This article explains how to set up the allowlist for the Security Awareness Service in Kerio Connect.
The allowlist ensures that simulated phishing emails from the Security Awareness Service are not blocked by Kerio Connect due to IP-based blocklist checks.
Note
Kerio Connect is operated by GFI Software. The user interface and available settings may change due to updates.
Therefore, also check the current documentation from GFI Software if the menu items described here differ in your version of Kerio Connect.
Prerequisites
Make sure the following prerequisites are met:
- You have administrator access to Kerio Connect.
- You know the current IP addresses or IP address ranges of the Security Awareness Service.
Create IP address group
- Log in to the Kerio Connect Administration.
- Navigate to Configuration > Definitions > IP Address Groups
- Click add.
- Create a new IP address group.
- Add the IP address ranges of the Security Awareness Service.
- Save the IP address group.
GFI also describes IP address groups under Configuration > Definitions > IP Address Groups. IP address groups can be used in other Kerio Connect settings as well.
Use IP address group as allowlist
- Navigate to Configuration > Content Filter > Spam Filter > Blocklist.
- Switch to the section Custom allowlist for IP addresses.
- Enable the option Use IP address group.
- Select the previously created IP address group.
- Save the changes by clicking Apply.
According to GFI, messages from servers on this whitelist are not checked against the Kerio Connect spam filters relevant in this area. The configuration is done via Spam Filter > Blocklist or in the current path via Configuration > Content Filter > Spam Filter > Blocklist.
If emails are still blocked
Note that according to GFI, the IP whitelist in Kerio Connect only applies to checks against Internet blocklists. If simulated phishing emails are still blocked or marked as spam, additional spam filter checks may be in effect.
In this case, also check:
- other spam filter rules in Kerio Connect
- Custom Rules under Configuration > Content Filter > Spam Filter > Custom Rules
- upstream gateways or firewalls
- web filters or link scanners
- antivirus or sandbox functions
GFI describes, for cases where custom allowlists do not fully override the spam filter, an additional rule under Custom Rules. This can treat a message as non-spam based on a header.
More information
The current IP addresses, IP address ranges, and domains for the Security Awareness Service can be found in the documentation for allowing simulated phishing emails.