gshaw Posted October 16, 2017 Posted October 16, 2017 Quick question for you all running G-Suite, how effective do you find the Spam \ Phishing \ Malware filtering in Gmail? Our basic Office 365 protection used to work well but recently I've been noticing more and more slipping through the net and the sales talks for going back to an external email security vendor increasing. Those third parties offer additional layers like link scanning etc. but are *pricey* as they're cloud and per-user based. So going back to G-Suite, how many bad emails have you seen getting through? I ask as some of the cybersecurity breaches have had fake Google login pages as the delivery method so by that alone it suggests the Gmail filter as equally vulnerable as O365?
FN-GM Posted October 16, 2017 Posted October 16, 2017 It isn't letting anything through here, not seen anything since we left 365. They have recently made improvements to prevent it. It seems too keen as it is also stopping legitimate stuff.
gshaw Posted March 26, 2018 Author Posted March 26, 2018 Interestingly this just popped up in my email feed, Google adding proactive anti-phishing features to G-Suite https://www.cnet.com/news/new-anti-phishing-features-come-to-google-g-suite Google is applying machine learning to threat indicators and advancing models to identify what could be a phishing attack. Google says updated phishing security controls can be configured to automatically switch on Google-recommended defenses. New default-on protections include: Automatically flag emails from untrusted senders that have encrypted attachments or embedded scripts. Warn against email that tries to spoof employee names or that comes from a domain that looks similar to your own domain. Offer enhanced protections against spear phishing attacks by flagging unauthenticated email. Scan images for phishing indicators and expand shortened URLs to uncover malicious links. At the moment to get these features in Office 365 takes a paid third-party product because the default O365 filter is frankly appalling when it comes to protecting against phishing attacks. Your move Microsoft...
rogerdnixon Posted March 26, 2018 Posted March 26, 2018 Email filtering in G Suite is excellent. If you put the SPAM filter on aggressive - only the best-behaved emails get through. We use admin quarantine to quarantine all SPAM (so users never se anything in their SPAM folder). We have also recently enabled the latest features which give users very explicit warning about anything remotely dodgy.
chinesewhispers Posted April 4, 2018 Posted April 4, 2018 Just picking up on this one. To answer the question, the default quarantines I find to be great, but being able to add your own rules based on a huge array of things from common phrases to attachment types, makes is even better. I find the filtering very good, though some do still get through, occasionally. Recently, we do get emails with links/attachments from non-existent users at our domain. The ones with attachments of a certain type get quarantined as per the policy I've set up, but others may make their way through. I spent some time today seeing if there was an easy to implement solution to the problem (spoofed emails allegedly from our domain), and have come up with this. A compliance rule set up on inbound messages, using the advanced match, with sender header and envelope sender containing our domain name. These get directed to a separate quarantine for inspection. It has caught some already (also caught by the default quarantine settings and my attachment compliance), and no false positives. Question for experienced users though, is there an easier way to do this? I'd have thought there would be, but haven't found it, and helpful Google conversation confirmed my method would work, but could offer no better/easier.
chinesewhispers Posted April 4, 2018 Posted April 4, 2018 To probably, hopefully answer my own question after a bit more digging, I've found the (new?) Safety section in the Settings for Gmail. It has a range of options covering what I need, though it doesn't have an option to move possibly offending emails to a quarantine for admin examination (to check if it's working correctly or not), you can move them to spam or mark them with a warning.
Primus Posted April 4, 2018 Posted April 4, 2018 Just picking up on this one. To answer the question, the default quarantines I find to be great, but being able to add your own rules based on a huge array of things from common phrases to attachment types, makes is even better. I find the filtering very good, though some do still get through, occasionally. Recently, we do get emails with links/attachments from non-existent users at our domain. The ones with attachments of a certain type get quarantined as per the policy I've set up, but others may make their way through. I spent some time today seeing if there was an easy to implement solution to the problem (spoofed emails allegedly from our domain), and have come up with this. A compliance rule set up on inbound messages, using the advanced match, with sender header and envelope sender containing our domain name. These get directed to a separate quarantine for inspection. It has caught some already (also caught by the default quarantine settings and my attachment compliance), and no false positives. Question for experienced users though, is there an easier way to do this? I'd have thought there would be, but haven't found it, and helpful Google conversation confirmed my method would work, but could offer no better/easier. Do you implement SPF and DKIM?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now