Cybersecurity and Infrastructure Security Agency Logo

Light mode

Gmail Baseline Report

Customer Name Customer Domain Customer ID Report Date Baseline Version Tool Version
Cool Example Org example.org ABCDEFG 07/20/2026 12:43:08 PDT 1 v1.0.0
Policy Indicators:

GMAIL-1 Mail Delegation

Control ID Requirement Result Criticality Details
GWS.GMAIL.1.1v1 Mail delegation SHOULD be disabled.
Automated Check
Pass Should Requirement met.

GMAIL-2 DomainKeys Identified Mail

Control ID Requirement Result Criticality Details
GWS.GMAIL.2.1v1 DKIM SHOULD be enabled for all domains.
Automated Check Configurable
Warning Should 2 of 3 agency domain(s) found in violation: lang.biz, example.org. View DNS logs for more details.

GMAIL-3 Sender Policy Framework

Control ID Requirement Result Criticality Details
GWS.GMAIL.3.1v1 An SPF policy SHALL be published for each domain that fails all non-approved senders.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall 1 of 3 agency domain(s) found in violation: example.org. View DNS logs for more details.

GMAIL-4 Domain-based Message Authentication, Reporting, and Conformance

Control ID Requirement Result Criticality Details
GWS.GMAIL.4.1v1 A DMARC policy SHALL be published at the full domain or the second-level domain for all Google Workspace domains, including user alias domains.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall 2 of 4 agency domain(s) found in violation: lang.biz, example.org. 1 domain(s) have multiple DMARC records and will fail the policy check: lang.biz. DMARC records should only have one record according to RFC 7489. View DNS logs for more details.
GWS.GMAIL.4.2v1 The DMARC message rejection option SHALL be p=reject.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall 2 of 4 agency domain(s) found in violation: lang.biz, example.org. 1 domain(s) have multiple DMARC records and will fail the policy check: lang.biz. DMARC records should only have one record according to RFC 7489. View DNS logs for more details.
GWS.GMAIL.4.3v1 The DMARC point of contact for aggregate reports SHALL include `reports@dmarc.cyber.dhs.gov`.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall 3 of 4 agency domain(s) found in violation: lang.biz, example.org, example.org.test-google-a.com. 1 domain(s) have multiple DMARC records and will fail the policy check: lang.biz. DMARC records should only have one record according to RFC 7489. View DNS logs for more details.
GWS.GMAIL.4.4v1 An agency point of contact SHOULD be included for aggregate and failure reports.
Automated Check Configurable
Warning Should 4 of 4 agency domain(s) found in violation: walls.info, lang.biz, example.org, example.org.test-google-a.com. 1 domain(s) have multiple DMARC records and will fail the policy check: lang.biz. DMARC records should only have one record according to RFC 7489. View DNS logs for more details.

GMAIL-5 Attachment Protections

Control ID Requirement Result Criticality Details
GWS.GMAIL.5.1v1 "Protect against encrypted attachments from untrusted senders" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.5.2v1 "Protect against attachments with scripts from untrusted senders" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.5.3v1 "Protect against anomalous attachment types in emails" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.5.4v1 Google SHOULD be allowed to automatically apply future recommended settings for attachments.
Automated Check
Warning Should The following OUs are non-compliant:
  • Cool Example Org: Automatically enables all future added settings is set to: disabled
GWS.GMAIL.5.5v1 Emails flagged by SCuBA policies GWS.GMAIL.5.1 through GWS.GMAIL.5.3 SHALL NOT be kept in inbox.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.

GMAIL-6 Links and External Images Protection

Control ID Requirement Result Criticality Details
GWS.GMAIL.6.1v1 "Identify links behind shortened URLs" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.6.2v1 "Scan linked images" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.6.3v1 "Show warning prompt for any click on links to untrusted domains" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.6.4v1 Google SHALL be allowed to automatically apply future recommended settings for links and external images.
BOD 25-01 Requirement Automated Check
Pass Should Requirement met.

