EMAIL-008: Email Routing Rules Audit

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Email routing rules should be reviewed for suspicious or unauthorized configurations. Malicious routing rules can redirect email to attacker-controlled destinations

Recommended value

All routing rules reviewed and documented with business justification

Remediation

Admin Console > Apps > Google Workspace > Gmail > Routing > Review all routing rules, default routing, and recipient maps for unauthorized entries

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-008
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
SI-4, AU-6
CIS Benchmark
2.8
MITRE ATT&CK
T1114.003, T1020