Gmail & Email Security
12 checks · 2 sub-categories
Email is still how the money leaves. Business email compromise in Australia rarely involves clever malware — it involves a mailbox rule quietly forwarding invoices to an attacker, a spoofed supplier domain, or a default Gmail setting that was never hardened. This section covers everything that decides which messages reach your staff and where their mail can go.
Inbound threat protection
Enhanced pre-delivery message scanning enabled
Google's additional pre-delivery scanning holds suspicious messages for deeper analysis. It is off by default in many tenants; we check whether it is on for every OU.
- CIS GW 3.1
- SCuBA GWS.GMAIL
Attachment protection settings hardened
Encrypted attachments, scripts in archives and anomalous attachment types should all be quarantined or flagged rather than delivered quietly. We check each of the three attachment safety controls.
- Essential Eight — Application control (supporting)
Link and external-image protection enabled
Link scanning and image proxying stop shortened URLs and tracking pixels from doing reconnaissance on your staff. We confirm both are on.
Spoofing and authentication protections enabled
Gmail can flag look-alike domain names, unauthenticated mail claiming to be from your domain, and inbound spoof of employee names. Each of these six sub-settings is checked individually.
- SCuBA GWS.GMAIL
- CIS GW 3.2
Security sandbox / Advanced phishing rules in use
Where the licence includes it, we check whether sandboxing is running against attachments and whether the action on detection is quarantine rather than 'keep in inbox with warning'.
Spam filter bypass and allowlists reviewed
Approved-sender lists and 'bypass spam filter' rules are a favourite attacker persistence trick and a common help-desk shortcut. Every entry is listed for review.
Mail flow, forwarding and data exfiltration
Automatic forwarding to external addresses disabled
Auto-forwarding is the single most common mechanism of undetected business email compromise. We check the domain-level setting and list every user-level forward already in place.
- Essential Eight — Restrict administrative privileges (supporting)
- CIS GW 3.4
Per-user filters and delegation reviewed
Attackers create filters that archive supplier emails, and mailbox delegations that persist after a password reset. We surface unusual filters and every mailbox delegation in the domain.
IMAP and POP access controlled
Legacy mail protocols are frequently used to bypass modern controls. We report whether IMAP/POP is enabled and for whom.
Routing, split delivery and catch-all rules documented
Custom routing rules can silently copy mail to an external host. Every routing, compliance and content-compliance rule is enumerated and explained.
Outbound gateway and relay settings reviewed
Misconfigured SMTP relay allows unauthenticated internal spoofing. We check relay restrictions and whether they require authentication and TLS.
Confidential mode and S/MIME posture reviewed
We report on confidential mode availability and, where hosted S/MIME is licensed, whether it is configured for the people who need it.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.