Sophos EMS: Set up Google Workspace journaling
Journaling for Sophos Email Monitoring System (EMS) is set up manually in Google Workspace. First, copy the journal destination address provided by Sophos Fusion, then create routing rules in the Google Admin Console for inbound and outbound email. If the environment already uses another email security solution, you must also configure an Inbound gateway.
Quick path: Copy the journal destination address in Sophos Fusion, select the appropriate organizational unit under Apps > Google Workspace > Gmail > Routing, configure the message types and headers, save the additional delivery to the destination address with TLS, and then return to Sophos Fusion to continue onboarding. Google states that changes can take up to 24 hours to take effect.
Purpose and scope of this guide
Journaling sends a copy of every email captured by the rule to Sophos EMS. Google attaches the copied message to a journal report and forwards it to the specified destination. The production message and the journal copy therefore follow two separate paths.
This guide covers only the Google Workspace side of this manual process: obtaining the journal destination address, creating routing rules, and configuring the Inbound Gateway when a third-party solution is upstream. Creating the EMS domain beforehand and analyzing the data in Sophos Fusion afterward are separate steps.
Prerequisites and decisions before making the change
Before you begin, you need:
- a Google Workspace administrator account;
- a domain created in Sophos Fusion so that the Configure External Dependencies dialog is open;
- the journal destination address displayed there in Step 1;
- the organizational unit to which the routing rule will apply;
- a decision on whether to capture both directions for all domains or only specific domains;
- if a third-party email security solution is upstream, its inbound delivery IP addresses for Google Workspace.
The Sophos instructions do not specify an additional Google role or a separate license check for this part of the process. If the dialog containing the destination address is unavailable, do not continue the routing configuration with a guessed address. The responsible Sophos Fusion administrator must first progress domain onboarding to Configure External Dependencies.
Sophos describes the following three options:
- Inbound and Outbound for all domains: one shared rule without a domain filter.
- Inbound for specific domains: an inbound rule that filters envelope recipients.
- Outbound for specific domains: an outbound rule that filters envelope senders.
To capture both directions for specific domains, you therefore need both an inbound rule and an outbound rule. Replace the example value example.com with the domain that the rule must actually cover.
Obtain the journal destination address from Sophos Fusion
After the domain is added, Sophos Fusion opens the Configure External Dependencies dialog.
- In Step 1, copy the provided email address.
- Keep the address secure and available for the following Google configuration. It is the journal destination address and is entered in Google as the Envelope recipient.
- Complete Step 2 only if a third-party email security solution is present. In that case, you will also configure the Inbound Gateway later.
Use the destination address exactly as provided by Sophos Fusion. An address you construct yourself or copy from another EMS domain is not an acceptable substitute.
Create the routing rule in Google Workspace
The common starting point for all options is Google Admin Console > Apps > Google Workspace > Gmail > Routing.
- Sign in to the Google Admin Console and open Routing.
- Select the organizational unit to which the journal rule will apply.
- Scroll to the Routing section.
- If no rule exists yet, select Configure. Otherwise, select Add Another Rule.
- Enter a unique description, such as
Journal rule for Sophos (external). - Under Email messages to affect, select the direction that matches the chosen option:
- Inbound and Outbound for both directions and all domains;
- Inbound for the inbound rule limited by recipient domain;
- Outbound for the outbound rule limited by sender domain.
- Under For the above types of messages, do the following, verify that Modify message is selected.
- Under Headers, select Add X-Gm-Original-To header.
- Under Also deliver to, select Add more recipients, then Add, and then Advanced.
- Under Envelope recipient, select Change envelope recipient and enter the destination address previously copied from Sophos Fusion.
- Under Spam and delivery options, clear Do not deliver spam to this recipient and leave Suppress bounces from the recipient enabled.
- Under Headers, enable both Add X-Gm-Original-To header and Add X-Gm-Spam and X-Gm-Phishy headers.
- Save this recipient configuration with Save. This returns you to the parent Add setting dialog.
- In that dialog, under Encryption (onward delivery only), enable Require secure transport (TLS).
- Open Show options and select the account types Users and Groups.
At this point, only the domain filter differs between the options.
Both directions for all domains
For the Inbound and Outbound option, do not add an envelope filter. Save the rule with Save.
This broad option is suitable when you want to capture the entire selected organizational unit. Its scope is determined by the organizational unit and selected account types, not by a Regexp domain filter.
Inbound for specific domains
For this rule, you can use the direction-specific example description EMS scan inbound.
Under Envelope filter, set the following values:
- Select Only affect specific envelope recipients.
- Select Pattern match.
- In the Regexp field, enter the required domain, for example
example.com. - Save the rule with Save.
This filter applies to envelope recipients. The Sophos example covers one domain. To capture multiple domains, construct the regular expression according to the requirements of your own Google Workspace environment.
Outbound for specific domains
For outbound email, create a separate rule and set Email messages to affect to Outbound. You can use EMS scan outbound as the direction-specific example description. Under Envelope filter, set:
- Only affect specific envelope senders;
- Pattern match;
- the required domain in the Regexp field, for example
example.com; - and finally Save.
