Ensuring that phishing simulations and security awareness training emails reach your users without being blocked is essential for an effective cybersecurity program. Microsoft 365 (O365) security filters may mistakenly classify these emails as spam or phishing attempts. To prevent this, you need to whitelist specific IP addresses and domains within Exchange and the Microsoft 365 Security Portal.
By following this guide, you will:
Ensure phishing simulations and security training emails reach users' inboxes.
Prevent important security awareness messages from being marked as spam.
Improve the effectiveness of your cybersecurity training initiatives.
Go to Exchange Admin Center.
Sign in with your administrator credentials.
Navigate to Mail Flow > Rules.
Click on Add Rule > Create Rule.
Enter the rule name: Hoplon Whitelisting.
Configure the rule conditions as follows:
Condition 1: Whitelist by IP Address
Under Apply this rule if, select The sender.
Choose IP address is in any of these ranges or exactly matches.
Enter the following IP addresses:
198.21.6.191
168.245.56.242
99.80.168.14
Set the Action:
Under Do the following, choose Modify the message properties.
Select Set the spam confidence level (SCL) and set it to Bypass spam filtering.
Configure the rule conditions as follows:
Condition 2: Whitelist by Domain
Click Add condition.
Under Apply this rule if, select The sender.
Choose Domain is and enter the domains:
Set the Action:
Under Do the following, choose Modify the message properties.
Select Set the spam confidence level (SCL) and set it to Bypass spam filtering.
Click Save to apply the rule.
This configuration ensures that emails from the specified IPs and domains bypass spam filters and reach users' inboxes
Sign in with your administrator credentials.
Expand Email & Collaboration in the left sidebar.
Navigate to Policies & rules > Threat Policies > Anti-spam.
Select the Inbound policy that you are using.
Locate the Allowed and blocked senders and domains section.
Click on Edit allowed and blocked senders and domains.
Under Allow domains, enter the following:
Click Save to apply the changes.
By implementing these whitelisting rules in Exchange and the Microsoft 365 Security Portal, you ensure that security awareness training emails and phishing simulations are effectively delivered to users. This prevents unnecessary filtering and supports a strong cybersecurity culture within your organization.
If you need further assistance, let us know!