GMAIL-7 Spoofing and Authentication Protection

Control ID Requirement Result Criticality Details
GWS.GMAIL.7.1v1 "Protect against domain spoofing based on similar domain names" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.2v1 "Protect against spoofing of employee names" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.3v1 "Protect against inbound emails spoofing your domain" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.4v1 "Protect against any unauthenticated emails" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.5v1 "Protect your Groups from inbound emails spoofing your domain" SHALL be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.6v1 Emails flagged by SCuBA policies GWS.GMAIL.7.1 through GWS.GMAIL.7.5 SHALL NOT be kept in inbox.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.
GWS.GMAIL.7.7v1 Google SHALL be allowed to automatically apply future recommended settings for spoofing and authentication.
BOD 25-01 Requirement Automated Check
Pass Should Requirement met.

GMAIL-8 User Email Uploads

Control ID Requirement Result Criticality Details
GWS.GMAIL.8.1v1 User email uploads SHALL be disabled to protect against unauthorized files being introduced into the secured environment.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.

GMAIL-9 POP and IMAP Access for Users

Control ID Requirement Result Criticality Details
GWS.GMAIL.9.1v1 POP and IMAP access SHALL be disabled to protect sensitive agency or organization emails from being accessed through legacy applications or other third-party mail clients.
BOD 25-01 Requirement Automated Check Configurable
Fail Shall The following OUs are non-compliant:
  • Cool Example Org (group michelle16@example.com): IMAP access is enabled
  • Cool Example Org (group michelle16@example.com): IMAP access is enabled
  • Kristen Haynes's OU (in Peter Lewis's OU): IMAP access is enabled
  • Charlene Reid's OU: IMAP and POP access are enabled
  • April Hernandez's OU (in Peter Lewis's OU/Kristen Haynes's OU): IMAP access is enabled

GMAIL-10 Google Workspace Sync

Control ID Requirement Result Criticality Details
GWS.GMAIL.10.1v1 Google Workspace Sync SHOULD be disabled.
Automated Check
Pass Shall Requirement met.

GMAIL-11 Automatic Forwarding

Control ID Requirement Result Criticality Details
GWS.GMAIL.11.1v1 Automatic forwarding SHOULD be disabled, especially to external domains.
Automated Check
Pass Shall Requirement met.

GMAIL-12 Per-user Outbound Gateways

Control ID Requirement Result Criticality Details
GWS.GMAIL.12.1v1 The option to use a per-user outbound gateway that is a mail server other than the Google Workspace (GWS) mail servers SHALL be disabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.

GMAIL-13 Unintended External Reply Warning

Control ID Requirement Result Criticality Details
GWS.GMAIL.13.1v1 Unintended external reply warnings SHALL be enabled.
Automated Check Log-Based Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Warn for external participants is set to disabled

GMAIL-14 Email Allowlist

Control ID Requirement Result Criticality Details
GWS.GMAIL.14.1v1 An email allowlist SHOULD NOT be implemented.
Automated Check
Pass Should Email allowlists are disabled in Cool Example Org.

GMAIL-15 Enhanced Pre-Delivery Message Scanning

Control ID Requirement Result Criticality Details
GWS.GMAIL.15.1v1 Enhanced pre-delivery message scanning SHALL be enabled to prevent phishing.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Enhanced pre-delivery message scanning is disabled

GMAIL-16 Security Sandbox

Control ID Requirement Result Criticality Details
GWS.GMAIL.16.1v1 Security sandbox SHOULD be enabled to provide additional email protections.
Automated Check Log-Based Check
No events found Should No relevant event in the current logs for the top-level OU, Cool Example Org. While we are unable to determine the state from the logs, the default setting is non-compliant; manual check recommended.

GMAIL-17 Comprehensive Mail Storage

Control ID Requirement Result Criticality Details
GWS.GMAIL.17.1v1 Comprehensive mail storage SHOULD be enabled to allow information traceability across applications.
Manual
N/A Should/Not-Implemented Currently not able to be tested automatically; please manually check.

