resources:courses:gws_c4
差别
这里会显示出您选择的修订版和当前版本之间的差别。
两侧同时换到之前的修订记录前一修订版后一修订版 | 前一修订版 | ||
resources:courses:gws_c4 [2025/01/23 18:18] – jackiez | resources:courses:gws_c4 [2025/01/25 10:27] (当前版本) – jackiez | ||
---|---|---|---|
行 6: | 行 6: | ||
还有NS记录,A记录等。 | 还有NS记录,A记录等。 | ||
{{: | {{: | ||
+ | ## 练习2 | ||
+ | 参考链接[[https:// | ||
+ | < | ||
+ | 2.TTL默认是3600,但正常使用Gmail后可以改为86400,这样更新频率会改为每天1次 | ||
+ | 3.如果是要把现行的邮箱系统转移到GWS上,可以保留现在的MX记录,但调低优先级(比如将优先级改为10+),当所有邮箱都经由Google后,再删除原MX记录,这样保证不会有邮件丢失</ | ||
+ | ## 练习3 | ||
+ | 检查MX | ||
+ | 工具URL为[[https:// | ||
+ | {{: | ||
+ | 点击报警会给出解决方法 | ||
+ | ## 测试1 | ||
+ | < | ||
+ | - Change your MX records in the admin console and reduce the Time to Live (TTL) value to one hour. Once the change has been implemented revert the TTL value to 24 hours | ||
+ | - **Make the change in your DNS console and reduce the Time to Live (TTL) value to 1 hour. Once the change has been implemented revert the TTL value to 24 hours** | ||
+ | - Change your MX records in the admin console and reduce the Time to Live (TTL) value to one hour | ||
+ | - Make the change in your DNS console and reduce the Time to Live (TTL) value to 1 hour | ||
+ | |||
+ | < | ||
+ | - **MX Record** | ||
+ | - TXT Record | ||
+ | - NS Record | ||
+ | - CNAME Record | ||
+ | |||
+ | <q>In general, from where would you manage your domain' | ||
+ | - All of the options here | ||
+ | - In your local DNS files | ||
+ | - **In your domain registrar console** | ||
+ | - In the Google Workspace admin console | ||
+ | |||
+ | < | ||
+ | - Customise a Google service address | ||
+ | - Control inbound mail to your domain | ||
+ | - **Domain verification** | ||
+ | - **Email security records** | ||
+ | |||
+ | ## 邮件安全 | ||
+ | 3招,SPF,DKIM和DMARC | ||
+ | SPF: verify the domain you own | ||
+ | DKIM: prevent email spoofing on outbound message by adding an encrypted header | ||
+ | DMARC: tell email servers how to handle messages that fail SPF/DKIM checks | ||
+ | |||
+ | ## 练习1 | ||
+ | SPF,通过添加TXT记录到DNS中 | ||
+ | Xserver中已经有一条记录了,现在在后面追加< | ||
+ | 记录生效需要24小时左右 | ||
+ | 参考链接:[[https:// | ||
+ | ## 练习2 | ||
+ | {{: | ||
+ | {{: | ||
+ | 生成后长这个样子 | ||
+ | {{: | ||
+ | 生成的记录在Xserver的DNS DKIM记录中已经有了,一模一样。 | ||
+ | 参考链接: | ||
+ | [[https:// | ||
+ | ## 练习3 | ||
+ | {{: | ||
+ | 这条TXT记录告诉收件邮箱服务器,如果判定Fail,如何操作,这里是通知管理员。 | ||
+ | ## 测试2 | ||
+ | < | ||
+ | - **It specifies which servers/ | ||
+ | - It can be used to verify that message content is authentic and has not changed | ||
+ | - It defines the action to take on suspicious incoming messages | ||
+ | |||
+ | < | ||
+ | - Enable DKIM from Apps > Google Workspace > Gmail > Authenticate email | ||
+ | - Enable DKIM directly in your DNS records | ||
+ | - Generate a key from your DNS records and add it to the Google Workspace admin console. Then Enable DKIM from Apps > Google Workspace > Gmail > Authenticate email | ||
+ | - **Generate a DKIM record from Apps > Google Workspace > Gmail > Authenticate email. Add the record to your DNS records and then start authentication from the admin console** | ||
+ | |||
+ | |||
+ | < | ||
+ | - SPF | ||
+ | - DKIM | ||
+ | - All of the options here | ||
+ | - **DMARC** | ||
