EMAIL-035: No domains bypass spam filtering and warnings (GWS.GMAIL.18.2)
- Platform
- Google Workspace
- Category
- Advanced Threat Protection
- Severity
- High
- Zero Trust pillar
- Data (weight 3)
- Golden fixtures
- 4
- Branch coverage
- Declared verdict paths, each proven by a fixture
- Provenance
- baseline
What it checks
SCuBA GWS.GMAIL.18.2: adding a domain to a bypass list disables spam filtering and suppresses the warning banners for every message from it, so any attacker who can send as that domain, or who compromises a single mailbox within it, reaches inboxes unfiltered and unlabelled. Reads gmail.spam_override_lists and fails where warningDomainsFound reports domains configured to bypass warnings.
Recommended value
No domain is configured to bypass spam filtering or warning banners
Remediation
Admin console > Apps > Google Workspace > Gmail > Spam, phishing and malware. Review every allowlist and inbound gateway entry, and remove domains configured to bypass filtering or hide warnings. Prefer narrowly scoped rules over blanket domain trust.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| field-missing | PASS |
| known-bad | FAIL |
| not-assessed | Not Assessed |
Framework mappings
- CISA SCuBA
- GWS.GMAIL.18.2v1
- NIST SP 800-53
- SI-8, SC-7, SI-3
- MITRE ATT&CK
- T1566