Jump to content

How effective is the G-Suite email filter against phishing attacks?  

5 members have voted

  1. 1. How effective is the G-Suite email filter against phishing attacks?

    • No phishing emails at all
      4
    • Some get through, mainly link based attacks
      1
    • Some get through, attachment based attacks
      0
    • Many get through, recommend an external service
      0


Recommended Posts

Posted

Quick question for you all running G-Suite, how effective do you find the Spam \ Phishing \ Malware filtering in Gmail? Our basic Office 365 protection used to work well but recently I've been noticing more and more slipping through the net and the sales talks for going back to an external email security vendor increasing. Those third parties offer additional layers like link scanning etc. but are *pricey* as they're cloud and per-user based.

 

So going back to G-Suite, how many bad emails have you seen getting through? I ask as some of the cybersecurity breaches have had fake Google login pages as the delivery method so by that alone it suggests the Gmail filter as equally vulnerable as O365?

Posted
It isn't letting anything through here, not seen anything since we left 365. They have recently made improvements to prevent it. It seems too keen as it is also stopping legitimate stuff.
  • 5 months later...
Posted

Interestingly this just popped up in my email feed, Google adding proactive anti-phishing features to G-Suite

 

https://www.cnet.com/news/new-anti-phishing-features-come-to-google-g-suite

 

Google is applying machine learning to threat indicators and advancing models to identify what could be a phishing attack. Google says updated phishing security controls can be configured to automatically switch on Google-recommended defenses.

 

New default-on protections include:

 

Automatically flag emails from untrusted senders that have encrypted attachments or embedded scripts.

Warn against email that tries to spoof employee names or that comes from a domain that looks similar to your own domain.

Offer enhanced protections against spear phishing attacks by flagging unauthenticated email.

Scan images for phishing indicators and expand shortened URLs to uncover malicious links.

 

At the moment to get these features in Office 365 takes a paid third-party product because the default O365 filter is frankly appalling when it comes to protecting against phishing attacks. Your move Microsoft...

Posted
Email filtering in G Suite is excellent. If you put the SPAM filter on aggressive - only the best-behaved emails get through. We use admin quarantine to quarantine all SPAM (so users never se anything in their SPAM folder). We have also recently enabled the latest features which give users very explicit warning about anything remotely dodgy.
  • 2 weeks later...
Posted

Just picking up on this one. To answer the question, the default quarantines I find to be great, but being able to add your own rules based on a huge array of things from common phrases to attachment types, makes is even better. I find the filtering very good, though some do still get through, occasionally. Recently, we do get emails with links/attachments from non-existent users at our domain. The ones with attachments of a certain type get quarantined as per the policy I've set up, but others may make their way through.

 

I spent some time today seeing if there was an easy to implement solution to the problem (spoofed emails allegedly from our domain), and have come up with this. A compliance rule set up on inbound messages, using the advanced match, with sender header and envelope sender containing our domain name. These get directed to a separate quarantine for inspection. It has caught some already (also caught by the default quarantine settings and my attachment compliance), and no false positives.

 

Question for experienced users though, is there an easier way to do this? I'd have thought there would be, but haven't found it, and helpful Google conversation confirmed my method would work, but could offer no better/easier.

Posted
To probably, hopefully answer my own question after a bit more digging, I've found the (new?) Safety section in the Settings for Gmail. It has a range of options covering what I need, though it doesn't have an option to move possibly offending emails to a quarantine for admin examination (to check if it's working correctly or not), you can move them to spam or mark them with a warning.
Posted
Just picking up on this one. To answer the question, the default quarantines I find to be great, but being able to add your own rules based on a huge array of things from common phrases to attachment types, makes is even better. I find the filtering very good, though some do still get through, occasionally. Recently, we do get emails with links/attachments from non-existent users at our domain. The ones with attachments of a certain type get quarantined as per the policy I've set up, but others may make their way through.

 

I spent some time today seeing if there was an easy to implement solution to the problem (spoofed emails allegedly from our domain), and have come up with this. A compliance rule set up on inbound messages, using the advanced match, with sender header and envelope sender containing our domain name. These get directed to a separate quarantine for inspection. It has caught some already (also caught by the default quarantine settings and my attachment compliance), and no false positives.

 

Question for experienced users though, is there an easier way to do this? I'd have thought there would be, but haven't found it, and helpful Google conversation confirmed my method would work, but could offer no better/easier.

 

Do you implement SPF and DKIM?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...