Issue
Users could not report phishing simulation emails using the PhishArm plugin in Gmail. Gmail flagged these emails as suspicious, which prevented the plugin from functioning correctly.
Screenshot of the issue:
Potential Cause
When Google is able to determine that a message sender is not authenticated and the content is malicious, then Google will not allow any third party Add-on, including PhishArm, to access information in the email.
A third-party security tool is routing emails; it could be altering the message structure or headers in a way that Gmail does not recognize, contributing to the emails being flagged as suspicious.
Step-by-Step Solution
Create Bypass Rules for Google Spam Filters
If the email continues to be flagged as suspicious, create a rule in Google Workspace Admin to bypass Gmail’s spam filters for these simulation emails.
Log into Google Admin Console:
Go to Admin Console.
Navigate to Gmail Settings:
From the homepage, click on Apps > Google Workspace > Gmail > Compliance.
Create a new filter rule:
Click on Add Another Rule under the Content Compliance section.
Create a rule below to bypass the spam filter for emails from the RH IP.
4. Save the rule:
Once saved, Gmail will bypass spam checks for emails coming from this IP, preventing them from being flagged as suspicious.
References:

