untrusted senders.

3

Enable suspicious-link protection

  • On the Safety page, locate Links and external images.
  • Enable Identify links behind shortened URLs.
  • Enable Scan linked images.
  • Enable Show warning prompt for any click on links to untrusted domains.
  • Enable Apply future recommended settings automatically.
  • Select Save.

The warning for clicks on untrusted domains is designed for the Gmail interface and is not available in POP or IMAP email clients.

4

Enable spoofing and authentication protection

  • On the Safety page, locate Spoofing and authentication.
  • Enable Protect against domain spoofing based on similar domain names. Select Move email to spam or Quarantine.
  • Enable Protect against spoofing of employee names. Select Move email to spam or initially use Keep email in inbox and show warning during testing.
  • Enable Protect against inbound emails spoofing your domain. Select Quarantine or Move email to spam.
  • Enable Protect against any unauthenticated emails. Initially select Keep email in inbox and show warning or Move email to spam until you have confirmed that legitimate senders authenticate correctly.
  • Enable Protect Groups from inbound emails spoofing your domain. Apply this to all groups, unless you have a documented reason to limit it to private groups.
  • Enable Apply future recommended settings automatically.
  • Select Save.
5

Enable Gmail Enhanced Safe Browsing

  • In the Admin console, go to Apps → Google Workspace → Gmail.
  • Select Spam, Phishing and Malware.
  • Select the organisational unit or access group to protect.
  • Locate Enhanced malware and phishing protection.
  • Tick the checkbox to enable the feature.
  • Select Save.

Enhanced protection performs additional checks on potentially dangerous messages, links and attachments. Google advises that changes can take up to 24 hours to apply.

6

Enable Security Sandbox, if licensed

  • Go to Apps → Google Workspace → Gmail.
  • Select Spam, Phishing and Malware.
  • Select the relevant organisational unit.
  • Scroll to Security sandbox.
  • Enable Virtual execution of attachments in a sandbox environment.
  • For maximum protection, select the option to scan all attachments.
  • Select Save.

Security Sandbox is available only with certain Google Workspace editions, including supported Business and Enterprise plans. Supported attachment categories include executables, Microsoft Office documents, PDFs and files inside certain archives. Sandbox scanning can delay message delivery by up to approximately three minutes.

7

Protect users using IMAP clients

  • Remain under Gmail → Spam, Phishing and Malware.
  • Locate the setting for link protection for IMAP clients.
  • Enable suspicious-link protection.
  • Select Save.

Gmail warning banners are generally displayed in Gmail’s web interface and might not appear in Outlook, Apple Mail or other third-party email applications.

8

Test before organisation-wide rollout

Send legitimate test messages that include:

  • PDF and Microsoft Office attachments
  • Encrypted attachments used by legitimate organisations
  • Links shortened through approved services
  • Links to recently registered or rarely used supplier domains
  • Messages from website forms, scanners and accounting platforms
  • Messages from senior employees using personal accounts
  • Messages from legitimate systems that do not use SPF or DKIM correctly

Confirm whether each message:

  • Arrives normally
  • Displays a warning
  • Is moved to spam
  • Is placed in admin quarantine
  • Is delayed for attachment analysis
9

Monitor the results

  • In the Admin console, open Reporting → Reports.
  • Review Gmail reports for Phishing, Malware, Spam and User-reported messages.
  • Open Apps → Google Workspace → Gmail → Manage quarantines.
  • Review quarantined messages regularly.
  • Investigate false positives before creating exceptions.
  • After successful testing, apply the settings to the top-level organisational unit.
  • Review exceptions and allowlists at least quarterly.

Important warnings

  • Do not enable every setting with Quarantine immediately. Test with warnings or spam actions first unless an actively exploited threat requires urgent blocking.
  • Encrypted attachments cannot be inspected normally. Blocking them may affect banks, government agencies, legal firms and secure document-delivery services.
  • Protection against unauthenticated messages may affect legitimate systems that have incorrectly configured SPF or DKIM.
  • Employee-name protection may flag legitimate messages sent from personal accounts.
  • Untrusted-link warnings can cause user confusion and increase support requests.
  • Security Sandbox can delay attachment delivery.
  • Warning banners might appear only in Gmail and not in third-party email clients.
  • Broad sender or domain allowlists can let phishing messages bypass important checks.
  • If a third-party email security platform is already in use, verify its routing and compatibility before changing Gmail protections.
  • Client-side encryption can prevent Gmail Enhanced Safe Browsing from examining protected content.
  • Changes can take up to 24 hours to apply.

Google Workspace disclaimer

These instructions provide general Google Workspace security guidance. The correct configuration depends on your Workspace edition, organisational structure, email routing, third-party filtering, business applications and acceptable level of risk.

Incorrect settings can quarantine legitimate email, interrupt automated systems or create security gaps through unnecessary exceptions. Document the existing configuration, test changes on a pilot group and maintain a rollback plan. If you are uncertain, have the settings reviewed and implemented by a qualified Google Workspace security engineer.