Skip to main content

Why is the Google PhishArm Plugin Not Working in Gmail?

K
Written by Karthek S
Updated yesterday

Issue

Users may sometimes be unable to report phishing simulation emails using the PhishArm Gmail plugin. This typically happens when Gmail flags the simulation email as suspicious, which prevents the plugin from accessing the email content and completing the report.

Screenshot of the issue:

Why Does This Happen?

Gmail has built-in security controls that restrict third-party add-ons when an email is considered unsafe.

If Gmail determines that:

The sender is not properly authenticated, and the email content appears malicious or suspicious

Gmail may block third-party add-ons, including the PhishArm plugin, from accessing the message.

This situation commonly occurs when a third-party email security gateway (such as Proofpoint, Mimecast, or another filtering solution) is involved. These systems may modify the email headers or message structure while routing the email, causing Gmail to classify the email as suspicious.

How Can I Resolve This Issue?

To ensure phishing simulation emails can be reported using the PhishArm plugin, you should configure Google Workspace to bypass spam filtering for simulation emails sent from the Right-Hand infrastructure.

Step 1: Log in to Google Admin Console

  • Navigate to the Google Admin Console.

  • Sign in with an administrator account.

Step 2: Navigate to Gmail Compliance Settings

  • Go to Apps

  • Select Google Workspace

  • Click Gmail

  • Open Compliance

Step 3: Create a Content Compliance Rule.

  • Ensure the rule applies to inbound messages.

  • Under Content Compliance, click Add Another Rule.

  • From the Location drop-down, select Full Headers

  • From the Match Type drop-down, select Contains Text

  • Under the content, add the below Right-Hand IPs and custom header

You can ask for the custom header, which is associated to your company tenant in cyberready from your customer success manager. Alternatively you can mail to [email protected] to get the same. The header has the following format:
X-RHS-TID-<unique hash>

1) 52.74.95.172

2) 168.245.54.27

3) 149.72.49.118

Screenshot 2024-09-25 101005.png


​Step 4: Save the Rule


After saving the rule, Gmail will bypass spam checks for emails sent from the specified IP address. This prevents simulation emails from being flagged as suspicious and allows the PhishArm plugin to access and report the email correctly.

Additional Recommendation:
If your organization uses third-party email security tools, ensure that phishing simulation emails from Right-Hand are also allow-listed or bypassed in those systems to prevent header or content modifications that could cause Gmail to flag the messages as suspicious.

References:

Did this answer your question?