The Settings menu allows access to the Defend console's main configuration options. When making changes, always select Save Changes at the top-right corner of the screen.
To update, review, and make changes to your settings, follow the steps below:
- Log in to the Defend console.
- Navigate to Settings.
- Configure your settings accordingly.
- When you have finished making changes, select Save Changes in the top-right corner of the page.
Configurable Settings
The configurable settings are:
-
Threat Notification:
The Threat Notification feature enables admins to convert security incidents into educational opportunities by removing dangerous emails from users' inboxes and replacing them with a clear explanation of why the email was removed. Visual email tags also categorize incoming emails with colorful indicators.
-
Dangerous Emails, Threat Notification Email:
Enable or disable sending the user an email notification when a dangerous email is detected.
- When enabled, the notification explains why the email was flagged as dangerous.
- The email is removed from the inbox only if the Dangerous Threat Tag is set to Add Threat Tag and Skip Inbox, or to Add Threat Tag and Spam Label. Otherwise, the email stays in the inbox, and the notification arrives alongside it.
-
Suspicious Emails, Threat Notification Email:
Enable or disable sending the user an email notification when a suspicious email is detected.
- When enabled, the notification explains why the email was flagged as suspicious.
- The email is removed from the inbox only if the Suspicious Threat Tag is set to Add Threat Tag and Skip Inbox, or to Add Threat Tag and Spam Label. Otherwise, the email stays in the inbox, and the notification arrives alongside it.
-
Dangerous Threat Tag:
Choose the action taken when a dangerous email is detected:
- Disabled: No tag is applied.
- Add Threat Tag: Applies the visual tag only, and the email stays in the inbox.
- Add Threat Tag and Skip Inbox: Applies the Dangerous label and moves the email from the inbox to a separate category.
- Add Threat Tag and Spam Label: Applies the Dangerous label and labels the email as spam.
-
Suspicious Threat Tag:
Choose the action taken when a suspicious email is detected:
- Disabled: No tag is applied.
- Add Threat Tag: Applies the visual tag only, and the email stays in the inbox.
- Add Threat Tag and Skip Inbox: Applies the tag and archives the email from the inbox to a separate category.
- Add Threat Tag and Spam Label: Applies the tag and labels the email as spam.
-
Category Tags:
Each category tag gives users instant visual identification of a specific type of email by displaying a colored tag in their inbox:
- First Time Sender Tag: Flags emails from a sender that the user hasn't received mail from before, helping surface potentially harmful messages.
- Financial Tag: Flags emails identified as containing financial topics, such as bank details.
- Sensitive Tag: Flags emails identified as containing sensitive-action topics, such as resetting a password.
- Impersonation Tag: Flags emails identified as impersonating another user or organization.
- Threat Notification Tag: Flags threat notification emails from Defend that contain details about a phishing attack the user was protected from.
For each tag, choose when it's applied to a matching email:
- Always Send: Applies the tag to every matching email.
- Disabled: No tag is applied.
- Send Only if Suspicious: Applies the tag only when the email is also flagged as suspicious.
-
Phishing Simulation Tests:
Choose how Defend classifies phishing simulation emails:
- Disabled (default): Defend classifies the email as it normally would.
- Benign: Applies External-level banners and actions to the email.
- Suspicious: Applies Suspicious-level banners and actions to the email.
- Dangerous: Applies Dangerous-level banners and actions to the email.
This setting defaults to Disabled, and any changes you make are recorded in the admin audit log.
-
Email Productivity:
Helps reduce inbox clutter by identifying graymail and spam. When enabled, these emails are labeled and moved from the inbox into the matching category.
- Configure the Graymail Tag and Spam Tag independently.
-
Domain-Wide Delegation:
Shows whether domain-wide delegation (DWD) is verified for your Google Workspace admin console. Defend requires DWD to be configured to function, and this status check runs automatically when you load the Settings page. No action is required to trigger it.
If DWD isn't yet verified, select Read the setup guide for step-by-step instructions, including:
- A link to open the Google Workspace admin console's Domain-Wide Delegation page.
- The Client ID to add as a new API client, with a Copy button.
- The required OAuth Scopes to grant, with a Copy button.
- A reminder to save your changes in the Google Workspace admin console, then select Re-check to verify.
-
EasyDMARC Integration:
- Monitor your Google Workspace domains to protect against email spoofing and improve email deliverability.
- Select View DMARC Configuration (or Set up DMARC monitoring) to get started.
-
Allow Filtering By All In Recent Emails:
- This setting determines which admins can view all emails processed on the Recent Emails page.
- The All threat filter can be enabled or disabled for all admins, or enabled only for Global Admins and admin policies.
-
Allow View, Download, or Delete of an External Email:
- Enable or disable actions (Email operations) that admins can take on external emails.
-
Allow KnowBe4 Intelligence to View Emails:
- Controls whether the KnowBe4 Intelligence team can view email content.
- When enabled, KnowBe4 Intelligence can access phish and suspected missed phish in the Recent Emails Operations tab to investigate and identify phishing emails and ensure service delivery.
- When disabled, this access is blocked.
-
Secure Email Gateway (SEG):
- Tell Defend about your current email gateway setup so it can integrate with your email system.
-
Company Impersonation Attacks:
- Add your organization's secondary domains and protected names so Defend can help safeguard your organization's identity against impersonation.
-
Linguistic Analysis:
- Defend uses natural language processing (NLP) to analyze the emotion and intent behind emails and detect suspicious behavior. Add any custom subject phrases here to help avoid false positives.
-
Default Language:
- Select which language Defend uses for the tags added to your users' emails.
- The languages available are Chinese (Mandarin) Simplified, Dutch, English, French, French Canadian, German, Hungarian, Italian, Japanese, Norwegian, Portuguese, Portuguese (Brazil), Spanish, and Spanish (Latin America).
Recommended Default Settings
The recommended default settings are displayed below:
Threat Notification
| Option | Default Setting |
|---|---|
| Dangerous Threat Notification (Email) | Enabled |
| Dangerous Threat Tag | Add Threat Tag and Skip Inbox |
| Suspicious Threat Notification (Email) | Enabled |
| Suspicious Threat Tag | Add Threat Tag and Spam Label |
| First Time Sender Tag | Always Send |
| Financial Tag | Always Send |
| Sensitive Tag | Always Send |
| Impersonation Tag | Add Threat Tag |
| Threat Notification Tag | Always Send |
Email Productivity
| Option | Default Setting |
|---|---|
| Graymail Tag | Disabled |
| Spam Tag | Disabled |

