Jump to content

Google Workspace - GMail - Quarantine - Rules


Recommended Posts

Posted

Sorry yet another post about Google Workspace...

 

Not long ago I finally thought I'd got my head around O365 quarantine and adding the rules, changing the default behaviours etc.

 

Then it was decided we were going to move to GMail...

 

I have found where the quarantine section is, but looking through the emails, I can't work out why most of them are there!

 

I've expanded the section for the 'Matched Rule' and it doesn't actually give me any information.

 

Q.JPG

 

I also can't seem to work out where these 'rules' are and what they contain...

Posted

The built-in spam/phishing rules in Gmail are kept deliberately opaque by Google, I think. If you were to add some specific rules of your own that directed mail into a quarantine, then you would likely see those rule names listed in the matching info.

 

Here's an example of a message quarantined by one of the built-in rules (we have enhanced spam settings turned on).

 

2023-11-01 16_13_58-Admin quarantine.png

 

And here's one quarantined by a custom rule (a rule named "Students - Quarantine Twitter").

 

2023-11-01 16_16_05-Admin quarantine.png

 

Doesn't really explain why you're not seeing any rule name there. Maybe a browser page issue? Clear cache or test in a private window?

  • Thanks 1
Posted (edited)
If you were to add some specific rules of your own that directed mail into a quarantine

 

Great, but where are the settings to do that? I've looked a few times now and can't find anywhere to set any rules...

 

Doesn't really explain why you're not seeing any rule name there. Maybe a browser page issue? Clear cache or test in a private window?

 

Thanks, I will look into that.

 

EDIT: Just tried in an incognito window and still no rule description... :mad:

Edited by Koldov
Posted
Great, but where are the settings to do that? I've looked a few times now and can't find anywhere to set any rules...

 

Admin > Apps > Google Workspace > Gmail > Compliance > Content compliance.

Create rules there (they can either be at the root or at a specific OU). Rules include an option to quarantine matching messages.

 

2023-11-02 10_36_59-Compliance.png

 

A rule can be set as disabled, but then overridden to be enabled at a child OU (or vice versa), which offers another layer of logic to rule building.

  • Thanks 1
Posted

Am seeing a smiilar lack of matching details on quarantined messages. Not exactly as you've shown in your screenshot, but here's a couple of examples: one shows a matching reason (albeit lacking in informative specifics) with another being blank.

 

2023-11-02 10_43_35-Admin quarantine.png

  • Thanks 1
Posted
Yeah that top one in the screenshot is what I get for all of mine, but at least it's not just me doing something stupid because I have no idea what I'm doing!
  • 2 months later...
Posted

Just a follow up and possibly an answer of sorts...

 

https://www.googlecloudcommunity.com/gc/Workspace-Q-A/Why-am-I-unable-to-see-the-specific-rule-that-triggered-an-email/m-p/429092

 

It's from a while ago, so Google obviously didn't 'fix' it or even see it as broken... but at least I know now it isn't something I've done (or am not doing)...

 

Something about, if it matches one of the basic/default 'Safety Features' rather than a particular 'rule' maybe (as we don't have any 'rules' set-up) there isn't any rule description to report a match to?

Posted

Also, this...

 

"Important: Source and matched string are displayed when available. Gmail makes a best effort to display the rule associated with a message, but some messages may not display a rule."

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...