Email Security - Cloud with AV/AS integration is enabled by modifying the domain mail exchange (MX) record and allowlisting the Email Security - Cloud IP ranges in Gmail. After Email Security - Cloud and Gmail are integrated, all emails are sent to Email Security - Cloud for AV/AS and advanced threat scanning before being delivered to a domain. Messages identified by Email Security - Cloud as malicious are quarantined. Messages not deemed as threats are forwarded to Gmail for processing.
A Sending Routing Rule is required to redirect internal email traffic to Google instead of Email Security - Cloud. If you do not configure a Sending Routing Rule, internal mail will be routed through Email Security - Cloud.
To enable outbound email scanning, you need to configure your existing inbound domain with outbound policies. Refer to Outbound email scanning for the process.
To configure Inline with Hygiene mode:
What you need
Administrative access to your Gmail account.
Administrative access to your Email Security - Cloud instance.
Step 1: Create the Inbound gateway rule in Gmail
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-4 under "Set up an inbound gateway" in the Google documentation.
For step 5, enter the following configuration settings:
Add IP addresses:
Under Gateway IPs, click Add.
Depending on the geographic region of your Email Security - Cloud account, enter the following IP addresses:
Email Security - Cloud region
IP Addresses
US
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.208.0/24
Click Save.
Note
If your geographic region has multiple IP ranges, you must repeat steps ai-aiii for each individual IP range. For example, EMEA users must complete these steps two times while USGOV users must only complete these steps once.
Add the Google IP ranges to the Inbound gateway rule.
Follow "Find Google Workspace IP address ranges" in the Google documentation to find the IP address ranges.
Under Gateway IPs, click Add.
Enter the IPs addresses of the Google Workspace mail servers found in step bi.
Click Save.
Note
You must repeat steps bii-biv for each individual IP range.
Add the IPv4 and IPv6 addresses.
Under Gateway IPs, click Add.
Enter the following IPs:
IPv4
IPv6
108.177.16.0/24
2600:1901:101::0/126
108.177.17.0/24
2600:1901:101::4/126
142.250.220.0/24
2600:1901:101::8/126
142.250.221.0/24
2600:1901:101::c/126
2600:1901:101::10/126
2600:1901:101::14/126
Click Save.
Note
You must repeat steps ci-ciii for each individual IP range.
Verify that the Automatically detect external IP option is unchecked.
Verify that the Reject all mail not from gateway IPs option is unchecked.
Verify that the Require TLS for connections from the email gateways listed above option is unchecked.
Click Save.
Step 2: Create the Google host in Gmail
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-3 under "Add a mail route for your domain" in the Google documentation.
For step 4, enter the following configuration settings:
For Name, enter Google Internal.
Select Multiple hosts.
Under Primary, enter aspmx.l.google.com in the Enter host name or IP entry box.
For Port, enter 25.
Click Add Primary.
Repeat steps 3c-3e for the following:
alt1.aspmx.l.google.com
alt2.aspmx.l.google.com
alt3.aspmx.l.google.com
alt4.aspmx.l.google.com
Verify that the Require mail to be transmitted via a secure (TLS) connection option is checked.
Verify that the Require CA signed certificate option is checked.
Click Save.
Step 3: Create the routing rule in Gmail
Log in to the Google Admin Console: admin.google.com.
Follow steps 1-4 under "Add a routing setting" in the Google documentation.
For step 5, enter the following configuration settings:
For the required description, enter Internal Routing.
Under Email Messages to affect, select Internal - Sending.
Under For the above types of messages, do the following, ensure that Modify Messages is selected from the drop-down menu.
Under Route, select Change Route.
Select Suppress bounces from this recipient.
Click the drop-down menu and select Google Internal.
Scroll to the bottom of the page and click Show options.
Under Account types to affect, select Users and Groups.
Under Envelope filter, select Only affect specific envelope senders.
Click the drop-down menu and select Pattern match.
Under Regexp, enter ".*".
Click Save.
Step 4: Modify the domain MX records
Depending on the geographic region of your Email Security - Cloud account, add the following MX records according to priority. Details on modifying MX records are beyond the scope of this document. Contact your domain registrar for more information.
Email Security - Cloud region | MX records |
|---|---|
US | primary.us.email.fireeyecloud.com (Priority 10) alt1.us.email.fireeyecloud.com (Priority 20) alt2.us.email.fireeyecloud.com (Priority 30) alt3.us.email.fireeyecloud.com (Priority 40) |
EMEA | primary.emea.email.fireeyecloud.com (Priority 10) alt1.emea.email.fireeyecloud.com (Priority 20) alt2.emea.email.fireeyecloud.com (Priority 30) alt3.emea.email.fireeyecloud.com (Priority 40) |
APJ | primary.ap.email.fireeyecloud.com (Priority 10) alt1.ap.email.fireeyecloud.com (Priority 20) alt2.ap.email.fireeyecloud.com (Priority 30) alt3.ap.email.fireeyecloud.com (Priority 40) |
USGOV | primary.us.etp.fireeyegov.com (Priority 10) alt1.us.etp.fireeyegov.com (Priority 20) alt2.us.etp.fireeyegov.com (Priority 30) alt3.us.etp.fireeyegov.com (Priority 40) |
CA | primary.ca.email.fireeyecloud.com (Priority 10) alt1.ca.email.fireeyecloud.com (Priority 20) alt2.ca.email.fireeyecloud.com (Priority 30) alt3.ca.email.fireeyecloud.com (Priority 40) |