BusinessGoogle WorkspaceSecurity

Protect your business against phishing

Four practical steps to protect yourself and your business against phishing: 2-step verification, DKIM, reporting suspicious email and a security audit.

· Updated · 2 min read

Illustration of a masked attacker sitting at a computer with an email inbox open on the screen

Phishing works much like fishing: an attacker puts out bait (fake messages) to catch unsuspecting computer users. The attacker tries to trick people into sharing personal information, login credentials or anything else that could be used against them in future attacks.

Follow the steps below to protect yourself and your business against phishing.

1. Turn on 2-step verification

2-step verification (also known as two-factor authentication, or 2FA) adds an extra layer of security to your account. With 2FA turned on, you sign in to your account in two steps, with:

  • Something you know (your password).
  • Something you have (your phone or a security key).

Even if your password is compromised, your account is still protected by the second layer.

Get started with 2-step verification on your account.

2. Activate DKIM

DomainKeys Identified Mail (DKIM) is an email authentication method designed to prevent forged sender addresses, a technique often used in phishing and spam.

With DKIM enabled on your mail server, it becomes much harder for an attacker to forge your email address and fool your clients or team members into thinking they’re communicating with you. DKIM lets email servers verify that an email was sent by you and wasn’t tampered with. It does this with private and public encryption keys, in much the same way online credit card transactions are secured.

DKIM needs an update to your domain’s DNS and to your Google Workspace settings. If you’re a Google Workspace subscriber, we’ll take care of this for you.

3. Report suspicious email

When Google identifies a suspicious email, it shows a warning message and an option to move the email to your spam folder. You have full control over this process and can mark or unmark emails as phishing attempts.

4. Get a professional security audit on your domain

To optimise the security of your Google Workspace deployment, you first need to identify your organisation’s unique risks. We offer our clients a free high-level security audit to make sure best practices are followed and your Google Workspace deployment is safe from unnecessary, preventable security risks.

Ready to move to Google Workspace?

Get a migration assessment from the cozan team.