Google Workspace administrator can not directly access their organization users emails, however, YES, he has following options to use Google Vault, Content Compliance rules, Audit API or Email delegation to view and audit users emails. In this article, We’ll show you how you can get bcc copy of your users/employees emails (sent and received emails) via Content Compliance Rule without knowing their Google Workspace password or putting forwarding in their mailboxes.
It is recommend for Google Workspace administrators to consider their local laws before performing email auditing on their users mailboxes.
This solution is primarily meant for auditing purpose you would like to track incoming and/or outgoing (including intra-domain) emails of one or all of your Google Apps users, without asking or changing their password or putting a forwarding rule in their mailboxes.
You can apply this rule on either one user, or an OU or even at all users and this rule will state, that any message which contain @yourdomain.com in the message header, then send its copy to the id which you define.
STEP 1 – Login to Google Workspace admin console
We assume you have administration permission to perform this task. First login to your organization Google Workspace admin console (admin.google.com).
STEP 2 – Navigate to Apps >> Google Workspace
Once you are logged into Google Workspace admin panel, click on Apps section icon from the admin dashboard and you will see the Google Workspace option in next new page.
STEP 3 – Click on Gmail app
As we will be applying a server side rule to our Gmail application, which will get us bcc copy of all sent and received emails of our users. Click on the Gmail app icon as shown in the screenshot below.
STEP 4 – Click on Compliance option
The rule we want to apply is a part of Gmail configure compliance features option available at the end of the page, go ahead and click on it.
STEP 5 – Select right organization unit
If you want to receive bcc copy of all the users in your domain, you can select the parent organization unit.
If you want to apply it on a specific function such as sales or marketing or IT Department or even only on a few users, you may create a new organizational unit and put required users in it.
After selecting right orgnaizational unit, scroll down to find “Content Compliance” and click on “Configure” as shown in the screenshot below
STEP 6 – Define Content Compliance rule’s scope
Enter a recommended short description that will appear within the setting’s summery for your rule to ensure other administrators in your domain can refer to it and understand this rule’s objective in your absence.
Select which emails you want to get as bcc for users, you can select any or all including inbound, outbound, internal sending or receiving, for the sake of this example, am only considering inbound and outbound, and not the intra-doamin ones.
STEP 7 – Define the expression
Lets define our condition, think of it like IF/Else statement-:
Select “If any of the following match the message”
Click on “Add” to add a condition statement
Click on “Advance Content Match”
Location should be “Full Headers”
Match Type should be “Contain Text”
Content should be “yourdomain.com” (you need to change yourdomain.com to your actual domain name)
Save your condition
STEP 8 – Who should get BCC?
Scroll down and click on “Add more recipients”
Click on “Add” to add a delivery recipients
Select Advance option
At envelope recipient section select “Replace Recipient”
Enter the email id on which you would like to get bcc copy
Scroll below and follow the next step in this article
STEP 9 – Prepend subject (recommended)
In this step, we’ll define a way to separate these bcc emails from your regular ones, so you can easily identify them and filter/label them if required.
Click on “Prepend custom subject”
Add any thing you would like to prepend in the subject of these bcc emails, for example [BCC]. Now all theses bcc copies that you’ll get will have [BCC] in front of the subject line, which will help you make filter in Gmail and put them under a label/folder.
Save your changes
STEP 10 – Done!
Last step to save all above settings finally.
Congratulations, you will now get a bcc copy of your users in the mailbox you put in your condition as shown in above example.