Google Workspace (GSuite) Whitelisting
Google Workspace (GSuite) Whitelisting
Overview
If your organisation uses Google Workspace (formerly GSuite), you need to configure Gmail and Google Admin to allow PhishGrid simulation emails through without being filtered or marked as spam.
Step 1 — Add approved senders in Google Admin
- Go to Google Admin Console (admin.google.com)
- Navigate to Apps → Google Workspace → Gmail → Spam, Phishing and Malware
- Under Email allowlist, add the PhishGrid sending IP addresses
- Click Save
Step 2 — Create a content compliance rule to bypass spam filtering
- In Google Admin → Gmail → Compliance
- Click Content compliance → Configure
- Set the rule to apply to Inbound messages
- Under Expressions, add: Sender IP matches the PhishGrid sending IPs
- Under Actions, select Bypass spam filter
- Click Save
Step 3 — Add domains to the allowlist
- Navigate to Gmail → Spam, Phishing and Malware
- Under Blocked senders and approved senders, click Approved senders
- Add the PhishGrid simulation domains (e.g.,
mailservers.xyz,secure365.org) - Click Save
Step 4 — Disable link scanning for simulation domains (if applicable)
If your organisation uses Google's link protection (via Workspace Business or Enterprise):
- Go to Gmail → Safety → Links and external images
- Review whether automatic link scanning is enabled
- If possible, add PhishGrid simulation domains to any link exclusion list
Note: Google Workspace does not provide granular link exclusion in all tiers. If link scanning cannot be disabled, consider this when interpreting results — some clicks may be automated.
Verifying whitelisting is working
- Send a test campaign to a small group (5–10 users) before launching organisation-wide
- Check that emails arrive in the Inbox (not Spam or Promotions)
- Check that clicking the simulation link records correctly in PhishGrid
- If emails land in Spam, revisit the content compliance rule and sender allowlist
- If links appear broken or redirect incorrectly, check link scanning settings
Troubleshooting
| Issue | Likely cause | Fix |
|---|---|---|
| Emails in Spam | Sending domain not in allowlist | Add to Approved Senders |
| Emails in Promotions | Promotional content scoring | Use content compliance rule to bypass |
| Links not tracking | Link scanning pre-fetching clicks | Disable link scanning or accept bot detection will handle it |
| No emails received | IP not whitelisted | Add to Email allowlist in Admin Console |