EMAIL-006: Email Allowlist/Blocklist Review

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Email allowlists and blocklists should be reviewed for overly permissive entries. Allowlisted senders bypass spam filtering and can be exploited if misconfigured

Recommended value

Minimal allowlist entries with no wildcard domains; blocklist actively maintained

Remediation

Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Review Email allowlists and Blocked senders lists for overly broad entries

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-006
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
SI-8, SC-7(5)
CIS Benchmark
2.6
CISA SCuBA
GWS.GMAIL.14.1v1
MITRE ATT&CK
T1566.001