Google Workspace ships with strong native spam and known-malware filtering, but like any large, high-value email platform, it's a consistent target for attackers who specifically craft phishing attempts to slip past broad, reputation-based filters. DefenceNet integrates directly with Google Workspace to add a behavioral, intent-based layer on top of that native protection.
How the Integration Works
DefenceNet connects to Google Workspace via OAuth, using Google's administrative APIs to gain read access to mail flow without acting as a routing gateway. There are no MX record changes, and no disruption to how mail is currently delivered — authorization is granted by a Workspace admin, and DefenceNet begins analyzing traffic from that point on.
Because the integration is API-native rather than gateway-based, DefenceNet can evaluate internal (domain-to-domain) email alongside external traffic — visibility that a pure perimeter filter typically doesn't have without additional configuration.
What DefenceNet Adds on Top of Native Filtering
Google's native filtering is effective against high-volume, previously-seen spam and malware. DefenceNet's behavioral AI is aimed at the attacks specifically designed to get past that layer: business email compromise (BEC) with no malicious link or attachment at all, brand impersonation, and QR-code-based (quishing) credential harvesting embedded in an image.
Because DefenceNet doesn't replace Google's native protection, most Workspace customers run both together — Google handling bulk spam and known malware, DefenceNet focused on the targeted, zero-day, and social-engineering-driven attacks that require behavioral and visual analysis to catch.
Frequently Asked Questions
Do we need to change our MX records to use DefenceNet with Google Workspace?
No. DefenceNet connects via OAuth API rather than acting as a mail gateway, so there's no MX record change and no disruption to existing mail delivery.
Does DefenceNet replace Google Workspace's built-in spam and phishing filters?
No — DefenceNet is designed to run alongside Google's native filtering, not replace it. Google handles bulk spam and known malware; DefenceNet focuses on the targeted, behavioral, and visual (quishing) threats that need deeper analysis to catch.
How long does the Google Workspace integration take to set up?
Setup consists of a Workspace admin authorizing DefenceNet via OAuth. Because there's no routing change, most organizations complete initial authorization and start seeing analysis of live traffic the same day.
Can DefenceNet see internal (domain-to-domain) email in Google Workspace, not just external mail?
Yes. Because the integration is API-native rather than perimeter-based, DefenceNet has visibility into internal mail flow by default — useful for catching lateral phishing following an account compromise.