WiseStamp for IT › Google Workspace › Step 12 of 12 — Troubleshooting Reference
Quick index
Symptom | Section |
Signature not appearing in Gmail | section 1 |
Two / duplicate signatures | section 2 |
Outbound mail not sending / rejected (server-side) | section 3 |
Signature missing only on some devices | section 4 |
Employees missing after sync | section 5 |
Admin can’t log in | section 6 |
Integration stuck / permissions | section 7 |
SPF "not found" / DKIM fails | section 8 |
Emails filtered as spam | section 9 |
Images broken / oversized | section 10 |
section 1 — Signature not appearing in Gmail
Directory connected but no deployment yet. Connecting the directory does not place signatures. Confirm Auto-Inject is On (Auto-Inject into Gmail) or server-side is configured (Server-Side Deployment).
Employee not Active. Auto-Inject works only for Active employees with a Primary Signature assigned. Check the Employees page.
Injection Off. Confirm the Injection toggle is On for the user (bulk or per-row) (Auto-Inject into Gmail).
Gmail not refreshed. Have the user refresh Gmail (and re-open compose).
Check Gmail settings. Gmail > Settings > Signature — confirm the WiseStamp signature is present and selected for new mail / replies.
section 2 — Two / duplicate signatures
Most common cause: the user has a manually added signature in Gmail > Settings > Signature in addition to WiseStamp. Remove the manual one, refresh Gmail.
Hybrid mode is designed to prevent duplicates (server-side only appends when no WiseStamp signature is detected). If duplicates persist, confirm the client-side signature is detected and check for a stray manual signature.
section 3 — Outbound mail not sending / rejected (server-side)
Emergency bypass: Google Admin Console > Apps > Google Workspace > Settings for Gmail > Compliance > Content compliance > find the WiseStamp rule > Disable. Mail then delivers without a server-side signature.
Contact WiseStamp support / your CSM.
Common causes to check: SMTP relay not allowing WiseStamp IPs or your domains; send route host/port wrong (<routing-code>.gw.smtp.wisestamp.net, port 25); SPF/DKIM misconfigured (section 8).
Keep super admin access available so bypass can be applied quickly.
Re-enable the compliance rule to resume signature deployment once resolved.
section 4 — Signature missing only on some devices
Auto-Inject writes into Gmail settings, so it covers Gmail where that account’s settings apply. Non-Gmail clients/apps or other senders won’t get the injected signature. For universal coverage use server-side or hybrid (Setup Overview, Server-Side Deployment).
The Chrome Extension only works in-browser (Gmail / Outlook web), not in native mobile apps.
section 5 — Employees missing after sync
Confirm directory integration is healthy and daily sync is on (Settings > Sync & Automations).
If using selective sync, the missing users' department/OU may be excluded — review the Sync specific selection (Scope Employee Sync).
Auto-synced accounts remove users no longer in the directory; a "missing" user may have been removed from Google Workspace.
A manual resync can be triggered from Sync settings.
section 6 — Admin can’t log in
Check for outages, refresh, clear cache/cookies, retry.
Chrome extension login loops: chrome://extensions/ > remove WiseStamp extension > log out and back in.
Subscription lapse: verify the subscription is active; renew to restore login and signature display.
Wrong audience: only owners/admins log into the main account; employees use the Employee Hub, not the main login.
SSO issues: confirm the user is assigned in the Google custom SAML app and the ACS/Entity ID/RelayState match (SSO with Google Workspace (SAML)).
section 7 — Integration stuck / permissions not granted
Google Admin Console > Apps > Google Workspace Marketplace apps > open WiseStamp > confirm permissions are Granted.
If the app wasn’t installed for Everyone at your organization, reinstall with org-wide scope (Connect Your Directory).
For the email-invite flow, confirm the super admin completed the Marketplace install and clicked Sync employees (Connect Your Directory).
section 8 — SPF "not found" / DKIM fails (server-side)
SPF not found:
Confirm include:outbound.smtp.wisestamp.net is in your SPF TXT record and has propagated.
SPF allows max 10 DNS lookups; nested records can break it. Flatten/consolidate; inspect with an SPF lookup tool.
DKIM fails after enabling server-side:
Temporarily disable the WiseStamp compliance rule; send a test; if DKIM now passes, injection is the cause.
Request your unique DKIM record from WiseStamp support (do not copy one from elsewhere).
Add it as a TXT record (value begins v=DKIM1;), TTL 1 hour.
Tell support you’ve added it so they enable DKIM signing on their side.
Re-enable the rule; send a test; confirm dkim=pass.
section 9 — Emails filtered as spam
Links: use full URLs, no redirects, link text matching the destination, all links reachable.
Wording: avoid spammy phrases and CTA-style buttons (e.g., "Sign Up", "Buy Now") in the signature.
Images: don’t overuse images; avoid images hosted across multiple external locations.
SPF: for server-side, ensure SPF includes WiseStamp (section 8).
section 10 — Images broken / oversized
Follow WiseStamp’s image size/quality best practices; oversized source images can render enlarged.
Confirm images are hosted/embedded as intended and the client isn’t blocking remote images.
Check dark-mode rendering separately.
When to escalate to WiseStamp support
Server-side mail flow failures after applying the emergency bypass.
DKIM record issuance and enabling DKIM signing.
SSO domain creation and metadata finalization.
Confirming the current server-side relay IP list and relay settings.
Confirming whether Google Group–based sync fits your setup.