Blog/ Gmail how-tos

How to Block an Entire Domain in Google Workspace

Nafiul HasanNafiul Hasan· 10 min read
Google Workspace Admin Console showing the Spam, Phishing and Malware settings used to block an entire sending domain for every user in the organisation

The short answer

A Google Workspace admin blocks an entire sending domain in Admin Console > Apps > Google Workspace > Gmail > Spam, Phishing and Malware > Blocked senders. Add the domain, choose reject or quarantine, and save. The block applies to every user in the organisation after propagation.

How a Google Workspace admin blocks an entire sending domain org-wide: blocked senders list, reject vs quarantine, collateral damage, and how to undo it.

On this page
  1. 01The short answer
  2. 02Before you start
  3. 03How to block a domain in Google Workspace: step by step
  4. 04Block methods compared
  5. 05What to do when the block is not working
  6. 06A faster way to handle domain-level noise at the inbox level

Blocking a domain in Google Workspace stops every user in your organisation from receiving mail from that domain — not just one inbox, but the whole account. The setting lives in the Admin Console and takes about two minutes to configure. The decisions that take longer are whether to reject the mail outright or quarantine it, and whether a domain-wide block is actually the right fix for what you are seeing.

This guide covers the org-wide admin block — the one only a super admin or a delegated admin with Gmail settings permission can set. For blocking a single sender inside your own Gmail inbox, that is a separate per-user setting and does not require admin access.

The short answer#

In the Google Workspace Admin Console, go to Apps, then Google Workspace, then Gmail, then Spam, Phishing and Malware. Find the Blocked senders section, click Configure, and add the domain you want to block. Gmail will reject any inbound message from that domain for every user in the organisation.

With the Reject action, Gmail returns a 550 SMTP error to the sending server. The sender receives a delivery failure notice. Mail never reaches a user inbox, lands in spam, or disappears silently. If you prefer to hold messages for review first, choose Quarantine instead — the mail goes to an admin-controlled hold rather than bouncing.

Before you start#

Blocking a whole domain is a blunt instrument. Before you configure it, check three things.

First, is the domain specific enough? Blocking a major shared provider — hotmail.com, gmail.com, yahoo.com — cuts off all personal email from those providers, including customers, partners, and job applicants who happen to use personal accounts there. If the spam originates from one of those large domains, a content compliance rule that targets specific patterns is almost always the better fix.

Second, what outcome do you want when a message arrives from this domain? Reject sends a 550 bounce back to the sender and generates a delivery failure report. Quarantine holds the message in an admin-controlled review queue without a bounce. If there is any chance the domain has legitimate senders you are not aware of, quarantine first.

Third, does anyone in your organisation have an active business relationship with someone at that domain? Blanket domain blocks regularly generate support tickets when a vendor or client shares the offending sending domain. Verify with the relevant team before the block goes live.

Blocking a shared domain cuts off everyone on it

A block on outlook.com stops every Microsoft personal email user who might contact your organisation, not just the spammer. If the unwanted mail comes from a major shared provider, use a content compliance rule that matches on sender patterns or subject keywords rather than the whole domain.

How to block a domain in Google Workspace: step by step#

You need super admin access or a delegated admin role with Gmail settings permission. The steps below apply to the Admin Console as of mid-2026.

  1. 1

    Open the Admin Console

    Go to admin.google.com and sign in with your admin account. From the Home screen, navigate to Apps, then Google Workspace, then Gmail.

  2. 2

    Open Spam, Phishing and Malware

    In the Gmail settings list, find and click Spam, Phishing and Malware. This section contains the Blocked senders setting alongside other anti-abuse controls such as enhanced pre-delivery message scanning.

  3. 3

    Configure the Blocked senders list

    Scroll to the Blocked senders section and click Configure if no rule exists, or Add another rule if one is already in place. A dialog opens where you name the setting and enter the addresses or domains to block.

  4. 4

    Add the domain

    In the Add addresses or domains field, type the domain you want to block — for example, spamsite.example. Do not prefix it with @. You can add multiple domains to a single rule by entering them one at a time.

  5. 5

    Choose reject or quarantine

    Select the action: Reject sends a 550 SMTP error to the sender and triggers a delivery failure notification on their end. Quarantine routes the message to an admin quarantine for review. If the domain is genuinely unknown territory, quarantine first so you can audit the traffic before making the block permanent.

  6. 6

    Set the scope

    By default the rule applies to the entire organisation. If you use organisational units and only want to protect a subset of users, change the scope to the relevant OU. Users outside that scope are unaffected.

