Gmail
Excellent Spam Filtering
Is Not A Security Programme
Gmail's filtering is genuinely among the best available, and it creates a quiet confidence that email is handled. The attacks that matter to a business, invoice fraud and compromised accounts, are precisely the ones a spam filter is not designed to catch.
Schedule a Workspace ReviewNothing To Filter On
A message asking a colleague to update the bank details on an invoice contains no attachment, no link and no suspicious phrasing a filter can act on. It is an ordinary email making an ordinary request, and the only thing wrong with it is that the sender is not who they appear to be.
Check The Basics First
Domain authentication and forwarding rules take an afternoon to review and close most of the practical exposure.
Talk to an ExpertDomain records that decide whether outsiders can send mail as you: authentication, alignment and the policy that enforces both.
What Needs Deciding
| Setting | Usual state |
|---|---|
| External forwarding | Allowed |
| Domain policy enforcement | Monitoring only |
| Delegated mailbox access | Unreviewed |
| Third party app access | Open |
The Insider Who Is Not
When an attacker holds valid credentials, their mail comes from inside and passes every check. Strong verification on the account is the control that matters, not the filter in front of it.
Deleted Is Deleted, Eventually
Administrative recovery of deleted mail exists within a limited window. Beyond it, content removed by a user, a departing employee or a retention rule is gone, which is why mail that matters needs a separate backup decision.
The filter handles the hundred messages that do not matter. The one that does looks entirely normal.Why configuration outranks filtering here.
The Findings Are Consistent Across Organizations
Three things turn up in almost every first review, and all three are configuration rather than expenditure.
Domain Policy Never Enforced
Authentication records are frequently published in a reporting-only mode and left there indefinitely, because moving to enforcement risks blocking a legitimate sender nobody has identified yet. Until that work is finished, anybody can send mail claiming to be your domain.
Forwarding Nobody Monitors
An automatic rule sending copies of mail to an outside address is the classic signature of a compromised account. Whether such rules are permitted, and whether anybody is alerted when one appears, is a setting most organizations have never examined.
Applications With Mailbox Access
Staff authorise third party applications to read their mail, often for a legitimate convenience. Those grants persist, and each one is another party holding access to your correspondence. Reviewing what has been authorised is frequently uncomfortable reading.
What This Platform Does Well
Genuine Strengths
Filtering quality, search, reliability and a simpler administrative model than the alternative. For organizations without dedicated IT staff, Workspace is materially easier to run day to day, and that advantage is real rather than marketing.
What Still Needs Doing
Domain authentication enforcement, forwarding policy, application access review and a backup decision. None of these is provided by default and none is difficult. They are simply the work that remains after the platform has taken care of everything it can.
Check Whether Anyone Can Send As You
Domain authentication left in reporting mode is the most common and most consequential finding in a Workspace review, and it is fixable without buying anything.
Review Your Mail ConfigurationGet in touch with Your Company
Questions about this solution? Reach us directly.