Overview
Gmail scans all messages for malware by default, but additional attachment protection settings add extra safeguards against encrypted files, malicious scripts, and uncommon file types that can slip through standard scanning. These settings apply to senders with no prior Gmail history or a low sender reputation.
Prerequisites
Super Admin access to the Google Admin console
Gmail Settings administrator privilege
Instructions
Sign in to the Google Admin console
Navigate to Apps > Google Workspace > Settings for Gmail > Safety
Scroll to the Attachments section and configure the following settings:
Protect against encrypted attachments from untrusted senders β Enable this setting. Encrypted attachments can't be scanned for malware and are a common attack vector.
Protect against attachments with scripts from untrusted senders β Enable this setting and set the action to Quarantine. This protects against documents containing malicious scripts that can harm devices.
Protect against anomalous attachment types in emails β Enable this setting. This protects against uncommon or archaic file types frequently used to spread malware. If your organization regularly receives specific uncommon file types from trusted sources, add those extensions to the allowlist.
Once all settings are configured, click Save.
