EN FR
Features How it works Pricing Contact Login
🕒 Last updated: September 10, 2026

Set up Google Workspace to work with Clean Mailbox as your inbound gateway

A step-by-step guide to declare Clean Mailbox as an inbound gateway in Google Workspace, and avoid delivery issues caused by SPF.

⚠️

The Google admin console changes regularly: the menus, labels and locations described below may differ from what you see today. This guide is provided as a courtesy to help you; it does not replace Google's own official support, which remains solely responsible for guiding its customers through the administration of their Google Workspace domain.

Why this is needed

When Gmail receives an email relayed by Clean Mailbox, it sees by default the IP address of our servers instead of the original sender's IP. If the sending domain enforces a strict SPF record (-all), Gmail may treat the email as unauthenticated — since Clean Mailbox's IP is not listed in the sender's SPF record.

Google Workspace has an Inbound gateway setting built exactly for this case: once your Clean Mailbox servers are declared, Gmail can recover the original sender's real IP address (by parsing the message's Received: from headers) to evaluate SPF, instead of evaluating SPF against the gateway's IP.

This guide is intended for the domain administrator (or your IT provider) and covers a configuration you only need to perform once, after pointing your MX records to Clean Mailbox.

💡

This guide applies to domains whose mailboxes are hosted on Google Workspace and protected on the inbound side by Clean Mailbox. Unlike some other mail systems, Gmail does not enforce the sender domain's DMARC policy on messages received through a declared inbound gateway; it relies instead on the authentication information available to it for its own spam evaluation.

IP addresses to allow

Clean Mailbox relays your incoming email from the following addresses. You'll need them for step 2 below.

TypeAddresses
IPv4 213.32.76.196/32
51.178.81.41/32
45.63.114.93/32
163.172.164.47/32
IPv6 2001:41d0:404:200::4d8f/128
2001:41d0:302:1000::500/128
2001:19f0:6801:10c:5400:ff:fe58:b68/128
2001:bc8:710:a30:dc00:ff:fe8a:301/128
⚠️

This list may change as Clean Mailbox's infrastructure evolves. Before applying this configuration, check the up-to-date list from your customer portal. Also note that Google Workspace only accepts public IP addresses in this setting: private ranges are rejected.

1

Open the inbound gateway setting

From the Google admin console, open the menu, then go to Apps → Google Workspace → Gmail, and click Spam, phishing, and malware. This page requires an account with Gmail admin privileges.

In the left panel, select the top-level organizational unit (unless you want this configuration to apply to a specific organizational unit only), then scroll down to the Inbound gateway setting and click Edit.

2

Add Clean Mailbox's IP addresses

In the panel that opens, click Add, then enter one of Clean Mailbox's IPv4 addresses listed above (one at a time, in x.x.x.x/32 format). Repeat for each address.

If your mail also flows over IPv6, you can try adding the IPv6 ranges the same way; if the field rejects them, contact us — IPv4 alone is sufficient for the vast majority of setups.

Then click Save to confirm the address list.

3

Set the recommended security options

On the same inbound gateway configuration page, three options are worth your attention:

ℹ️

If a Received: from header is malformed, Gmail can't determine the original IP address and falls back to checking only the previous hop. An advanced spam-tagging option using regular expressions also exists, to tell Gmail to trust a gateway's own spam score instead of running its own evaluation; most Customers don't need it since Clean Mailbox already filters spam upstream, but contact us if you'd like to use it.

Click Save at the bottom of the page. Changes can take up to 24 hours to apply, though it's usually faster; you can track the rollout in the admin console's audit log.

Verify it works

Once the configuration is saved and your MX records' TTL has expired, send a test email from an external domain with a strict SPF record, and check the received message (via Gmail's Show original menu) that the SPF/Authentication-Results evaluation is based on the sender's original IP address, not Clean Mailbox's.

Frequently asked questions

Does Google still enforce the sender's DMARC policy?

No: according to Google's own documentation, the sending domain's DMARC policy is not enforced on messages received through a declared inbound gateway. Gmail relies on the authentication information available to it for its own spam evaluation.

Should I also add Clean Mailbox's IPs to my allowlist?

No, it wouldn't have any effect: when the same IP address appears both in the inbound gateway list and in an allowlist, the gateway list entry takes precedence. To give a specific sender the benefit of a spam-filter bypass, add that sender's real original IP (identified via the headers) to the allowlist, not the gateway's IP.

Questions about the Clean Mailbox configuration?

Our support team can help you confirm the IP addresses to allow or diagnose a delivery issue. For the administration of your Google Workspace domain itself, please reach out to Google support or your IT provider.

Contact Clean Mailbox →

Let's protect your mailbox.

Questions about the trial, setup, pricing, or a partnership? We're here — and we answer fast.

30-day free trial, no card required
Works with any mail server
Setup in under 5 minutess
Infrastructure based in France 🇫🇷