+ | |||
+ | < | ||
+ | - Gmail signs all outgoing messages with a temporary key generated for your domain | ||
+ | - **Gmail signs all outgoing messages with this default DKIM domain key d=\*.gappssmtp.com** | ||
+ | - Gmail signs all outgoing messages with a key generated using the From address in the message | ||
+ | - Messages are sent as normal with no additional headers | ||
+ | |||
+ | ## 邮件安全配置 | ||
+ | 对于未受信任的发件人的加密附件,处理方式是隔离。 | ||
+ | {{: | ||
+ | < | ||
+ | ## 练习2 | ||
+ | 对于外包人员,禁止他们的自动转发邮件到个人邮箱,并且禁止POP和IMAP,但那些开户GWS Sync的人例外。 | ||
+ | {{: | ||
+ | 现在Rules也会终止工作 | ||
+ | ## 测试3 | ||
+ | < | ||
+ | - Keep email in inbox without warning | ||
+ | - **Move email to spam** | ||
+ | - Send to a designated user | ||
+ | - **Keep email in inbox and show warning** | ||
+ | |||
+ | < | ||
+ | - Ask each user to create an allowlist of allowable file types | ||
+ | - **Add an allowlist of allowable file types to the entry in the Attachments section on the Safety page** | ||
+ | - Have all messages that trigger this setting delivered to a quarantine and then release the messages manually | ||
+ | - You cannot control what file types are considered anomalous so you must disable this protection to allow messages to be delivered | ||
+ | |||
+ | < | ||
+ | - **An outbound gateway ensures that the same mail server delivers all messages from otherdomain and that server has a record that the mail has been sent** | ||
+ | - Mail delivery times are improved because messages bypass the Gmail servers | ||
+ | - **An outbound gateway can prevent the appearance of "on behalf of" addresses in the From field** | ||
+ | - Allows your users to send mail from their business and personal Gmail account from one inbox | ||
+ | |||
+ | < | ||
+ | - **True** | ||
+ | - False | ||
+ | |||
+ | ## 练习1 | ||
+ | 添加一个信任IP地址,虽然是信任,但如果从它发出来可疑邮件,仍然会被放入垃圾邮箱 | ||
+ | {{: | ||
+ | 从自己的邮箱发一封邮件给GWS管理员邮箱。 | ||
+ | 在Console中添加黑名单 | ||
+ | {{: | ||
+ | {{: | ||
+ | 参考链接:[[https:// | ||
+ | ## 练习2 | ||
+ | 创建白名单 | ||
+ | Gmail> | ||
+ | {{: | ||
+ | {{: | ||
+ | < | ||
+ | < | ||
+ | 参考链接:[[https:// | ||
+ | |||
+ | ## 测试4 | ||
+ | < | ||
+ | - Can be used for batch delivery of email to Gmail | ||
+ | - Improves mail delivery performance | ||
+ | - **Spam filtering** | ||
+ | - **Message archiving** | ||
+ | |||
+ | < | ||
+ | - Configure a blocked senders list and add the domain' | ||
+ | - Ask each of your user's to block the domain | ||
+ | - **Configure a blocked senders list and add the domain name to the list** | ||
+ | - Contact Google Support and ask them to block the organization for you | ||
+ | |||
+ | < | ||
+ | - Setup a security sandbox rule for the user to have all mail verified by the sandbox prior to delivery | ||
+ | - **Add a spam setting which bypasses spam filters for messages received from addresses within an approved senders list. Add the user's email address to the list** | ||
+ | - Ask each of your users to add the contact to their personal contacts | ||
+ | - Add the user's email address to your email allowlist | ||
+ | |||
+ | ## 邮件合规检查 | ||
+ | - Attachment compliance | ||
+ | - Content compliance | ||
+ | - objectionable content compliance | ||
