How to set up IP address-based whitelisting
1. Get the latest configuration manual:
-
Go to the client settings and open the Whitelisting menu item on the left side.
-
From there, you can download the whitelisting guide (“SoSafe Whitelisting Manual.pdf”) by clicking on the Read how to do it (1) button or email it to someone else by clicking on the Send (2) button.
2. Configure IP Address-Based Whitelisting
Use the following links to learn how to configure IP Address-Based whitelisting for Microsoft 365 and Google Workspace environments:
How to set up DMI whitelisting
Direct Message Injection (DMI) delivers simulated phishing emails directly to your users' inboxes using a secure connection. This method bypasses the need for IP whitelisting and provides faster, more reliable delivery than traditional SMTP.
Use the following links to learn how to configure DMI whitelisting for Microsoft 365 and Google Workspace environments:
How to test your whitelisting
Regardless of the whitelisting approach, because clients may have multi-layer security systems, it is crucial always to test that whitelisting is working as expected after the configuration.
To do so, send all test emails to an inbox from the company’s email domain, and then check to see if they were all received. In addition, the customer should check whether they are being forwarded to the micro-learning pages correctly when clicking the links.
-
Go to the client settings and open the Whitelisting menu item on the left side.
-
Click on the Send test emails (1) button, and enter an email address belonging to the company email domain.
-
On the Send test emails page:
-
To test the delivery of all templates, regardless of the configured trainings, select All phishing simulation templates.
-
b. To test specific templates, select Only templates used in active and scheduled trainings, and then select the trainings to test from the Scheduled and Active lists.
c. Enter an email address from the client email domain and click Send to test the template delivery based on the previous selection.
Confirm whitelisting
-
Open the test user’s email to validate that the Phishing Simulation emails are in the inbox.
-
Then click on the email body links to confirm access to the micro-learning pages (like the example from below).
-
After testing the Whitelisting delivery, click on Confirm successful whitelisting (1) to enable the toggle.
-
On the Confirm client whitelisting page, select both checkboxes and click Confirm.
Whitelisting troubleshooting
Whitelisting can be a complex topic, as email delivery behavior often depends on each company
To support a smoother experience, check this article for additional configuration options that allow to fine-tune the simulation delivery and end-user experience based on each company’s specific email and security stack.
You can check for any issues related to email delivery. However, it's important to note that emails that are redirected to spam folders due to incorrect whitelisting configurations will not generate a delivery error. For details on how to check email delivery issues, please refer to the FAQ.