G DATA Phishing Simulation

Whitelisting

Please note: Whitelisting is the sole responsibility of the Customer. If problems occur with your campaign that are solely due to the Customer’s network and its protection mechanisms, G DATA cannot provide any guarantee of smooth operation. To allow you to review your whitelisting before the actual campaign, G DATA offers various testing options. By submitting the data, you confirm that whitelisting has been performed correctly.

The phishing scenarios used in G DATA Phishing Simulation are modeled on real attacks. Therefore, it may happen that protection technologiesespecially from the area of anti-spam technologiesdetect the simulated attacks.

What must be ensured on the customer side?

To ensure that the simulated phishing emails reach your participants, whitelisting of the phishing domains used in these protection technologies is necessary. In addition, in our phishing scenarios we use websites that, in various ways, attempt to prompt your employees to disclose sensitive data such as login credentials or phone numbers. In this case, additional whitelisting in deployed web filters may be required.

To ensure that your G DATA Phishing Simulation runs smoothly and delivers meaningful measurements, it is important that

  • the emails we send reach the participants' mailboxes,

  • attachments have not been deleted,

  • automatic downloading of images in the participants' email client is disabled,

  • the included links are not blocked and a participant’s click reaches our servers,

  • the links and attachments are not opened by any malware analysis software as part of sandbox analysis procedures.
    This type of check opens links and attachments within a protected sandbox environment before the data is forwarded to the recipient. Our servers cannot distinguish whether the click was performed by such software or by the recipient. This would distort the evaluation of your phishing simulation.

You can find the IPs and domains we use, which must be enabled accordingly in your company, in the Awareness Manager under the TAB Whitelisting.

Help with whitelisting

There is a wide range of web filters, mail servers, proxy servers, firewalls, etc. on the IT market. For this reason, it is not possible for us to provide whitelisting guidance for all products.

Below, we have compiled a selection of instructions for you.

For all other products, if you have any questions, please contact the manufacturer support of the product used in your environment or your service partner who set up the product for you.

Microsoft Exchange Online and Microsoft Defender standard setup for phishing simulation

You can easily set up whitelisting in the Microsoft Defender portal with a standard configuration of your Exchange Online.

By creating a phishing simulation campaign in Microsoft Defender you can add our sender domains and our sender IP address for incoming email. Microsoft then controls further whitelisting through a phishing rule running in the background.

Microsoft provides a convenient bypass of its protection mechanisms for phishing campaigns if the incoming emails are received via the Microsoft standard connector. This connector is "invisible" and is used by Microsoft to receive emails if no additional connector has been created by your administrator to route mail flow differently through your own connectors.

This can be the case, for example, when using third-party spam and virus protection, or if you operate Exchange Online in hybrid mode with an on-premises Exchange. If you have set up such connectors in your environment, it must be ensured that

  1. our IPs are either not received via these connectors or

  2. whitelisting must be set up within the Microsoft Defender protection mechanisms themselves.

If you have changed mail flow via connectors, proceed to the next section of this article.

Microsoft Exchange Online and Microsoft Defender alternative setup
When using third-party software in conjunction with Exchange Online, please note that enhanced filtering must be enabled.

As an alternative to setting up a phishing simulation campaign in Microsoft Exchange Online, if you have set up an alternative mail flow, you can whitelist the IPs of your G DATA campaign within the protection mechanisms themselves:

* Bypass rules for attachments and links must be created if they were sent from our domains.

Exchange Online Protection (EOP)

Exchange Online Protection (EOP) is both part of Microsoft 365 Defender and also used as a standalone product for cloud protection of on-premises Exchange servers.

The instructions correspond to the procedure for Exchange Online (Office 365) and Microsoft 365 Defender:

Only the bypass rules for attachments and links are omitted, since this function is not included in EOP.

Domain whitelisting (firewall)

To obtain realistic results for a phishing simulation, a number of domains must be reachable. You can view which ones these are in the Awareness Manager under the TAB "Perform whitelisting" ("Step 1: Configure security technologies").

Show screenshot
365 Add rule

All domains listed here must be reachable and must not be blocked by the firewall in use. The reason is that otherwise not all clicks in the sent emails can be evaluated.

Due to the large number of available firewall products and the lack of any way to evaluate which solution is used in your specific case, it is not possible to offer a 1-to-1 guide here.

Google Workspace

To ensure that the emails of your phishing simulation campaign reliably arrive in your employees' inboxes, two settings are required in Google Workspace. Please set up both for all user accounts that are intended to participate in the campaign.

This Google Workspace guide is intended as an aid for our Customers. It is not official G DATA documentation. G DATA assumes no liability for the accuracy or completeness of the content.

You need administrator access to the Google Admin console (admin.google.com). In addition, you need the sender IP addresses for your G DATA phishing simulation. You can find these addresses in G DATA Awareness Manager under Whitelisting

Step 1: Add IP addresses to the allowlist

  1. Open the Google Admin console.

    Navigate to Apps  Google Workspace  Gmail  Spam, phishing, and malware.

  2. Select Email allowlist (E-Mail allowlist).

  3. Enter the sender IP addresses provided by G DATA. Save the setting.

This setting ensures that the simulation emails are not classified as spam.

Step 2: Adjust advanced phishing and malware protection

This step is important!

The allowlist alone is not sufficient. Google explicitly notes that the advanced security features also apply to senders on the allowlist. In particular, checking linked images can modify or block tracking pixels and simulation content.

  1. Navigate to Apps  Google Workspace  Gmail  Security.

  2. Scroll to the section "Links and external images".

  3. Disable the option "Scan linked images".

  4. Apply the change to the participating organization units or accounts.

Disable this setting only for the duration of the campaign. Disable the setting only for the participating accounts. Re-enable the protection after the simulation unless it is required permanently for tests.

Test whitelisting

Test whitelisting
Please note that as soon as your company has multiple sites with its own infrastructure, the tests must be carried out for all sites.

On this page you will find three control functions that you can use after whitelisting to test whether the requirements listed above have been met.

Step 1: Configure security technologies

With the Check reachability button, you can test whether all domains we use are reachable. Reachable domains are marked with a green check mark.

Step 2: Check whitelisting

Both control functions must be completed successfully once before you can start the campaign.

Test run

So far, a single mailbox has been checked.

After steps 1 and 2 of the check have been completed, whitelisting should be correct. Before the actual campaign is carried out, you now optionally have the possibility to test receipt of the emails by means of a test run. To do so, specify 5 email addresses with which you want to test the campaign. If you have multiple sites or different protection mechanisms, ensure that you select the addresses so that all eventualities are covered.

Select participants for a test run G DATA Phishing Simulation
Inform participants before sending the emails that they must not open the emails. Only then will you know afterward whether your security technologies are configured correctly.

You can repeat the test run as often as you like.

After successful delivery, a corresponding notice is displayed in the G DATA Awareness Manager.

Successful campaign test G DATA Phishing Simulation

If the status for all items in the Dashboard is green, the campaign is ready for sending the data and starting the campaign.