EMAIL-016: Links and External Images Protection

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Link protection should be enabled to scan URLs for phishing and malware. External image proxying prevents tracking pixels and IP disclosure

Recommended value

URL scanning, click-time warnings, and external image proxying enabled

Remediation

Admin Console > Apps > Google Workspace > Gmail > Safety > Links and external images > Enable 'Identify links behind shortened URLs', 'Scan linked images', and 'Show warning prompt for click on links to untrusted domains'

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-016
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed

Framework mappings

NIST SP 800-53
SI-3, SI-8
CIS Benchmark
2.16
CISA SCuBA
GWS.GMAIL.6.1v1, GWS.GMAIL.6.2v1, GWS.GMAIL.6.3v1, GWS.GMAIL.6.4v1
MITRE ATT&CK
T1566.002, T1204.001