Phishing Simulation

Sending Domains & IPs

Sending Domains & IPs

PhishGrid delivers simulation and awareness emails from a set of sending domains and IP addresses. These values are specific to your account and can change over time — new domains or IPs may be added as infrastructure scales or rotates. Always whitelist the current values, never a fixed list copied from elsewhere.


Where to find your values

In the PhishGrid platform, go to Settings → IP & Domains. This lists everything currently active for your account:

  • Simulation domains — used for phishing simulation emails
  • Awareness / content domains — used for training and awareness content
  • Sending IP addresses — the mail servers PhishGrid sends from
  • Simulation header — a custom message header on simulation mail, where available (the most reliable value to whitelist on)

What to whitelist

Across every layer of your mail security — gateway, spam filter, connection/IP filter, and link/URL protection — allow:

  1. Every sending domain listed under Settings → IP & Domains
  2. Every sending IP address listed there
  3. Your awareness/content domain, if you run training content

Then follow the guide for your mail system in this section.


Whitelisting methods

Depending on your stack you can allow PhishGrid mail by one or more of these. Combine at least two (typically IP + one more) for reliable delivery:

Method What it does Notes
By IP address Allow PhishGrid's sending IPs at the connection/gateway layer Most reliable; least likely to be spoofed
By sending domain Allow PhishGrid's envelope/From domains Easy, but weaker on its own
By message header Match PhishGrid's simulation header and bypass filtering The strongest cross-gateway method where your account exposes a header
Advanced Delivery (Microsoft 365) Register domains, IPs and simulation URLs in the phishing-simulation override Microsoft's sanctioned path for third-party simulations
Bypass link/URL scanning Stop URL rewriting / time-of-click protection for PhishGrid domains Prevents scanner pre-fetches from registering as clicks (false positives)
Bypass attachment sandboxing Exclude PhishGrid senders from attachment detonation Only needed if your simulations use attachments

Because the list is dynamic

  • Re-check before every campaign. Open Settings → IP & Domains and confirm your whitelist still matches; add any newly listed domain or IP before launching.
  • Prefer IP- and header-based rules. They survive domain changes better than a static domain list.
  • Don't hardcode. Avoid baking a fixed list into permanent rules without a review reminder — dynamic values drift.

Verify it worked

  1. Send a small test campaign (5–10 users) before launching organisation-wide.
  2. Confirm emails arrive in the Inbox (not Spam/Junk/Promotions).
  3. Confirm a click is recorded correctly in PhishGrid (not pre-triggered by a scanner).
  4. If anything fails, see Emails Not Being Received — Troubleshooting Guide.