Instiq
Chapter 6 · Monitoring and troubleshooting·v1.0.0·Updated 6/15/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 6 (Domain 6 "Monitoring/troubleshooting": reports and audit logs = usage/security reports/admin-login-Drive-Gmail audit logs/BigQuery export; troubleshooting = Email Log Search/header analysis/investigation-tool cross-data investigation-bulk action/no-access isolation/GCDS checks).

6.2Troubleshooting (mail delivery and investigation)

Key points

Understand tracking delivery with Email Log Search, analyzing message headers, investigating incidents and taking bulk action with the investigation tool, and isolating typical access/sync/sharing problems.

Operations bring daily tickets like "mail not delivered" or "cannot share." Knowing the tools to isolate cause from symptom leads to quick resolution.

6.2.1Troubleshooting mail delivery

When mail is missing/slow, use Email Log Search to track a specific message delivery status (delivered, rejected, marked spam, delayed). For root cause, message header analysis (route, SPF/DKIM/DMARC results) helps. On the config side, suspect MX, SPF/DKIM/DMARC, or routing errors. Map "track whether a specific mail arrived = Email Log Search" and "check spoofing verdict/route = header analysis."

6.2.2The investigation tool and isolating problems

For security incidents (e.g., phishing spread), use the investigation tool to search logs across data and take bulk actions such as bulk-deleting the messages or addressing devices. For access problems, isolate in order: license assignment, service on/off, OU policy, 2SV/context-aware access conditions. For sync issues, check GCDS config/logs. Map "investigate incidents across data and act in bulk = investigation tool" and "no access = isolate license/service/OU policy/access conditions."

Exam point

Common: symptom → tool/cause. E.g., "check whether a specific mail arrived" = Email Log Search; "check spoofing verdict/route" = header analysis; "bulk-delete phishing mail" = investigation tool; "service unavailable" = isolate license/service on-off/OU policy/access conditions; "not syncing" = check GCDS.

Warning

Watch the mix-ups: (1) Email Log Search (delivery tracking) and the investigation tool (cross-data investigation/bulk action) serve different purposes. (2) For "no access," isolate in order license → service → OU policy → access conditions. (3) Investigation-tool bulk actions are powerful—confirm scope before running.

Diagram of Email Log Search (delivery tracking) and header analysis, the investigation tool (cross-data investigation/bulk action), and isolating no-access in order license→service→OU policy→access conditions.
From symptom to cause

6.2.3Section summary

  • Track mail delivery = Email Log Search; root cause = header analysis and MX/SPF/DKIM/DMARC checks
  • Cross-data incident investigation and bulk action = investigation tool
  • For no-access, isolate in order: license → service → OU policy → access conditions

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To track whether a specific email arrived (delivered/rejected/marked spam), what do you use?

Q2. To investigate phishing mail spread across the org and bulk-delete it, what do you use?

Q3. To examine spoofing verdicts and the route of an email in detail, which best fits?

Q4. A user reports they cannot use a service. Which isolation order is most appropriate?

Q5. GCDS sync is not working. What should you check first?

Q6. Which correctly contrasts Email Log Search and the investigation tool?

Check your understandingPractice questions for Chapter 6: Monitoring and troubleshooting

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.