How to Restrict Temporary Employees' Email Domains in Google Workspace?

Your organization has a strict requirement that your temporary employees can only send emails to and receive emails from specific external domains. You must define a policy in Google Workspace that meets this requirement for users in the temporary employee organizational unit (OU). What should you do?

  1. Create a policy in Gmail settings that rewrites the recipient for outbound messages and quarantines incoming messages to review before delivery.
  2. Add the allowed domains when configuring the restrict delivery setting in Gmail settings, and select the box to bypass for internal emails.
  3. Restrict sending and receiving to Google Groups, and carefully curate the temporary employees' memberships.
  4. Configure the restrict delivery setting to limit domains that the temporary employees can communicate with. Allow Google Docs sharing notifications. Source Reference Answer

Community Votes

D
67%
B
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests applying granular Gmail delivery restrictions via OUs, with the common trap being misapplying organization-wide settings instead of targeting specific user groups.

This question tests configuring Gmail's restrict delivery settings within an organizational unit to limit external email communication. The community consensus favors applying the restriction directly to the target OU while ensuring essential services like Google Docs notifications remain functional.

Option B is frequently chosen because it correctly identifies the restrict delivery feature, but it fails to specify applying the policy to the designated temporary employee OU, risking unintended organization-wide restrictions.

Community Discussion (3 comments)

ptsironis 👍 1 Selected: D
This approach directly addresses the requirement by limiting outbound email to approved domains and allowing necessary inbound communication, such as Google Docs sharing notifications. By configuring the restrict delivery setting, you can ensure that temporary employees adhere to the organization's email communication policy while still allowing essential collaboration.
3fd692e 👍 1 Selected: D
I'm going with D. B and D both work but neither is a 100% clear winner. I picked D because it specifically called out applying the restrictions for the temporary users. B appears that it will apply to everyone in the organization. D, final answer.
apb98 👍 1 Selected: B
By configuring the restrict delivery setting and specifying allowed external domains, you ensure that temporary employees can only communicate with designated external domains.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D correctly utilizes the Gmail restrict delivery setting to limit both sending and receiving to specified external domains. By configuring this at the OU level, administrators can precisely target temporary employees without affecting other staff. Additionally, explicitly allowing Google Docs sharing notifications prevents workflow disruptions while maintaining strict email boundaries.

Why the Other Options Are Wrong

Option A incorrectly suggests rewriting recipients and quarantining inbound mail, which is unnecessary and disrupts legitimate communication. Option B describes the correct feature but lacks OU scoping, meaning it would inadvertently restrict all organization members rather than just the temporary staff. Option C relies on Google Groups as a workaround, which is overly complex and not the native method for domain-level email restrictions in Google Workspace.

Community Comment Notes

Community feedback highlights that Option D’s explicit mention of the target OU makes it superior to Option B, which appears organization-wide. Comment [2] correctly notes that while both B and D reference the restrict delivery setting, D specifically addresses the requirement for temporary users. Comment [1] reinforces that D balances security compliance with necessary collaboration tools like document sharing.

Official Reference

Exam Strategy

Always match policy configurations to the specific scope mentioned in the prompt (e.g., OUs vs. organization-wide). When multiple options use the same feature, carefully compare how each handles scoping and exception handling to identify the most precise administrative action.

Related Analysis

← Back to PWA Study Guide