Jump to content

Recommended Posts

Posted (edited)

Although I've asked here previously as I thought quite a few schools use GMail via Google Workspace I still can't find any answers... and I can't work out what's going on, or what setting/rule I need to sort this out!

 

I thought it would be quite a simple question 'how to let an email through' but but after reading Google help pages and forum answers, I'm still no closer to understanding the process.

 

We have a big change coming up and the process will require password change emails, so far on the test users every email has been caught and quarantined. Soon I will have hundreds of these...

 

I've checked the matched rule which says 'Spoofing and Authentication (Domain Spoof or No Auth'), but analysing the headers in MX toolbox show all passes for TLS, SPF, DKIM etc.

 

Anyway, regardless of the reason I need to let these emails get through.

 

I've got everything ticked in Apps > Google Workspace > Settings for Gmail > Safety > Spoofing and authentication (Choose an action = Quarantine)

 

In Apps > Google Workspace > Settings for Gmail > Spam, phishing and malware (Spam = Allowed senders list with all the 'bypass' options ticked)

 

Quick question what do you put in 'address' on these lists and can you use wildcards like *@example.com ...?

 

In Apps > Google Workspace > Settings for Gmail > Compliance (a rule for Approved Sender = Inbound, If ANY of the following match the message, Location: Sender header, Contains text: example.com)

Spam

Bypass the spam filter for this message

Contains text: example.com

 

However, logically I'm presuming none of those help as it's not being identified as Spam...? Also I've noticed in the Email Log Search, these rules seem to only kick in after I've released the message from quarantine.

 

Although, the MX toolbox header analyser seems to pass it also has this line - "X-Gm-Auto-Quarantined 1" and I've found an email that failed in my DMARC report as the emails appear to come from the platform they have some sort of extra information in the address such as "<header_from>schoolname.co.uk</header_from> </identifiers> <auth_results> <dkim> <domain>example.com</domain>'' and 'bounces'.

 

Which might explain the 'spoofing' part...?

 

Anyway, how do I get them through? Can anyone tell me if I wanted an email from [email protected] to get through without turning off all the good stuff?

 

Edited by Koldov
Posted

If you raise a support ticket with the details of the message e.g. the full message details, Google can look at the back end logs and say exactly why an email was blocked. Do this as soon as possible as they don't keep the detailed logs for long - about 4 days I seem to recall. If the sender is legit, get the recipient to pop the sender into their contacts which can help.

Posted
52 minutes ago, Koldov said:

I've checked the matched rule which says 'Spoofing and Authentication (Domain Spoof or No Auth'), but analysing the headers in MX toolbox show all passes for TLS, SPF, DKIM etc.

...

Although, the MX toolbox header analyser seems to pass it also has this line - "X-Gm-Auto-Quarantined 1" and I've found an email that failed in my DMARC report as the emails appear to come from the platform they have some sort of extra information in the address such as "<header_from>schoolname.co.uk</header_from> </identifiers> <auth_results> <dkim> <domain>example.com</domain>'' and 'bounces'.

 

Which might explain the 'spoofing' part...?

IIRC an email can pass DKIM, in that it is signed, but not pass the DKIM alignment portion of DMARC (if the domain in the DKIM signature doesn't match the envelope's 'from' domain). That would be a misconfiguration on the part of the sender: at that point your Gmail service is just honouring the sender's DMARC policy, which might be instructing Gmail to quarantine it regardless of whatever rules you've got set up.

Posted
57 minutes ago, Koldov said:

Anyway, how do I get them through? Can anyone tell me if I wanted an email from [email protected] to get through without turning off all the good stuff

Having that email address in an address list that's used in a rule in Admin > Apps > Google Workspace > Settings for Gmail > Spam, phishing and malware > Spam is probably all you should need to do to get messages from that sender to bypass the spam filters. However, if there's a misconfiguration on the sender side, it might end up rejected or quarantied regardless, before it even reaches that rule.

  • Thanks 1
Posted

Yes, you're right it definitely is being quarantined before it reaches that rule. For the ones I've released it shows the following (as in, once released from quarantine, only then it looks at those rules):

 

image.png.4170de6f7a33e22d6790b43b8ef6150c.png

 

Also you are correct it fails on the DKIM alignment (that's annoying):

 

image.png.916c935010f41c4f113e0340b13edb49.png

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...