G DATA Phishing Simulation

Allowlist the IP addresses used by G DATA in the spam filter, Exchange Online (Office 365)

1.

Open the Microsoft 365 Admin Center.

2.

In the left-side menu, click Security.

Screenshot anzeigen
365 Security

3.

In the left-side menu, click Exchange message trace. You will then be taken to the Exchange Admin Center.

Screenshot anzeigen
365 Message trace

4.

In the left-side menu, click Mail flow and then, in the submenu that opens, click Rules.

Screenshot anzeigen
365 Security

5.

Click Add a rule. In the submenu that opens, select Create a new rule.
A new pane opens on the right-hand side of the screen. Give the rule a name, for example, "G DATA PhishingSIM WhitelistDomains".

Screenshot anzeigen
365 Add rule

6.

Under Apply this rule if, select The sender in combination with IP address is in any of these ranges or exactly matches.

Screenshot anzeigen
365 Add rule
365 Add rule

7.

Enter one of the IP addresses used by our campaign and click Add. Repeat the process until all required domains have been added. Finally, click Save.

The IPs and domains we use, which must be allowlisted accordingly in your organization, can be found in Awareness Manager under the tab "Perform allowlisting".
Screenshot anzeigen
IP addresses in the Awareness Manager

8.

In the drop-down menu "Do the following", select Modify the message properties.
In the next drop-down menu, select Set the spam confidence level (SCL) as the change.
Another pane opens on the right-hand side of the screen.

Screenshot anzeigen
365 Add rule

9.

In the drop-down menu, select "Bypass spam filtering" and click Save.

Screenshot anzeigen
365 Add rule

10.

Click Next.

11.

In the next window, make sure that Rule mode is set to "Enforce" and select a Severity for this rule. Rule matches are grouped in activity reports by Severity. Severity is only a filter to make the reports easier to use. Severity has no Impact on the priority in which the rule is processed. The Severity levels are:

  • Not specified

  • Low

  • Medium

  • High

  • Do not audit (rule matches are not shown in rule reports)

Screenshot anzeigen
365 Add rule

12.

Click Next.

Screenshot anzeigen
365 Add rule

13.

In the next window, review the settings again and click Finish.

Screenshot anzeigen
365 Add rule

14.

Your rule is then available in your rule list. However, it is still disabled. Click Disabled, and a new pane opens on the right-hand side of the screen.

Screenshot anzeigen
365 Rule disabled

15.

Set the status slider to Enabled.

Screenshot anzeigen
365 Rule disabled

Allowlisting our IP addresses for G DATA Phishing Simulation in the Exchange Online (Office 365) junk email filter is now complete.

You can find additional information about creating rules at Microsoft at Manage mail flow rules in Exchange Online.