Phishing Simulation

Google Workspace (GSuite) Whitelisting

Google Workspace (GSuite) Whitelisting

Overview

Google Workspace needs Gmail and the Admin console configured to allow PhishGrid simulation emails through without filtering or spam-marking. Use your current values from Sending Domains & IPs.


Step 1 — Add approved sender IPs (Email allowlist)

  1. Google Admin Console → Apps → Google Workspace → Gmail → Spam, Phishing and Malware.
  2. Under Email allowlist, add your PhishGrid sending IP addresses.
  3. Save.

Step 2 — Content compliance rule to bypass spam

  1. Gmail → Compliance → Content compliance → Configure.
  2. Apply to Inbound messages.
  3. Expression: Source IP matches your PhishGrid sending IPs (or match your PhishGrid simulation header, if your account provides one).
  4. Action: Bypass spam filter for this message. Save.

Step 3 — Approved senders (domains)

  1. Gmail → Spam, Phishing and Malware → Blocked senders / Approved senders → Approved senders.
  2. Add your PhishGrid simulation domains. Save.

Google's link protection (Business/Enterprise) can pre-fetch links. Where your tier allows, add your PhishGrid domains to a link exclusion; otherwise PhishGrid bot-detection will discount automated clicks.

Verify

Issue Likely cause Fix
Emails in Spam Domain not approved Add to Approved Senders
Emails in Promotions Promotional scoring Bypass via content compliance rule
Links not tracking Link scanning pre-fetch Exclude domains or rely on bot detection
No emails received IP not allowlisted Add to Email allowlist

Console menus and labels vary by product version and edition — use these as a guide and confirm against your gateway's admin documentation. Always whitelist the current values from Sending Domains & IPs, and send a 5–10 user test campaign before launching organisation-wide.