← Google Workspace audit scope

Gmail & Email Security

12 checks · 2 sub-categories

Email is still how the money leaves. Business email compromise in Australia rarely involves clever malware — it involves a mailbox rule quietly forwarding invoices to an attacker, a spoofed supplier domain, or a default Gmail setting that was never hardened. This section covers everything that decides which messages reach your staff and where their mail can go.

Inbound threat protection

  • Enhanced pre-delivery message scanning enabled

    Google's additional pre-delivery scanning holds suspicious messages for deeper analysis. It is off by default in many tenants; we check whether it is on for every OU.

    • CIS GW 3.1
    • SCuBA GWS.GMAIL
  • Attachment protection settings hardened

    Encrypted attachments, scripts in archives and anomalous attachment types should all be quarantined or flagged rather than delivered quietly. We check each of the three attachment safety controls.

    • Essential Eight — Application control (supporting)
  • Link and external-image protection enabled

    Link scanning and image proxying stop shortened URLs and tracking pixels from doing reconnaissance on your staff. We confirm both are on.

  • Spoofing and authentication protections enabled

    Gmail can flag look-alike domain names, unauthenticated mail claiming to be from your domain, and inbound spoof of employee names. Each of these six sub-settings is checked individually.

    • SCuBA GWS.GMAIL
    • CIS GW 3.2
  • Security sandbox / Advanced phishing rules in use

    Where the licence includes it, we check whether sandboxing is running against attachments and whether the action on detection is quarantine rather than 'keep in inbox with warning'.

  • Spam filter bypass and allowlists reviewed

    Approved-sender lists and 'bypass spam filter' rules are a favourite attacker persistence trick and a common help-desk shortcut. Every entry is listed for review.

Mail flow, forwarding and data exfiltration

  • Automatic forwarding to external addresses disabled

    Auto-forwarding is the single most common mechanism of undetected business email compromise. We check the domain-level setting and list every user-level forward already in place.

    • Essential Eight — Restrict administrative privileges (supporting)
    • CIS GW 3.4
  • Per-user filters and delegation reviewed

    Attackers create filters that archive supplier emails, and mailbox delegations that persist after a password reset. We surface unusual filters and every mailbox delegation in the domain.

  • IMAP and POP access controlled

    Legacy mail protocols are frequently used to bypass modern controls. We report whether IMAP/POP is enabled and for whom.

  • Routing, split delivery and catch-all rules documented

    Custom routing rules can silently copy mail to an external host. Every routing, compliance and content-compliance rule is enumerated and explained.

  • Outbound gateway and relay settings reviewed

    Misconfigured SMTP relay allows unauthenticated internal spoofing. We check relay restrictions and whether they require authentication and TLS.

  • Confidential mode and S/MIME posture reviewed

    We report on confidential mode availability and, where hosted S/MIME is licensed, whether it is configured for the people who need it.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.