← All controls

18 Residual mail & service hygiene

The remaining mail and service defaults, all of them free on every edition. Gmail's Safety protections — attachments, links and external images, spoofing and unauthenticated senders — are turned on and set to quarantine rather than a warning banner; the spam-bypass holes (an over-broad approved-senders list, 'bypass spam filters for internal senders') are closed; comprehensive mail storage is turned on so Vault actually sees everything; and unused services such as Google Sites are turned off, because an unused publishing surface inside the tenant is a free phishing host carrying your domain's reputation. The Gmail Security Sandbox (25 Gmail Security Sandbox + safety-toggle verification) adds attachment detonation on top of these toggles, but it is edition-gated and these are not.

Caveats

Setup steps

  1. open ↗

    Apps › Google Workspace › Gmail › Safety

    Attachments (encrypted, scripts, anomalous)
    On + Quarantine
    Links and external images
    all On
    Spoofing and authentication
    all On (incl. 'Protect against domain spoofing based on similar domain names' and 'Protect against any unauthenticated emails')
  2. open ↗

    Apps › Google Workspace › Gmail › Spam, phishing and malware

    Bypass spam filters for internal senders
    Off
    approved-sender lists
    empty or narrowly justified
    Enhanced pre-delivery message scanning
    On
  3. open ↗

    Apps › Google Workspace › Sites › Service status

    Sites service status
    Off for everyone

How to verify

  1. Walk the four hygiene screens and confirm each setting matches the control; there is no user-visible surface to probe.

v0.2.0 Assure policy #27 · #18 ↗