Monitor the health of your Gmail settings
Supported editions for this feature: Frontline Plus; Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus. Compare your edition
From the security health page, you can monitor the configuration of advanced Gmail settings in your Google Admin console.
Before you begin
For the steps to get to the security health page in the Admin console, go to Get started with the security health page.
Important: Updates to DNS records at your domain host might take up to 48 hours to appear on the security health page, depending on your domain provider.
Email routing
Expand section | Collapse all & go to top
Automatic email forwardingTurn off the automatic email forwarding option to reduce your risk of data exfiltration through email forwarding, which is a common technique employed by attackers. For details, go to Disable automatic forwarding.
If you turn off this setting, users won’t see the forwarding option in their Gmail settings. Any existing forwarding rules or filters they created will no longer work. However, any forwarding rules created by you or other admins will still apply.
Include the spam header in all default routing rules that you have defined (if any). This action reduces the risk of spoofing and phishing or whaling. Other servers that get messages from your organization can use this information to determine how to treat those messages: Reject, admin quarantine, send to spam, and so on.
For more details and instructions, see Set up Default routing for your organization.
Tip: If you're adding or updating routing settings for a large organization, we recommend you try out the new rules with a small set of users. For more information, go to Best practices for faster rules testing.
Filtering content & protecting data
Expand section | Collapse all & go to top
Comprehensive mail storageComprehensive mail storage—Ensures that a copy of all sent or received messages in your domain is stored in the associated users' Gmail mailboxes. This setting reduces your risk of data deletion.
Recommendation
Turn this setting on:
- If you have a non-Gmail system that uses the SMTP relay service to route messages on behalf of your users and you want to display the messages in your users’ Gmail mailboxes.
Examples: Ticket-tracking systems, bug databases, or automated notification systems - If you store messages in Google Vault for users who turn on SMTP relay.
- If you send email with Google Workspace services other than Gmail.
For details, go to Set up comprehensive mail storage.
Mail Transfer Agent-Strict Transport Security (MTA-STS).
Preventing spoofing, phishing & spam
Expand section | Collapse all & go to top
DKIMNote: The security health tool performs lookups based only on the default Google DKIM selector (google._domainkey).
Configure DKIM for your domain by adding a digital signature to outgoing message headers using the DKIM standard. This action reduces spoofing and phishing or whaling risks. Mail servers receiving email from your domain can authenticate that your domain sent this email.
For details and instructions, go to Set up DKIM.
Status
Specifies whether a Sender Policy Framework (SPF) record is configured for your domain or if it's missing or misconfigured.
Recommendation
Configure an SPF record for your domain to help authorize email sent through your domain. This action reduces the risk of spoofing and phishing or whaling.
For better protection, use SPF and DKIM to help validate the domain that’s sending the email.
For details and instructions, go to Set up SPF.
Status
Specifies whether a Domain-based Message Authentication, Reporting, and Conformance (DMARC) record is configured for your domain or if it's missing or misconfigured.
After you configure SPF and DKIM, configure a DMARC record for your domain. This action reduces the risk of spoofing and phishing or whaling.
For details and instructions, go to Set up DMARC.
If you add a DMARC record, your users are less likely to be spoofed. In some cases, your users may experience challenges with mailing lists if they are not properly configured to operate with DMARC. Current versions of LISTSERV or MailMan can interoperate with DMARC senders. For more information, go to Set up DMARC.
Bypass spam filters for messages received from internal senders
How to turn off this setting
Configure a new Spam setting or edit an existing Spam setting.
For details and instructions, see Add a custom spam filter in Add custom spam filters to Gmail.
Using advanced phishing & malware protection
Expand section | Collapse all & go to top
Attachment safetyEnable additional Gmail attachment safety settings to reduce your risk of malware infection. For details and instructions, go to Turn on attachment protection.
Important: Google scans all messages to protect against malware, even if the additional malicious attachment protection settings are not enabled. Using these settings helps you catch additional email previously unidentified as malicious.
- Keep email in inbox and show warning (default)
- Move email to spam
Enable additional Gmail Safety settings to reduce your risk of email phishing due to links and external images. For details and instructions, go to Turn on external images and links protection.
Important: Google scans all messages to protect against phishing, even if these additional links and external images safety settings are not enabled. These settings help Gmail to catch additional email previously unidentified as phishing.
- If you enable the settings Identify links behind shortened URLs and Scan linked images, you can improve the quality of phishing detection. In turn, potentially more malicious emails will have warnings or will be moved to spam folders.
- If you enable the Show warning for any click on links to untrusted domains setting, when your users click a link in Gmail messages to untrusted domains, they get a warning. They can then choose to continue opening the link or cancel.
Turn on additional safety settings to reduce your risk of spoofing. For details and instructions, go to Turn on spoofing and authentication protection.
Important: Google scans all messages to protect against spoofing even if these additional spoofing protection settings are not enabled.
- Keep email in inbox and show warning (default)
- Move email to spam
- Quarantine
Managing spam & allowlists
Expand section | Collapse all & go to top
Approved senders without authenticationRequire sender authentication for all approved senders to reduce the risk of spoofing and phishing or whaling. We don’t recommend using this option because it bypasses the spam folder for approved senders that don't have authentication, such as SPF or DKIM, configured.
For details, go to Add custom spam filters to Gmail.
Recommendation
To reduce the risk of spoofing and phishing or whaling, do not configure email allowlist IPs.
If you have mail servers that are forwarding email to Gmail: To take full advantage of the Gmail spam filtering service and for best spam classification results, set their IP addresses as Inbound mail gateways and do not add them to an IP allowlist. For details, go to Set up an inbound mail gateway.
How to remove email allowlist IPs
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu and then Apps > Google Workspace > Gmail > Spam, Phishing and Malware.
Requires having the Gmail Settings administrator privilege.
- Point to Email allowlist and click Edit.
- Remove any IP addresses and click Save.
For more details and instructions, go to Add IP addresses to allowlists in Gmail.
Setting up Gmail
Expand section | Collapse all & go to top
MX record configurationConfigure the MX records to point to Google’s mail servers as the highest priority record to ensure correct mail flow to your Google Workspace domain users. This action reduces the risk of data deletion (through lost email) and malware threats.
For details and instructions, go to Activate Gmail for Google Workspace and Google Workspace MX record values.
Using third-party email clients
Expand section | Collapse all & go to top
POP and IMAP accessRelated topics
Google, Google Workspace, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.