Skip to main content
Skip table of contents

Setting up Spoof Intelligence to let simulated phishing emails through (Microsoft Defender)

When using Microsoft 365, it is possible that simulated phishing mails cause these warnings to appear:

  • This sender (example@example.com) is from outside your organization

  • We could not verify the identity of the sender. Click here to learn more.

  • The actual sender of this message is different than the normal sender. Click here to learn more

To prevent this warning, you can make use of the Tenant Allow/Block Lists feature in Microsoft 365. Doing so only takes a few minutes and we have prepared a step-by-step guide to make things easy for you.

  1. Log in to your email server portal with an administrator account.

  2. In the menu on the left, select Email & collaboration / Policies & rules and then select Threat policies.

  3. Under Rules, select Tenant Allow/Block Lists.

spoofint-lists.png
  1. Select the Spoofed senders tab and then select Add. A new dialog will open.

spoofint-domainpairs.png
  1. In the SoSafe Manager, navigate to Settings / Whitelisting and there select SoSafe mail servers. You must now determine whether your setup is based on individual IP addresses or an IP range. If an IP range is being used, follow the steps on the left. If individual IPs are used, follow the steps on the right.

spoofing-range.png

Manager view when using IP range

  1. Go back to the email server portal. In the dialog window you opened (see 4.), you must add the entries in the list provided below. Note that you can only add 20 entries at a time. You must therefore split up the list into 2 add/save procedures.

List of required entries, click to expand

*, 18.153.184.1
*, 18.153.184.2
*, 18.153.184.3
*, 18.153.184.4
*, 18.153.184.5
*, 18.153.184.6
*, 18.153.184.7
*, 18.153.184.8
*, 18.153.184.9
*, 18.153.184.10
*, 18.153.184.11
*, 18.153.184.12
*, 18.153.184.13
*, 18.153.184.14
*, 18.153.184.15
*, 18.153.184.16
*, 18.153.184.17
*, 18.153.184.18
*, 18.153.184.19
*, 18.153.184.20
*, 18.153.184.21
*, 18.153.184.22
*, 18.153.184.23
*, 18.153.184.24
*, 18.153.184.25
*, 18.153.184.26
*, 18.153.184.27
*, 18.153.184.28
*, 18.153.184.29
*, 18.153.184.30

  1. Under Spoof type, select Internal. Under Action, select Allow. Finish the process by selection Add.

spoofint-ips.png

Manager view when using individual IPs

  1. Go back to the email server portal. In the dialog window you opened (see 4.), you must add the IPv4 entries shown in the Manager. Following the example in the screenshot, these would be the required entries:
    *, 3.67.54.56
    *, 3.65.81.9

  2. Under Spoof type, select Internal. Under Action, select Allow. Finish the process by selection Add.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.