GMAIL-18 Spam Filtering

Control ID Requirement Result Criticality Details
GWS.GMAIL.18.1v1 Domains SHALL NOT be added to lists that bypass spam filters.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Spam filters are bypassed for one or more domains: {Scuba: [Scuba: (lang.biz, example.org)]}
GWS.GMAIL.18.2v1 Domains SHALL NOT be added to lists that bypass spam filters and hide warnings.
BOD 25-01 Requirement Automated Check
Fail Shall The following OUs are non-compliant:
  • Cool Example Org: Warnings and spam filters are bypassed for one or more domains: {Scuba: [Scuba: (lang.biz, example.org), Example: (bbc.co.uk, npr.org), ExampleList: (test.com)]}, {Second Rule: [ExampleList: (test.com)]}
GWS.GMAIL.18.3v1 "Bypass spam filters" and "hide warnings for all messages from internal and external senders" SHALL NOT be enabled.
BOD 25-01 Requirement Automated Check
Pass Shall Requirement met.

DNS Logs

DNS queries ScubaGear made while identifying SPF, DKIM, and DMARC records. Note: if DNS queries unexepectedly return 0 txt records, it may be a sign the system-defualt resolver is unable to resolve the domain names (e.g., due to a split horizon setup).

SPF

Query Name Query Method Summary Answers
c​h​a​n​.​c​o​m traditional Query returned 2 txt records M​S​=​m​s​8​1​6​7​0​3​5​8
v​=​s​p​f​1​ ​i​n​c​l​u​d​e​:​s​p​f​.​e​f​w​d​.​r​e​g​i​s​t​r​a​r​-​s​e​r​v​e​r​s​.​c​o​m​ ​-​a​l​l
s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
b​a​k​e​r​-​d​a​v​i​s​.​c​o​m traditional Query returned 3 txt records m​s​c​i​d​=​f​/​4​e​0​7​1​K​O​h​k​m​P​8​A​a​n​r​5​s​N​g​U​q​y​T​B​r​v​r​F​x​5​n​K​S​s​w​P​x​u​5​Z​s​q​L​0​b​d​A​g​V​o​3​m​7​f​5​K​Y​u​+​i​n​b​K​A​5​Y​v​i​U​P​z​z​/​S​x​N​S​0​p​l​o​J​Q​=​=
v​=​s​p​f​1​ ​i​n​c​l​u​d​e​:​s​p​f​.​p​r​o​t​e​c​t​i​o​n​.​o​u​t​l​o​o​k​.​c​o​m​ ​-​a​l​l
g​o​o​g​l​e​-​s​i​t​e​-​v​e​r​i​f​i​c​a​t​i​o​n​=​P​5​G​M​V​W​S​D​L​F​8​E​H​8​E​D​9​3​1​T​T​L​8​Q​W​1​2​A​F​2

