We have built this guide to make allowlisting as easy as possible for you and your team.
If you are looking for a list of where we send from, then look no further!
All of our messages that are sent over SMTP are sent through the following IP:
IP (1): 22.214.171.124
Clickable URLs in phishing and training emails
If you need to understand what links are in our communications that may be accidentally detonated by any pre-scanning software:
Make sure to add the URLs exactly as they appear below!
This is the domain that Phin will use for our own branding and communications.
In order to make sure training reminders and simulated phishing make it through your email filtering process, you will need to allow the following base domains if sending IP can not be configured.
Depending on what system you are filtering through, you may need to add a wildcard version of the domains such as *.shippingalerts.com. We utilize subdomains to make the domains go farther. So the below list is just the base domains of our phishing emails.
New-PhishSimOverrideRule -Name PhishSimOverrideRule -Policy PhishSimOverridePolicy -Domains betterphish.com,shippingalerts.com,amazingdealz.net,berrysupply.net,coronacouncil.org,couponstash.net,creditsafetyteam.com,autheticate.com,notificationhandler.com,phinsecurity.com -SenderIpRanges 126.96.36.199
Sometimes it is important to enable a Transport rule to force emails to show in users' inboxes whether they have “Focused Inbox” mode enabled or not. This script will create a new Transport Rule
New-TransportRule -Name "Bypass Focused Inbox for Phin" -SenderIpRanges “188.8.131.52/32” -SetHeaderName "X-MS-Exchange-Organization-BypassFocusedInbox" -SetHeaderValue "True"
Additionally, you may need to enable Advanced Delivery policy/rules so that test emails are properly identified as phish simulation tests and are not blocked. If these emails are reported to Microsoft, they will also NOT be scanned, causing false positive click reports.
Commands to be run from the “Exchange Online PowerShell”:
New-TenantAllowBlockListItems -Allow -ListType Url -ListSubType AdvancedDelivery -Entries "*.betterphish.com/*","*.shippingalerts.com/*","*.amazingdealz.net/*","*.berrysupply.net/*","*.coronacouncil.org/*","*.couponstash.net/*","*.creditsafetyteam.com/*","*.autheticate.com/*","*.notificationhandler.com/*" -NoExpiration
Commands to be run in the “Exchange Security & Compliance PowerShell”:
New-PhishSimOverridePolicy -Name PhishSimOverridePolicy
New-PhishSimOverrideRule -Name PhishSimOverrideRule -Policy PhishSimOverridePolicy -Domains 'betterphish.com','shippingalerts.com','amazingdealz.net','berrysupply.net', 'coronacouncil.org','couponstash.net','creditsafetyteam.com','authenticate.com','notificationhandler.com' -SenderIpRanges 184.108.40.206
Allowlist by sending domains:
Follow the steps under the “Add a list of approved senders that bypass spam filters” section
Bulk Upload the following comma separated list of 20 domains:
Allowlist by IP:
Our dedicated sending IPs:
- Phishing email: 220.127.116.11
- Reminders: 18.104.22.168