Configure Google Workspace advanced phishing and malware protection settings
SKILL.md
Implementing Google Workspace Phishing Protection
Overview
Google Workspace provides advanced phishing and malware protection through the Admin Console under Apps > Google Workspace > Gmail > Safety. Key features include Enhanced Pre-Delivery Scanning that examines messages more thoroughly before they reach inboxes, attachment and link protection that scans for malware and checks against known malicious sites, and spoofing detection for domain and employee name impersonation. Google's Advanced Protection Program (APP) provides the strongest account security for high-privilege users.
When to Use
When deploying or configuring implementing google workspace phishing protection capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
Google Workspace Business Standard or higher license
Gmail Settings administrator privilege
Understanding of organizational email flow and third-party integrations
Access to Google Admin Console (admin.google.com)
DNS management access for SPF, DKIM, DMARC configuration
Workflow
Step 1: Configure Advanced Phishing Protection
Navigate to Admin Console > Apps > Google Workspace > Gmail > Safety
Enable "Protect against domain spoofing based on similar domain names"
Enable "Protect against spoofing of employee names"
Enable "Protect against inbound emails spoofing your domain"
Set action for detected spoofing: quarantine or move to spam with warning banner
Apply settings to all organizational units or specific high-risk groups
Step 2: Enable Enhanced Pre-Delivery Scanning
In Safety settings, enable "Enhanced pre-delivery message scanning"
This adds additional delay (seconds) to scan messages more thoroughly
Configure to detect phishing attempts that evade initial filters
Enable "Identify links behind shortened URLs"
Enable "Scan linked images" for image-based phishing detection
Step 3: Configure Attachment Protection
Enable "Protect against encrypted attachments from untrusted senders"
Enable "Protect against attachments with scripts from untrusted senders"
Enable "Protect against anomalous attachment types in emails"
Configure action: warn users, move to spam, or quarantine
Create exceptions for known legitimate encrypted file senders