Google Workspace phishing protection — how to stop phishing in Gmail
Enable Gmail’s advanced anti-phishing features, enforce SPF/DKIM/DMARC at DNS level, and require 2-step verification for all accounts — these three measures deliver Google Workspace phishing protection that aligns with NCSC guidance and can be implemented within a single working day.
Treating phishing like a nuisance: relying on spam filters and training alone
Many small firms treat phishing as an annoyance: they rely on Gmail’s basic spam filter and run an annual awareness session. That approach assumes people will spot everything and that default filtering is sufficient, but it leaves clear gaps. Spam filters catch known patterns; targeted impersonation (spear-phishing) and credential-harvesting links frequently bypass simple rules. Training helps, but human error is inevitable—especially during busy periods such as payroll runs or month-end invoicing.
Common weaknesses in this pattern
- Default Gmail settings left unchanged — no advanced phishing or attachment scanning.
- DNS records (SPF/DKIM/DMARC) not set or misconfigured, so spoofed domains can still reach inboxes.
- Only annual training with no context-specific reminders or phishing simulations.
- No incident plan: when a user clicks a malicious link there’s no fast containment route.
Why that fails for UK firms: a single compromised account can authorise invoice changes, send payroll fraud or exfiltrate customer data — exposures that attract regulatory attention from the ICO. Remediation then costs time and may require reporting.
Concrete examples (what happens if you keep this approach)
- Example A — Supplier invoice fraud: an attacker spoofs a supplier email, the accountant approves a changed bank detail because the message looks legitimate; the business loses funds before the fraud is spotted.
- Example B — CEO impersonation: urgent-sounding request arrives during a busy day; without domain authentication signals (DMARC) the spoofed email lands in the inbox, a senior signs it off, and payment is sent to attackers.
Treating phishing like a breach risk: layered configuration, detection and response
The better pattern is layered controls across configuration, detection and user policies. Start with DNS authentication — SPF, DKIM and DMARC — so receiving servers can reject spoofed mail. Turn on Gmail’s advanced anti-phishing and attachment protections, enforce organisation-wide 2-step verification (2SV), and enable suspicious login alerts and context-aware access policies. Pair those controls with short, task-focused phishing drills and an incident playbook that describes immediate containment steps.
Key components of this approach
- DNS hardening: publish SPF, sign with DKIM and enforce a DMARC policy (p=quarantine or p=reject when comfortable).
- Gmail protections: enable advanced phishing and malware scanning, attachment sandboxing, and link protection.
- Authentication: require 2SV for every user and consider hardware security keys for privileged accounts.
- Detection & response: configure alerts for unusual outbound mail patterns and automated account suspension on confirmed compromise.
- People: run short, practical simulations and an incident checklist that anyone can follow.
Why that works for UK SMEs: layered controls reduce probability of compromise and shorten detection time, which lowers recovery cost and regulatory risk. If you want an implementation checklist and on-going support, see Google Workspace support for business for hands-on help.
Concrete examples (how this approach prevents damage)
- Example C — Supplier invoice fraud blocked: DMARC rejects the spoofed sender and Gmail’s link protection flags the unusual payment URL; the finance team is alerted and payment is stalled.
- Example D — Compromised login contained: 2SV prevents the attacker from signing in even with stolen credentials, automated alerts flag the failed attempts and IT suspends the account pending review.
Related reading
- our google workspace support for business guide
- Google Workspace support UK SMEs — practical help for growing businesses
- How to run a Google Workspace security investigation in 7 steps
- Google Workspace support London — practical help for growing UK firms
- Google Workspace business efficiency: practical steps for UK SMEs
FAQ
How do I start enforcing SPF/DKIM/DMARC for my Google Workspace domain?
Publish an SPF record that lists Google mail senders, enable DKIM signing from the Google Admin console and start DMARC in monitoring mode (p=none) to collect reports; move to p=quarantine or p=reject once you’ve fixed legitimate sender issues.
Will enabling 2-step verification stop phishing completely?
No single control is perfect, but requiring 2-step verification for all accounts cuts the risk of account takeover dramatically; most users can enable app-based or SMS 2SV in about 5 minutes each, or you can roll out hardware keys for higher-risk accounts.
Should I report a phishing attack to UK authorities?
Yes — report significant incidents and data-loss events to the ICO when personal data is breached; for general phishing guidance and reporting routes see the NCSC’s advice collection.
How quickly can my business be protected if we adopt the layered approach?
Core controls (SPF/DKIM/DMARC, basic Gmail protections and mandatory 2SV) can usually be configured within one working day for a small organisation, with ongoing tuning and monitoring over the following weeks.