The difference from the inbound rule is security-relevant: outbound rules filter envelope senders, whereas inbound rules filter envelope recipients. If both directions are required, both rules must be fully configured.
Configure the optional Inbound Gateway
This step applies only if a third-party email security solution already delivers email to Google. Skip it if no such solution is present.
- In the Google Admin Console, open Apps > Google Workspace > Gmail > Spam, Phishing and Malware.
- Select the affected organizational unit.
- Under Inbound gateway, select the edit icon.
- Enable Inbound gateway.
- Enter the inbound delivery IP addresses through which the email reaches Google.
- Save with Save.
The IP addresses must belong to the third-party solution’s actual delivery path. Sophos provides neither example addresses nor a method for determining them. If the addresses are unclear, stop the change and involve the operator of the upstream solution.
Validation and expected result
After saving, first compare the configured Google values with the planned configuration:
- the correct organizational unit and direction under Email messages to affect;
- Modify message and the headers X-Gm-Original-To, X-Gm-Spam, and X-Gm-Phishy;
- the exact Envelope recipient copied from Sophos Fusion;
- Suppress bounces from the recipient enabled and Do not deliver spam to this recipient cleared in this additional-recipient configuration;
- Require secure transport (TLS) and the account types Users and Groups;
- for limited rules, the appropriate recipient or sender filter with the correct domain in the Regexp field;
- when using a third-party solution, an active Inbound gateway with the correct delivery IP addresses.
Then return to Sophos Fusion and continue domain onboarding. For a limited functional test, send messages in each configured direction using users in the covered organizational unit or domain. The expected result is that the routing rule additionally forwards these messages to the journal destination address. Do not confuse production delivery with the additional journal delivery.
Google changes can take up to 24 hours to take effect. The Google Workspace Admin audit log shows whether and when the administrative change was recorded, but the entry does not prove that the routing rule is already effective everywhere. If no messages arrive in EMS, repeat the limited mail-flow test after this window has elapsed.
Troubleshooting by symptom
No journal messages appear after saving
First, check the Google Workspace Admin audit log to see whether and when the administrative change was recorded. This entry does not indicate whether the rule is already effective everywhere. During Google’s stated window of up to 24 hours, do not repeatedly create new rules. Afterward, test mail flow again and compare the organizational unit, direction, Users, Groups, and any Regexp filter with the test account.
Only one message direction is captured
Under Email messages to affect, check whether Inbound and Outbound is selected. A domain-limited configuration requires two rules: inbound with Only affect specific envelope recipients, and outbound with Only affect specific envelope senders. Using the wrong envelope filter can exclude the required direction from the scope.
A specific domain or group is missing
Check the selected organizational unit, Users, Groups, and the domain value in the Regexp field. example.com is only a placeholder. Also verify that the rule filters recipients for inbound email and senders for outbound email.
Journaling stopped working after an upstream security solution was introduced
If a third-party email security solution is in the delivery path, check under Apps > Google Workspace > Gmail > Spam, Phishing and Malware > Inbound gateway that the gateway is active and that the configured IP addresses match the actual inbound delivery path. Do not guess unclear or changing provider IP addresses; confirm them with the solution’s operator.
The rule is complete, but EMS still does not confirm mail flow
After Google’s change window has elapsed, test each configured direction again. Only when both directions are configured do you need one captured inbound message and one captured outbound message. If the routing rule’s scope, destination address, TLS, and, where applicable, the Inbound Gateway are correct, you have exhausted the Google Workspace checks described here. Document the timestamps, sender, recipient, organizational unit, rule name, and the time when the change was recorded in the Google Workspace Admin audit log, then provide them to the team responsible for EMS onboarding in your organization. If that team confirms the Google configuration and EMS still does not detect mail flow, it should open a case with Sophos Support using these details.
Safe rollback and offboarding
Sophos describes how to create the Google routing rules, but not how to disable or delete them. This guide therefore does not provide a click path for doing so.
Before rollback, document the journal destination address, organizational unit, rule names, directions, domain filters, headers, TLS setting, and any Inbound Gateway. Then use only the Google Workspace change or deletion process approved by your organization. For a shared rule or shared Inbound Gateway, stop the process until all dependencies have been clarified.
After the approved rollback, use the same limited test cases to verify that no additional journal copies are sent to the EMS destination address and that normal mail flow continues to work. Do not remove an Inbound Gateway solely because EMS is being decommissioned: it may still be part of the third-party security solution’s delivery path.
Operations and lifecycle
During regular reviews, compare the Google configuration with the documented EMS scope. Changes to organizational units, domains, the upstream email security service, its delivery IP addresses, and the journal destination address provided by Sophos Fusion are especially relevant. After any such change, retest every configured direction. Also check the Google Workspace Admin audit log to determine whether and when the administrative change was recorded.
If the source of the mailboxes or groups managed in Sophos Fusion changes, Prepare Sophos Fusion Directory Sync for Sophos Email can help with a separate review of the directory inventory. Directory Sync does not replace either the routing rules or the Inbound Gateway.
Google provides background information about journaling in Route journal messages to Google Vault. For this EMS setup, the Sophos fields described above and the destination address provided by Sophos Fusion remain authoritative. After changes to either service, recheck the UI labels, scope, and mail flow.