Google Workspace phishing protection: complete 2026 workflow

A complete 2026 Google Workspace phishing protection workflow: Gmail's built-in filters, admin console settings, reporting habits and monthly simulations.

Gmail blocks more than 99.9% of spam, phishing and malware before it reaches an inbox — but the attacks that get past it are the expensive ones: business email compromise, targeted spear phishing and credential harvests that carry no malicious link for a filter to catch. A complete Google Workspace phishing protection workflow in 2026 has three layers: what Gmail does by default, what an admin must switch on in the console, and what staff must learn to catch the remainder. This guide walks through all three.

What Gmail already blocks — and what it misses

Google's AI-powered defenses stop more than 99.9% of spam, phishing attempts and malware, blocking nearly 15 billion unwanted emails a day. For commodity threats — mass campaigns with bad links and obvious payloads — the default protection is genuinely strong.

What slips through is different in kind, not degree:

Layer 1: the admin console checklist

Sign in to admin.google.com and work through these in order. Each is a switch an admin owns, not a user setting.

  1. Enforce SPF, DKIM and DMARC. Publish the records at your DNS host, then turn on DMARC in Gmail settings with a reject policy for your primary domain. This is what stops attackers spoofing your own domain in the first place.
  2. Turn on enhanced phishing and malware protection. In Apps > Google Workspace > Gmail > Safety, enable the enhanced protections: scans of images and attached content, and keep trusted domain allowlists short.
  3. Warn on external senders and unauthenticated mail. Enable the external sender banner and the warning for mail received over an unencrypted connection.
  4. Protect attachments. Keep attachment and link scanning on for anomalous files and hidden scripts, and use attachment sandboxing where your edition supports it.
  5. Route suspicious mail for admin quarantine. Where your edition supports it, send suspicious emails to admin quarantine rather than straight to spam — this gives you visibility of what is actually targeting your users.
  6. Review Security Center weekly. Where the Security Investigation tool is included, a weekly look at phishing reports and affected users turns Gmail's telemetry into a habit.

Expected result: the technical floor is set. This layer stops the mass campaigns; it will not stop a convincing invoice fraud, which is why the next two layers exist.

Layer 2: give staff one reporting habit

Gmail's report phishing button moves suspicious mail to Google and improves filtering for everyone. Keep it as the single action staff take when something looks wrong — and close the loop fast. A user who reports and hears nothing within a day stops reporting.

If you run Cyber Aware, the report-a-phish add-in for Gmail and Outlook gives the same habit a training hook: reports feed the learner's risk score and your phishing campaign results, so the report button becomes part of the programme rather than a dead end.

Layer 3: monthly simulations close the loop

Filters and banners do nothing for the plain-text CEO fraud email. The only defence against it is a staff member who has seen the trick before. That is what monthly phishing simulations deliver: a safe version of the real attack on a steady cadence, with anyone who clicks immediately enrolled into a short course on exactly the trick that caught them.

A sensible 2026 cadence:

Cyber Aware runs the whole loop under your own brand: simulations from a library of 100+ templates, auto-enrolment on click, and monthly compliance reports. Directory sync with Google Workspace enrols joiners and removes leavers automatically, so the training programme keeps itself current.

The workflow at a glance

LayerOwnerWhat it stops
Gmail filters and admin settingsIT adminMass campaigns, malware, spoofed domains
One reporting habitEvery staff memberAnything that lands in the inbox
Monthly simulationsProgramme ownerThe targeted attacks filters miss

Troubleshooting

FAQ

Is Gmail's built-in protection enough on its own? For commodity spam and malware, close to yes. For business email compromise and targeted attacks, no — those carry no links or attachments for filters to catch, which is why staff training and simulations carry the rest.

Where do I enable the phishing protections? In the Google Admin console: Apps > Google Workspace > Gmail > Safety. Enhanced protections, external warnings and attachment scanning all live there.

How often should we simulate phishing in Google Workspace? Monthly for everyone, with a higher cadence for finance and executive inboxes. Steady monthly variation beats an annual test.

Does the report phishing button help beyond Gmail? Yes — reported mail trains Google's filters for the whole tenant and gives you a per-user signal you can feed into training.

Do we need third-party email security on top of Google Workspace? Depends on risk appetite. Gmail's baseline is strong for SMBs; high-target sectors often add a gateway. Either way, the human layer decides the outcome of the attacks that pass both.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.