InboxGuards checks supported Google Workspace audit records approximately every 5 minutes and turns configured account-takeover signals into plain-English alerts. Google ingestion delays and API coverage still apply.
Section 01
A compromised Google Workspace account may be used for suspicious sign-ins, malicious app consent, forwarding, or impersonation. Google records some relevant activity, subject to edition, configuration, retention, and API coverage.
That's the gap InboxGuards addresses. We check available Google Workspace admin audit records approximately every 5 minutes and raise an alert when a configured account-takeover rule matches. Google ingestion delays and API coverage still apply.
Section 02
Google security systems may expose hijacked-account or suspicious-sign-in verdicts in supported audit records. Availability depends on the Google Workspace edition, tenant configuration, and provider processing.
InboxGuards checks for those verdicts and turns supported results into alerts. Delivery depends on when Google records and exposes the event and when the next InboxGuards check completes.
Section 03
Our monitor is tuned for the specific patterns behind real-world email fraud and account takeover:
Section 04
Stolen passwords are how most takeovers start. Once a day InboxGuards reads the list of user email addresses from your Workspace directory (the same read-only admin.directory.user.readonly scope used for the 2-Step Verification check) and checks each one against Have I Been Pwned and LeakCheck — including LeakCheck's info-stealer malware logs, which show credentials copied off an infected device. Every email domain your users have is also swept for leaked addresses that have never signed in, such as former staff or shared mailboxes.
New findings become one alert per person, graded by what was exposed: an address alone, a password, or a fresh stealer-log capture. Leaked values themselves are never stored or shown. The Dark Web tab on your dashboard lists every address checked, when, and what was found, and has a Scan now button for an immediate recheck.
Section 05
The Google audit records currently used by InboxGuards do not expose user-created Gmail filter changes, such as "delete anything containing invoice." InboxGuards cannot detect those changes; evaluate other tools against their exact authorized data sources.
A filter can be one part of a larger compromise, but related activity does not always produce a record available to InboxGuards. Supported forwarding changes, OAuth grants, and sign-in records are checked when Google exposes them; the service cannot guarantee that activity surrounding a hidden filter will be visible.
Section 06
InboxGuards connects with read-only access to supported Google Workspace audit records — it does not request mailbox-content access and cannot modify your account. Alerts describe available evidence in plain English and include general response guidance; your administrator or IT provider remains responsible for tenant changes.
You also get a monthly letter-grade scorecard covering your alerts, response, and 2-Step Verification coverage — an informational snapshot, not a certification. It's $4 per user per month, no minimum, with a 30-day money-back guarantee. InboxGuards supplies alerts and general response steps; your administrator or MSP remains responsible for tenant changes and incident response.