  7. 7

    Save and verify

    Click Save. Google Workspace begins propagating the rule across its infrastructure. Changes usually take effect within a few minutes, but the Admin Console may cite up to 24 hours for full propagation. Confirm with a test message from the blocked domain or check Email Log Search under Reporting to verify the rule is being applied.

Propagation can take up to 24 hours

The Admin Console notes that some settings can take up to 24 hours to propagate fully. In practice the Blocked senders list usually applies within minutes, but do not assume the block is live the instant you hit Save. Use Email Log Search to confirm the rule is triggering before reporting the issue closed.

Block methods compared#

Google Workspace offers more than one way to restrict inbound mail from a domain. The blocked senders list is the fastest path, but a routing rule or content compliance rule gives more control when the situation is more nuanced than a clean all-or-nothing block.

Diagram showing inbound email flow before and after an admin domain block: before, messages from a spam domain reach user inboxes; after the blocked senders rule is applied, messages are rejected at the organisation boundary and never delivered
The blocked senders rule stops mail at the organisation boundary rather than after it has landed in a user inbox.
MethodWhere to configureEffect on the mailBest for
Blocked senders listGmail > Spam, Phishing and MalwareRejects with 550 SMTP error, or routes to admin quarantineDomains you are confident you never want mail from under any circumstances
Content compliance ruleGmail > Compliance > Content complianceReject, quarantine, modify, or redirect based on content patterns and conditionsDomains where some mail is legitimate — block only messages matching specific patterns
Routing ruleGmail > Routing > Inbound gatewayRoutes mail through an external security product before deliveryOrganisations using a third-party email security gateway for filtering
Individual user blockGmail settings > Filters and Blocked AddressesMoves matching messages to spam for that one user onlyA single user blocking a sender without admin involvement

What to do when the block is not working#

The blocked senders list is reliable when correctly configured, but several things can make it appear that mail from the blocked domain is still getting through.

SymptomLikely causeFix
Mail from the domain still arrives after saving the rulePropagation is not complete — changes can take up to 24 hoursWait and test again. Use Email Log Search (Admin Console > Reporting > Email Log Search) to confirm whether the rule is being evaluated on inbound messages.
Mail still arrives after 24 hoursThe rule scope does not cover the affected users — it was saved at a narrower organisational unitEdit the blocked senders rule and expand the scope to the whole organisation, or to the OU that contains the affected users.
Mail arrives from a similar but different domainThe spammer is rotating across subdomains or domain variants (e.g., mail.spam.example and spam.example as separate domains)Add each variant to the blocked senders list, or switch to a content compliance rule that matches on sender patterns rather than a fixed domain string.
The From address looks blocked but mail still arrivesThe sender is spoofing the From header while the envelope sender (the actual authenticated domain) is differentCheck Email Log Search for the envelope sender and the SPF / DKIM result. Block the envelope sender domain, not just the From display domain.
Legitimate mail is also being rejectedA vendor, partner, or customer uses the same domain as the blocked senderReplace the blanket block with a content compliance rule that applies conditions, or add the legitimate sender address to the allowed senders list to override the block.

Email Log Search confirms whether a rule is firing

In Admin Console > Reporting > Email Log Search, search for the blocked domain in the sender field. The log shows the rule applied to each message, whether the outcome was Rejected or Quarantined, and the envelope sender domain — which matters when a From address is being spoofed from a different authenticated domain.

A faster way to handle domain-level noise at the inbox level#

The admin block in Google Workspace handles org-wide rejection — a permanent, binary decision you make once and maintain from the Admin Console. It works well for domains you are confident you will never want mail from. The harder problem is the domain you see this week and then again next week in a slightly different form, or a bulk-sender operation that cycles through dozens of subdomains before you can update the list.

AI Emaily's spam protection and cold-email filter work at the inbox level and match on sender behaviour and domain patterns rather than a fixed list. A domain rotation that would bypass a blocked senders entry is caught by the same signal set. The filter applies automatically on inbound mail without a rules update each time the sender adapts. We build AI Emaily. It connects to your existing Gmail mailbox without changing your DNS or admin settings, and it comes with a 7-day free trial on the Pro and Autopilot plans — there is no permanent free tier, but you can cancel before day seven if it is not the right fit. See the pricing page at aiemaily.com/pricing or the homepage at aiemaily.com.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

The admin block stops the domain. The inbox still needs a layer underneath it.

AI Emaily's spam protection and cold-email filter work at the inbox level and match on behaviour rather than a fixed list — catching domain variants and rotating senders the blocked senders rule misses. Try it on a 7-day free trial.

  • 7-day free trial
  • Cancel anytime
  • Every provider