Gmail blocks more than 99.9% of spam, phishing and malware before it reaches an inbox — but the attacks that get past it are the expensive ones: business email compromise, targeted spear phishing and credential harvests that carry no malicious link for a filter to catch. A complete Google Workspace phishing protection workflow in 2026 has three layers: what Gmail does by default, what an admin must switch on in the console, and what staff must learn to catch the remainder. This guide walks through all three.
What Gmail already blocks — and what it misses
Google's AI-powered defenses stop more than 99.9% of spam, phishing attempts and malware, blocking nearly 15 billion unwanted emails a day. For commodity threats — mass campaigns with bad links and obvious payloads — the default protection is genuinely strong.
What slips through is different in kind, not degree:
- Business email compromise (BEC). A plain-text email from a lookalike domain impersonating a supplier or the CFO carries nothing for a filter to flag. Australians lost $166.8 million to payment redirection scams in 2025, up 9.3% on the prior year.
- Targeted spear phishing. Low-volume, personalised attacks written specifically to evade broad filtering models.
- Credential harvests on clean-looking pages. A link that passes URL checks but lands on a fresh, well-made clone of your sign-in page.
Layer 1: the admin console checklist
Sign in to admin.google.com and work through these in order. Each is a switch an admin owns, not a user setting.
- Enforce SPF, DKIM and DMARC. Publish the records at your DNS host, then turn on DMARC in Gmail settings with a reject policy for your primary domain. This is what stops attackers spoofing your own domain in the first place.
- Turn on enhanced phishing and malware protection. In Apps > Google Workspace > Gmail > Safety, enable the enhanced protections: scans of images and attached content, and keep trusted domain allowlists short.
- Warn on external senders and unauthenticated mail. Enable the external sender banner and the warning for mail received over an unencrypted connection.
- Protect attachments. Keep attachment and link scanning on for anomalous files and hidden scripts, and use attachment sandboxing where your edition supports it.
- Route suspicious mail for admin quarantine. Where your edition supports it, send suspicious emails to admin quarantine rather than straight to spam — this gives you visibility of what is actually targeting your users.
- Review Security Center weekly. Where the Security Investigation tool is included, a weekly look at phishing reports and affected users turns Gmail's telemetry into a habit.
Expected result: the technical floor is set. This layer stops the mass campaigns; it will not stop a convincing invoice fraud, which is why the next two layers exist.
Layer 2: give staff one reporting habit
Gmail's report phishing button moves suspicious mail to Google and improves filtering for everyone. Keep it as the single action staff take when something looks wrong — and close the loop fast. A user who reports and hears nothing within a day stops reporting.
If you run Cyber Aware, the report-a-phish add-in for Gmail and Outlook gives the same habit a training hook: reports feed the learner's risk score and your phishing campaign results, so the report button becomes part of the programme rather than a dead end.
Layer 3: monthly simulations close the loop
Filters and banners do nothing for the plain-text CEO fraud email. The only defence against it is a staff member who has seen the trick before. That is what monthly phishing simulations deliver: a safe version of the real attack on a steady cadence, with anyone who clicks immediately enrolled into a short course on exactly the trick that caught them.
A sensible 2026 cadence:
- One simulation per month for everyone, rotating pretexts: invoice fraud, payroll change requests, shared-document links, MFA reset notices.
- Higher frequency for finance and executive inboxes, which sit in the blast radius of BEC.
- Monthly reporting so click and report rates become a trend line rather than a one-off number — human risk reporting exists for exactly this.
Cyber Aware runs the whole loop under your own brand: simulations from a library of 100+ templates, auto-enrolment on click, and monthly compliance reports. Directory sync with Google Workspace enrols joiners and removes leavers automatically, so the training programme keeps itself current.
The workflow at a glance
| Layer | Owner | What it stops |
|---|---|---|
| Gmail filters and admin settings | IT admin | Mass campaigns, malware, spoofed domains |
| One reporting habit | Every staff member | Anything that lands in the inbox |
| Monthly simulations | Programme owner | The targeted attacks filters miss |
Troubleshooting
- Staff still click simulation emails. Check the pretext mix — if every simulation looks like the last one, attention fades. Rotate pretexts and difficulty monthly.
- Too many false positives in quarantine. Tighten trusted allowlists and review the quarantine weekly; blanket quarantining teaches staff that email security is someone else's problem.
- Report rates are falling. Measure reports, not just clicks — a falling report rate usually means the reporting loop is slow or invisible.
- DMARC reports show unknown senders. Legitimate third parties often send as your domain (payroll, CRM). Authorise them via SPF includes before moving to a reject policy.
FAQ
Is Gmail's built-in protection enough on its own? For commodity spam and malware, close to yes. For business email compromise and targeted attacks, no — those carry no links or attachments for filters to catch, which is why staff training and simulations carry the rest.
Where do I enable the phishing protections? In the Google Admin console: Apps > Google Workspace > Gmail > Safety. Enhanced protections, external warnings and attachment scanning all live there.
How often should we simulate phishing in Google Workspace? Monthly for everyone, with a higher cadence for finance and executive inboxes. Steady monthly variation beats an annual test.
Does the report phishing button help beyond Gmail? Yes — reported mail trains Google's filters for the whole tenant and gives you a per-user signal you can feed into training.
Do we need third-party email security on top of Google Workspace? Depends on risk appetite. Gmail's baseline is strong for SMBs; high-target sectors often add a gateway. Either way, the human layer decides the outcome of the attacks that pass both.
Related guides
- How to connect Cyber Aware to Okta for SSO and SCIM provisioning
- How to connect Cyber Aware to Slack for phishing alerts
- Security awareness training
- Compare platforms
Sources
- Google Workspace security — the 99.9% spam, phishing and malware blocking claim
- Google Workspace blog — how Gmail's AI defenses work at scale
- National Anti-Scam Centre: Targeting scams report 2025 — $166.8m lost to payment redirection scams in 2025