EMAIL-007: Inbound Gateway Configuration

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Inbound email gateways should be properly configured to preserve sender authentication results. Misconfigured gateways can strip SPF/DKIM/DMARC headers or bypass security filtering

Recommended value

Inbound gateways configured with correct IP ranges and header preservation

Remediation

Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Inbound gateway > Verify gateway IPs and that authentication headers are preserved

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-007
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
SI-8, SC-7
CIS Benchmark
2.7
MITRE ATT&CK
T1566.001, T1566.002