Instiq
Chapter 6 · Monitoring and troubleshooting·v1.0.0·Updated 6/15/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 6 (Domain 6 "Monitoring/troubleshooting": reports and audit logs = usage/security reports/admin-login-Drive-Gmail audit logs/BigQuery export; troubleshooting = Email Log Search/header analysis/investigation-tool cross-data investigation-bulk action/no-access isolation/GCDS checks).

6.2Troubleshooting (mail delivery and investigation)

Key points

Understand tracking delivery with Email Log Search, analyzing message headers, investigating incidents and taking bulk action with the investigation tool, and isolating typical access/sync/sharing problems.

Operations bring daily tickets like "mail not delivered" or "cannot share." Knowing the tools to isolate cause from symptom leads to quick resolution.

6.2.1Troubleshooting mail delivery

When mail is missing/slow, use Email Log Search to track a specific message delivery status (delivered, rejected, marked spam, delayed). For root cause, message header analysis (route, SPF/DKIM/DMARC results) helps. On the config side, suspect MX, SPF/DKIM/DMARC, or routing errors. Map "track whether a specific mail arrived = Email Log Search" and "check spoofing verdict/route = header analysis."

6.2.2The investigation tool and isolating problems

For security incidents (e.g., phishing spread), use the investigation tool to search logs across data and take bulk actions such as bulk-deleting the messages or addressing devices. For access problems, isolate in order: license assignment, service on/off, OU policy, 2SV/context-aware access conditions. For sync issues, check GCDS config/logs. Map "investigate incidents across data and act in bulk = investigation tool" and "no access = isolate license/service/OU policy/access conditions."

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.