Google Workspace phishing add-on: what to add, and what you already have
Before you buy anything, know this: Gmail's built-in filtering is good, and Workspace admins can make it stricter. Most add-ons are trying to solve one of two different problems. Know which one you have.
Problem 1: phishing reaches inboxes
That's a filtering problem. Start with the Workspace admin console's safety settings: protections against spoofing, suspicious attachments and links. Then think about an API email-security vendor if mail still gets through.
Problem 2: someone gets in anyway
Once an attacker has a working password and session, the mail they send comes from a real account and reads fine. The signs show up in the audit logs instead: a sign-in from a new place, a new Gmail filter that skips the inbox, a forwarding address, a delegate, an OAuth grant, a 2-Step Verification change. We wrote about that Gmail filter blind spot.
Comparison
| Option | Solves | Install | Price |
|---|---|---|---|
| Workspace built-in protection | Problem 1 | Already on. Tune it in the admin console. | Included |
| API email security vendors (for example Material, IRONSCALES, Avanan) | Mostly problem 1, some cover problem 2 | API connection | Varies. Check each vendor. |
| MSP with a managed SOC | Both, if in scope | Through your provider | Varies |
| InboxGuards | Problem 2 | Google Workspace Marketplace, read-only admin consent | $2/user/mo or $20/user/yr |
How InboxGuards works on Google Workspace
An admin grants two read-only scopes. InboxGuards checks the audit records at the fastest cadence standard plans allow, with no premium security licensing needed, and raises an alert when a configured takeover signal appears. It doesn't read message content, can't change your settings, and isn't a staffed SOC. Revoke access from your admin console at any time.
Common questions
Does Gmail already block phishing?
Gmail filters a lot of phishing and malware, and Workspace admins can tighten the settings. Filtering judges incoming messages, though. It doesn't tell you that someone signed into a real account and added a filter or forwarding address.
What permissions does InboxGuards request on Google Workspace?
Two read-only Admin SDK scopes: admin.reports.audit.readonly for audit logs and admin.directory.user.readonly for user status and 2-Step Verification enrollment. Gmail message content is not requested.
Where do I install it?
From the Google Workspace Marketplace listing, or by signing up at inboxguards.com.
About InboxGuards
- Price: $2 per active user per month, or $20 per user per year. No minimum, no setup fee.
- 30-day money-back guarantee. No free trial.
- Read-only access to supported Microsoft 365 and Google Workspace audit records. It does not read message content and cannot change tenant settings.
- It is an alarm. It is not a staffed SOC and not an email gateway.
- Owned and operated by Orion CMD LLC, Omaha, Nebraska. hello@inboxguards.com, 402-650-8407.