DKIM

Query Name Query Method Summary Answers
g​o​o​g​l​e​.​_​d​o​m​a​i​n​k​e​y​.​c​h​a​n​.​c​o​m traditional Query returned 1 txt records v​=​D​K​I​M​1​;​ ​k​=​r​s​a​;​ ​p​=​M​I​I​B​I​j​A​N​B​g​k​q​h​k​i​G​9​w​0​B​A​Q​E​F​A​A​O​C​A​Q​8​A​M​I​I​B​C​g​K​C​A​Q​E​A​3​9​3​D​g​v​o​A​H​B​y​h​n​2​J​d​v​M​I​D​n​C​b​H​K​x​l​T​C​f​5​j​Z​j​Y​S​w​d​u​7​L​j​x​A​g​y​E​u​5​L​f​0​L​u​k​s​3​2​f​b​+​B​f​b​7​/​8​+​W​0​N​F​3​0​K​T​m​i​F​R​N​I​E​l​L​Z​U​f​M​m​J​J​e​A​I​7​U​z​n​8​2​t​5​n​b​p​L​0​w​r​Z​1​P​5​C​T​0​O​E​+​L​Z​6​X​q​Z​S​8​B​f​H​c​F​V​S​b​9​f​/​k​Q​5​H​o​e​+​r​G​p​R​R​c​w​j​B​j​c​U​T​1​T​I​N​K​I​8​+​3​2​N​E​O​p​o​G​y​Y​I​0​w​9​e​0​a​p​j​x​v​U​e​1​a​B​"​ ​"​R​t​x​j​c​C​0​w​7​w​I​e​v​P​m​O​I​F​O​z​D​P​n​O​x​m​G​T​e​t​o​3​M​W​Y​9​I​G​S​M​z​8​E​e​e​a​w​q​A​p​N​a​F​x​9​b​D​1​d​C​Z​u​e​J​W​x​7​P​n​d​t​J​6​J​X​Z​h​m​1​Q​K​3​4​Z​X​f​i​f​Y​1​w​N​8​4​s​C​0​y​p​a​I​z​I​B​q​r​j​C​R​m​l​a​o​+​7​V​h​D​l​1​6​a​Y​J​H​Y​j​P​V​K​L​s​J​C​Y​h​S​o​G​v​Y​f​/​9​w​4​I​e​Q​I​D​A​Q​A​B
g​o​o​g​l​e​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
g​o​o​g​l​e​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
s​e​l​e​c​t​o​r​1​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
s​e​l​e​c​t​o​r​1​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
s​e​l​e​c​t​o​r​2​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
s​e​l​e​c​t​o​r​2​.​_​d​o​m​a​i​n​k​e​y​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
g​o​o​g​l​e​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m traditional Query returned NXDOMAIN
g​o​o​g​l​e​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m DoH Query returned NXDomain
s​e​l​e​c​t​o​r​1​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m traditional Query returned NXDOMAIN
s​e​l​e​c​t​o​r​1​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m DoH Query returned NXDomain
s​e​l​e​c​t​o​r​2​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m traditional Query returned NXDOMAIN
s​e​l​e​c​t​o​r​2​.​_​d​o​m​a​i​n​k​e​y​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m DoH Query returned NXDomain

DMARC

Query Name Query Method Summary Answers
_​d​m​a​r​c​.​c​h​a​n​.​c​o​m traditional Query returned 1 txt records v​=​D​M​A​R​C​1​;​ ​p​=​r​e​j​e​c​t​;​ ​r​u​a​=​m​a​i​l​t​o​:​r​e​p​o​r​t​s​@​d​m​a​r​c​.​c​y​b​e​r​.​d​h​s​.​g​o​v​;​ ​p​c​t​=​1​0​0​;​ ​r​u​f​=​m​a​i​l​t​o​:​r​e​p​o​r​t​s​@​d​m​a​r​c​.​c​y​b​e​r​.​d​h​s​.​g​o​v
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z​.​t​e​s​t​-​g​o​o​g​l​e​-​a​.​c​o​m traditional Query returned 0 txt records
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z​.​t​e​s​t​-​g​o​o​g​l​e​-​a​.​c​o​m DoH Query returned 0 txt records
_​d​m​a​r​c​.​t​e​s​t​-​g​o​o​g​l​e​-​a​.​c​o​m traditional Query returned 1 txt records v​=​D​M​A​R​C​1​;​ ​p​=​r​e​j​e​c​t​;​ ​r​u​a​=​m​a​i​l​t​o​:​m​a​i​l​a​u​t​h​-​r​e​p​o​r​t​s​@​g​o​o​g​l​e​.​c​o​m
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z traditional Query returned NXDOMAIN
_​d​m​a​r​c​.​s​u​l​l​i​v​a​n​-​g​r​a​h​a​m​.​b​i​z DoH Query returned NXDomain
_​d​m​a​r​c​.​b​a​k​e​r​-​d​a​v​i​s​.​c​o​m traditional Query returned 2 txt records v​=​D​M​A​R​C​1​;​p​=​r​e​j​e​c​t​;​p​c​t​=​1​0​0​;​ ​r​u​a​=​m​a​i​l​t​o​:​D​M​A​R​C​@​h​q​.​d​h​s​.​g​o​v​,​ ​m​a​i​l​t​o​:​r​e​p​o​r​t​s​@​d​m​a​r​c​.​c​y​b​e​r​.​d​h​s​.​g​o​v
v​=​D​M​A​R​C​1​;​p​=​r​e​j​e​c​t​;​p​c​t​=​1​0​0​;​ ​r​u​a​=​m​a​i​l​t​o​:​D​M​A​R​C​@​h​q​.​d​h​s​.​g​o​v