This article explains why whitelisting is required for the Security Awareness Service.
In order to use the Security Awareness Service, certain IP addresses, IP address ranges, and domains must be allowed.
Why is Whitelisting Necessary?
Whitelisting ensures that simulated phishing emails, notifications, and training emails reliably reach the recipients.
Additionally, whitelisting prevents security and filtering systems from distorting the results of the phishing simulation.
Without proper whitelisting, the following issues may occur, for example:
- Emails are moved to the junk or spam folder.
- Emails are blocked or delivered with delays.
- Links or attachments are pre-scanned by security solutions.
- Sandboxes automatically open links or attachments.
- Clicks, opens, or other actions are incorrectly counted as a result.
What Needs to Be Allowed?
Depending on your system landscape, IP addresses, IP address ranges, and domains must be allowed.
The current values can be found in the documentation portal:
Allowances for Sending Simulated Phishing Emails
Note
Check whitelisting not only in your email system but also in other security solutions that may affect mail flow or web access.
This includes, for example, spam filters, firewalls, web filters, sandboxes, or endpoint security solutions.