Follow the steps to setup the external email for scan:
Log in to the Google Admin Console: https://admin.google.com/ as an admin user with permissions to configure apps, specifically Gmail.
Tag the non-internal emails so that they can be scanned by Email Security - Cloud.
Select Apps from the menu on the left. If you cannot see the option, recheck the permissions granted to you.
Select Google Workspace. If you cannot see the option, recheck the permissions granted to you.
In the main panel, scroll down to find and select Compliance. This will show the full set of compliance sections in the main panel.
In the Content Compliance section, click Configure. A pop-up form will appear.
Enter a name for the rule (example: Add External Header). Select the Inbound checkbox.
From the 'Add expressions that describe the content you want to search for in each message' drop-down menu, select If ALL of the following match the message.
Click the Add button. The Add Setting pop-up window will appear.
Set the match type to Metadata match. For attribute, select Source IP.
For Match type, select Source IP is not within the following range. Add similar rules for the following ranges of the respective region.
USA 34.223.36.0/24 3.93.93.0/24 EMEA 3.123.5.0/24 63.34.218.0/24 APJ 3.112.99.0/24 3.112.100.0/24 USGOV 15.200.32.0/24 APPROX 3.97.207.0/24 3.97.208.0/24
Scroll down and select If the above expressions match, do the following.
Select Add custom headers. Click the blue Add button that appears.
Enter X-ETP-Source as the header key. Enter External as the header value.
Click Save to add the header. Click Save to add the content compliance setting.
To allowlist the IP addresses, return to the Settings for Gmail page.
In Advanced Settings > Email allow list, enter the IP addresses for your region (listed above). Separate IP addresses with a comma. Click Save.