+ | 触发后的动作 | ||
+ | - rejected before reaches the recipient | ||
+ | - be sent to admin | ||
+ | - be modified before delivery | ||
+ | DLP对策 | ||
+ | ## 练习1 | ||
+ | {{: | ||
+ | ## 练习2 | ||
+ | {{: | ||
+ | 然后发一封包含Jupiter(在标题或是正文)的邮件到自己个人邮箱,发现是收不到的。 | ||
+ | ## 练习3 | ||
+ | {{: | ||
+ | 发送违规邮件,然后查看隔离邮件(使用管理员账号) | ||
+ | {{: | ||
+ | 也可以访问下列URL [[https:// | ||
+ | < | ||
+ | ## 其他合规对策 | ||
+ | - email and chat auto-deletion 删除超过某一时间的信息 | ||
+ | - OCR for email attachment (并不是所有GWS版本都支持) | ||
+ | - restrict delivery (一般用于教育账号) | ||
+ | - Security sandbox (微软家的EDR也有这个功能) | ||
+ | |||
+ | ## 测试5 | ||
+ | < | ||
+ | - **Add baddomain.com to a blocked senders list** | ||
+ | - Add baddomain.com' | ||
+ | - 1Create a security sandbox rule to filter and delete messages to/from baddomain.com | ||
+ | - Configure the ' | ||
+ | |||
+ | < | ||
+ | - **Deny** | ||
+ | - **Allow** | ||
+ | - Return to sender | ||
+ | - Deliver to another recipient | ||
+ | |||
+ | <q>In which type of compliance control can you apply a Data Loss Prevention (DLP) rule for Gmail?</ | ||
+ | - Objectionable content | ||
+ | - **Content compliance** | ||
+ | - Optical Character Recognition (OCR) | ||
+ | - Attachment compliance | ||
+ | |||
+ | < | ||
+ | - **An objectionable content setting works on inbound and outbound messages** | ||
+ | - In an objectionable content setting you use a predefined list of objectionable words for filtering for objectionable content | ||
+ | - An objectionable content setting works on inbound messages only | ||
+ | - **In an objectionable content setting you create word lists for filtering for objectionable content** | ||
+ | |||
+ | ## Mail routing | ||
+ | 有3种方式,默认的Direct,还有Dual,以及Split Delivery | ||
+ | Dual用于小范围测试邮件,需要新旧2个邮箱都收到邮件。(或是邮件迁移时,比如收购公司接收的一批邮箱(非GWS)) | ||
+ | Spli用于进来的邮件分发到不同邮箱,它同Dual都是暂时操作而非长期。 | ||
+ | ## 练习1 | ||
+ | 设定Split Delivery | ||
+ | {{: | ||
+ | Port不能为空 | ||
+ | {{: | ||
+ | {{: | ||
+ | 这样所有未定额站以识别的用户发来的邮件都会被转到Legacy邮件服务器,适用于还未迁移到Gmail的人。 | ||
+ | 参考链接:[[https:// | ||
+ | |||
+ | ## 其他Routing选项 | ||
+ | - outbound mail gateway server 用于备份或是过滤邮件 | ||
+ | - virtual user table, | ||
+ | - Inbound e-mail journal acceptance to Vault 保存邮件到另一个邮件平台 | ||
+ | - 3rd party email archiving | ||
+ | |||
+ | |||
+ | ## 测试6 | ||
+ | < | ||
+ | - Indirect delivery | ||
+ | - Split delivery | ||
+ | - **Dual delivery** | ||
+ | - Direct delivery | ||
+ | |||
+ | < | ||
+ | - A routing setting can be applied at an OU level | ||
+ | - Address lists can be used to control or bypass a routing setting | ||
+ | - **All of the options here** | ||
+ | - A routing setting can be applied to specific senders and recipients | ||
+ | |||
+ | < | ||
+ | - An outbound gateway | ||
+ | - Alternate secure route | ||
+ | - **A mail host** | ||
+ | - An SMTP relay | ||
+ | |||
+ | < | ||
+ | - Alternate secure route | ||
+ | - **SMTP Relay service** | ||
+ | - **Non-Gmail mailbox** | ||
+ | - Outbound gateway | ||
+ | < | ||
+ | {{: | ||
+ | {{: | ||
+ | 这时会发现Gmail,Drive和Calendar等核心GWS服务已经不可用。所以直接删除账户吧。 | ||
+ | {{: | ||
+ | 会确认有没有MarketplaceAPP,如果有,要先删除APP才能删除账户。 | ||
resources/courses/gws_c4.1737623927.txt.gz · 最后更改: 2025/01/23 18:18 由 jackiez