ISSUE 32 · 6 MIN READ ·

Your internal mailing list is readable by the whole internet

A Google Group set to public years ago still publishes its message archive to anyone who searches. How to check who can view your groups and close them in ten minutes.

Somewhere in your organisation there is probably a mailing list — a Google Group used for a team, a project, a support alias, or announcements. People email it, the group fans the message out to everyone on it, and a copy is quietly kept in an archive. That’s all working as intended. What’s easy to miss is a single setting buried in the group’s configuration that decides who is allowed to read that archive — and on more groups than anyone expects, the answer is “anyone on the web”.

When a group’s visibility is set to public, its entire history of messages becomes a web page that search engines can index and strangers can read. Not the members’ inboxes — the archive. Every thread anyone ever sent to that list: the internal discussion, the customer’s support email with their details in it, the message where someone pasted a password “just for a moment”, the reply chain about a deal that hadn’t been announced. None of it was written to be public. All of it is, if the wrong toggle is set.

This is the quiet failure, and it’s one of the tidiest examples of the pattern. The group works flawlessly for the people using it. Nothing signals that a second, silent audience — the open internet — is reading over their shoulder. It’s the sort of exposure that surfaces only when someone outside searches for the right phrase and finds your internal conversations sitting on a public page. Google’s own Groups product had exactly this problem exposed at scale a few years ago, when researchers found large numbers of organisations unknowingly publishing their lists.

Why it stays invisible

The setting defaults to reasonable, and then decays. Someone creates a group, picks an access option in a hurry — often not certain what each one means — and moves on. The choice between “only members can view” and “anyone on the web can view” is a dropdown most people click through once and never revisit. If it lands on public, nothing ever tells them.

It stays hidden because a public archive looks identical to a private one from the inside. Members send and receive exactly as they would either way; the archive page they never visit is the only thing that differs. There’s no warning banner, no “this group is public” reminder in your daily use. And groups accumulate — new teams, short-lived projects, aliases set up for one event — each one another dropdown that may or may not have been set the safe way, and none of them prompting anyone to check.

Find it yourself

You can audit who can read your groups in about ten minutes. There are two vantage points — a quick personal check and a thorough admin one.

The quick check, for any group you own or manage:

  1. Go to groups.google.com and open My Groups.
  2. Open a group, then click Group settings in the left-hand menu.
  3. Find the Who can view conversations setting, under the General section.
  4. If it’s set to Anyone on the web, that group’s archive is readable by strangers. Change it to Group members (or Entire organization, if that’s the intent).

The thorough check, if you administer Google Workspace for the organisation:

  1. Sign in to the Admin console at admin.google.com.
  2. Go to Directory → Groups, and also check Apps → Google Workspace → Groups for Business → Sharing settings, which sets the tenant-wide ceiling for how public any group is allowed to be.
  3. Under Sharing settings, set Accessing groups from outside this organization to Private so that no individual group can be made public unless you deliberately allow it, then review individual groups for any that were already opened.

The fix

Good looks like this: every group readable only by the people who are meant to read it, and an organisation-wide sharing setting of Private acting as a backstop so a future group can’t be created public by accident. That backstop matters more than fixing groups one by one — it turns the safe choice into the default and takes the decision out of the hands of whoever is in a hurry next.

Once you’ve set the ceiling, walk the existing groups and close any that were opened. You won’t lose the messages; changing who can view an archive doesn’t delete it, it just draws the curtain. Where a group genuinely needs to be public — an open community list, a published support forum — leave it public on purpose, and make sure everyone posting to it knows the archive is a public page, so nobody pastes into it something they’d never put on your website.

To keep it closed, let the organisation-wide Private setting do the standing work, and add a twice-a-year glance at the group list to catch anything created outside it. It’s a small habit, and it converts “who can read our internal lists?” from an uncomfortable shrug into a question you’ve actually answered.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.