Organizations using Google Workspace alongside KnowBe4’s phishing simulation tests and Defend must complete additional configuration steps to ensure proper email delivery and accurate testing results. This article outlines the recommended best practices for configuring Defend while using phishing simulation tests.
For instructions on adding Defend's sending IP addresses:
- For a list of Defend's sending IP addresses, see the Defend- KnowBe4 Simulation Emails article.
- For instructions on adding these IP addresses in Google Workspace, see the Whitelist by IP Address in Google Workspace article.
Tags and Threat Notifications
By default, phishing simulation tests will be marked with tags, or users will receive a threat notification about them. This default behavior simulates a real-world scenario for how Defend would react to a legitimate phishing email.
If you want to see if users still select phishing emails without tags, you can remove them from any phishing simulation tests by adding KnowBe4's sending IP addresses to Defend's allowlist. This process will also prevent users from receiving threat notifications for phishing simulation tests.
For a full description of Defend's tags, see the
For full details, see the Whitelisting Guide and Defend - Allow or Deny Lists article.
Phishing Simulation Tests
As an alternative to removing tags and threat notifications from phishing simulation tests entirely, you can use the Phishing Simulation Tests setting on the Settings > Threat Notification page to control which tags and actions are applied instead. For a description of each option, see the Defend | Google Workspace Settings article.
Setting this to Suspicious or Dangerous will still trigger the other actions configured for that level, such as the corresponding Threat Tag setting (for example, Add Threat Tag and Skip Inbox or Add Threat Tag and Spam Label). This setting doesn't affect detection.