Sending Domains & IPs
Sending Domains & IPs
PhishGrid delivers simulation and awareness emails from a set of sending domains and IP addresses. These values are specific to your account and can change over time — new domains or IPs may be added as infrastructure scales or rotates. Always whitelist the current values, never a fixed list copied from elsewhere.
Where to find your values
In the PhishGrid platform, go to Settings → IP & Domains. This lists everything currently active for your account:
- Simulation domains — used for phishing simulation emails
- Awareness / content domains — used for training and awareness content
- Sending IP addresses — the mail servers PhishGrid sends from
- Simulation header — a custom message header on simulation mail, where available (the most reliable value to whitelist on)
What to whitelist
Across every layer of your mail security — gateway, spam filter, connection/IP filter, and link/URL protection — allow:
- Every sending domain listed under Settings → IP & Domains
- Every sending IP address listed there
- Your awareness/content domain, if you run training content
Then follow the guide for your mail system in this section.
Whitelisting methods
Depending on your stack you can allow PhishGrid mail by one or more of these. Combine at least two (typically IP + one more) for reliable delivery:
| Method | What it does | Notes |
|---|---|---|
| By IP address | Allow PhishGrid's sending IPs at the connection/gateway layer | Most reliable; least likely to be spoofed |
| By sending domain | Allow PhishGrid's envelope/From domains | Easy, but weaker on its own |
| By message header | Match PhishGrid's simulation header and bypass filtering | The strongest cross-gateway method where your account exposes a header |
| Advanced Delivery (Microsoft 365) | Register domains, IPs and simulation URLs in the phishing-simulation override | Microsoft's sanctioned path for third-party simulations |
| Bypass link/URL scanning | Stop URL rewriting / time-of-click protection for PhishGrid domains | Prevents scanner pre-fetches from registering as clicks (false positives) |
| Bypass attachment sandboxing | Exclude PhishGrid senders from attachment detonation | Only needed if your simulations use attachments |
Because the list is dynamic
- Re-check before every campaign. Open Settings → IP & Domains and confirm your whitelist still matches; add any newly listed domain or IP before launching.
- Prefer IP- and header-based rules. They survive domain changes better than a static domain list.
- Don't hardcode. Avoid baking a fixed list into permanent rules without a review reminder — dynamic values drift.
Verify it worked
- Send a small test campaign (5–10 users) before launching organisation-wide.
- Confirm emails arrive in the Inbox (not Spam/Junk/Promotions).
- Confirm a click is recorded correctly in PhishGrid (not pre-triggered by a scanner).
- If anything fails, see Emails Not Being Received — Troubleshooting Guide.