Enhanced Email Security
Georgetown University is launching an enhancement to email security tool designed to reduce inbox clutter and protect our community from digital threats. This system uses advanced filtering to handle two main types of content:
- Malicious Threats: Sophisticated protection that silently removes phishing and malware before they reach you.
- Graymail: A productivity tool that identifies newsletters and promotions, moving them to a dedicated space so you can focus on what matters.
Benefits
What You Will See
- The “Graymail” Label: Within 24-48 hours, you will see a new label called “Graymail” in your Gmail folders/labels list.
- Native Google Reporting Buttons: The standard Google “Report Phishing” and “Report Spam” buttons are now fully active.
How to…
Locate and Manage Graymail
- Open Gmail on your desktop or mobile device.
- Look for the Graymail label in the left-hand navigation menu (under “Labels”).

- Click the label to view filtered messages.
- Drag the message from the Graymail folder to the Inbox tab, or right-click and select Move to Inbox. This tells the system you want to see these emails prominently in the future.
Mark Email as Spam
If you receive “junk” mail that isn’t a newsletter but is clearly unwanted advertising or bulk mail:
- Select the email in your Inbox or Graymail folder.
- Click the Report Spam icon (the stop sign with an exclamation point) in the top toolbar.

- The message will be moved to your Spam folder and deleted after 30 days.
How to Report a Phishing Email
Phishing is a fraudulent attempt to get you to share sensitive information like passwords or credit card numbers.
- Open the suspicious message.
- Click the More icon (three vertical dots) next to the “Reply” button.
- Select Report phishing. (Note: You can also report SPAM here)
For every reported message, you will receive a clear explanation of the outcome and actions taken.
Frequently Asked Questions (FAQs)
Google was working just fine, why are we doing this?
While Google Workspace provides strong native defense against traditional, signature-based threats like standard malware and known bad links, organizations require an advanced, behavioral-based security platform to stop sophisticated, modern attacks.
These supplementary systems analyze communication context and establish behavioral baselines to detect payload-free scams and compromised trusted accounts that easily bypass standard authentication filters.
Furthermore, by integrating directly via API, this added layer protects against internal lateral attacks between employees and automatically organizes bulk marketing messages under a dedicated Graymail label, offering comprehensive protection and inbox management that standard tools cannot achieve alone.
What is Graymail?
Unlike SPAM (which is unsolicited and often malicious), Graymail consists of legitimate emails that you may have signed up for but don’t need to see immediately.
- Examples: Newsletters, retail promotions, and marketing updates.
- The Problem: These messages clutter your inbox, making it harder to find urgent business or academic communications.
**Note: Companies that we do business with may also send graymail, like Zoom or Canvas.
What is this security platform and how does it work?
It is an advanced, behavioral-based email security platform. It integrates with Google Workspace to detect and remove email-based threats such as phishing, malware, and business email compromise. It learns the normal communication behavior of everyone in your organization, allowing it to detect anomalies and block sophisticated attacks before they reach your inbox.
Is the system reading all my emails?
No. While the system scans messages for threats, it does not store, persist, or retain the contents or attachments of emails that its detection models identify as non-malicious. Only the content and attachments of emails identified as malicious are subject to further processing.
What should I do if a suspicious email makes it into my inbox?
You should report it using the standard methods provided by GMAIL (e.g., clicking “Report as Phishing” in Gmail). Because the security tool integrates directly with GMAIL native features, reporting the message helps improve protection and trains the system for the future.
Why did an email appear in my inbox and then suddenly disappear?
This is normal behavior. The system processes messages in a secure environment after they are delivered. If it determines a message is malicious, it removes it automatically. If you happen to be watching your inbox closely, you might see a message briefly arrive and then disappear milliseconds later.
What should I do if I am missing an expected email?
On rare occasions, legitimate emails may be flagged by the system. First, check your spam folder, as well as the “Graymail” folder under Labels. If you still cannot find it, contact help@georgetown.edu with the sender’s email address, subject line, and approximate date/time sent so they can investigate.
What is the Graymail folder?
Graymail is automatically filtered into a special folder to keep your primary inbox clean and focused on important communications.

How do I train the system if it misclassifies my emails?
You can actively train your inbox by moving messages:
- If an email goes to Graymail: Move the message from the Graymail folder back to your Inbox. This tells the system it is not graymail and should be delivered normally in the future.
- If graymail ends up in your Inbox: Move the message from your Inbox into the Graymail folder. This teaches the system to recognize these messages as graymail going forward.
How long does it take for the system to learn my preferences?
Training occurs continuously as you move messages, and improvements usually take effect within a few hours to a few days.
Can I opt out of email security entirely?
Unfortunately, no.
- Enterprise-Wide Threat Protection: Email security is enforced at the organization level to safeguard the entire university against phishing, ransomware, malware, and data breaches. Allowing individual users to opt out would create security blind spots, leaving those mailboxes and the broader network vulnerable to attack.
- Centralized System Integration: The security platform operates via a centralized API integration directly within our cloud email environment. Because it runs at the domain level rather than as a user-installed app or extension, settings are managed universally by University Security teams.
- Prevention of Internal (Lateral) Attacks: Cyberattacks often involve compromised internal accounts sending malicious messages to co-workers. Uniform security coverage ensures that incoming and internal messages are consistently scanned to stop threats from spreading laterally across the organization.
- Regulatory Compliance & Governance: Organizations are required to adhere to industry security standards, legal regulations, and corporate governance policies. Maintaining consistent threat detection and message protection across all mailboxes is essential for meeting these compliance obligations.
Note on User Control: While individual opt-outs are not permitted, users retain direct control over how non-malicious messages are organized. Moving emails between your Inbox and Graymail folder continuously tunes the system to respect your personal email preferences.
Need additional support?
Contact the UIS helpdesk at help@georgetown.edu.