5 min read By Excello Mail Team

The Emails KnowBe4 Just Built an AI to Catch Have No Link, No Attachment, and a Perfectly Clean DMARC Pass.

KnowBe4 announced Defend for Google Workspace on August 31, extending its behavioral AI email security to Gmail for the first time. The product is built to catch business email compromise, zero-payload phishing, and prompt injection attacks, the exact categories of message that carry no link, no attachment, and often nothing at all for DMARC to flag.

Most email security products still describe themselves by what they scan: links, attachments, headers. On August 31, KnowBe4 announced Defend for Google Workspace, its first extension of behavioral email security to Gmail, and the announcement is notable less for the product itself than for the three threat categories it names as the reason it exists: business email compromise, zero-payload phishing, and prompt injection. None of those three require a link. None require an attachment. Some require nothing a mail filter has traditionally had eyes on at all.

A Model Built for Messages With Nothing to Scan

Defend for Google Workspace will be available to KnowBe4 customers running Google Workspace on September 15, across SMB, mid-market, and enterprise environments, reaching a base of more than three billion Google Workspace users worldwide. At its core is a multi-engine behavioral AI model trained on KnowBe4’s own telemetry: more than 1.15 billion daily event signals and sixteen years of accumulated behavioral data. Rather than inspecting a message for a malicious URL or a weaponized file, the engines evaluate conversational intent, display-name spoofing, and the pattern of a request itself, the wording, the timing, the relationship it claims to have with the recipient.

That distinction matters because a zero-payload BEC message often has nothing else to evaluate. A finance-themed request to change a vendor’s bank details, sent in plain text from an account the recipient has corresponded with before, carries no indicator that a link scanner or an attachment sandbox was ever going to catch. The message is the attack. KnowBe4 built Defend for Google Workspace to sit at that layer instead, and paired it with real-time coaching: the moment a risky message is flagged, the intended recipient gets a contextual notification at the point of risk, turning a near-miss into a training moment rather than a silent block. The product also integrates natively with PhishER Plus, which the company says can hunt down and pull back a matching threat across every enterprise Gmail inbox in under two minutes once one instance is identified.

Why This Targets Google Workspace Specifically

KnowBe4’s behavioral engine has protected Microsoft 365 environments for years. Extending it to Gmail acknowledges something every security team running Google Workspace already knows: native Google controls are tuned heavily toward spam volume, known malware signatures, and bulk abuse patterns, and they are not designed to weigh whether a single, individually crafted message asking for a wire transfer matches the sender’s normal behavior. A message that is short, plausible, and sent from an account with an established relationship to the recipient does not look like spam to a spam filter. It looks like an email.

Why DMARC Was Never Built to Catch This

DMARC answers one question: did the domain in the message’s From header authorize the infrastructure that sent it. A zero-payload BEC message frequently makes that question irrelevant before it is even asked. The message may come from a compromised internal mailbox, which means the domain, the DKIM signature, and the DMARC policy are all completely genuine, because the account sending it is genuine. It may come from a freemail account with a display name spoofed to match a real vendor’s name, which authenticates cleanly against the freemail provider’s own DMARC policy while lying entirely in the part of the message DMARC does not look at. Either way, the message can pass every authentication check available and still be the entire attack, because DMARC was designed to confirm who was authorized to send, not to evaluate what a message is asking the reader to do.

What This Means for Your Program

Treat DMARC as the floor for your email program, not the ceiling. A domain enforcing p=reject has closed off direct spoofing of that domain, which is real and necessary progress. It has not touched compromised-account BEC, freemail impersonation, or a request typed by a human with nothing malicious attached to it.

Budget for a behavioral or intent-based layer, not just an authentication one. Whether that layer comes from your existing security stack or a new addition, the categories KnowBe4 is targeting here, zero-payload phishing and prompt injection among them, require evaluating what a message says and how it fits a pattern, not what infrastructure sent it.

Push security awareness to the point of risk, not just the annual training calendar. A contextual warning delivered the moment a suspicious request lands does more to stop a wire transfer than a phishing simulation run six months earlier.

Don’t assume Gmail’s native filtering was built for this threat category. Bulk spam controls and individually targeted, well-written social engineering are different problems, and a Google Workspace environment relying only on the former has a real gap the latter can walk through.

The Takeaway

KnowBe4 did not build Defend for Google Workspace because DMARC failed. It built it because DMARC was never the tool for this job, and neither was a spam filter tuned for volume. Zero-payload phishing and behavioral BEC are attacks made entirely of intent, carried in a message that authenticates perfectly because there was never anything to fake at the protocol level. Closing that gap takes a layer built to read the message, not just verify the sender.


DMARC confirms a domain had the authority to send. It cannot tell you that a genuine, authenticated account just asked someone to reroute a payment. Excello Mail turns your DMARC aggregate reports into a clear, continuous record of every domain and service sending as you, so the authentication layer stays airtight while your team builds the behavioral defenses for what happens inside a message that has nothing else to flag. Sign up for free to Excello Mail and get that foundation in place.