Google Workspace user forwarding email out of non Google Workspace domain

Set up the gsuite integration.

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Goal

Create a signal when Google Workspace detects a user setting up mail forwarding to a non-Google Workspace domain.

Strategy

Monitor Google Workspace logs to detect when email_forwarding_out_of_domain events.

Triage and response

  1. Determine if the email address defined in @event.parameters.email_forwarding_destination_address is legitimate.
  2. If the forwarding destination address is not legitimate, review all activity for {{@usr.email}} and all activity around the following IP: {{@network.client.ip}}.