CyberHoot’s Email-Relay IP Addresses, Domains, and Allow-list Articles

12th May 2026 | HowTo CyberHoot’s Email-Relay IP Addresses, Domains, and Allow-list Articles

Updated: May 12th, 2026

This article is a reference to CyberHoot’s mail relay IP Addresses and Domain names.  The process of allowing phishing tests through to your end users inboxes is dependent upon your mail and spam filters.  CyberHoot provides instructions and scripts on bypassing Microsofts Spam, Clutter, and Junk filters as well as adding our mail domains to the safe senders lists.

Please note that if you are using multiple filters in series, you will also need to set up X-Headers in addition to allow lists to deliver email to your end users.  You may wish to run powershell scripts we have prepared to make your life easier.

CyberHoot Training Assignments Relay:

CyberHoot assignments are delivered via email.  Currently, all assignments flow through AWS SES, as such, there is no need to create an allow list as AWS SES reputation is excellent, but if you choose to, you can add our domain name and the following IP addresses below to the allow list.

  • DNS Name:  cyberhoot.com
  • IP Addresses: 54.240.125.36/32 and 54.240.125.37/32

Phishing Test Mail Relays

If you are planning on sending traditional (attack-based) Phishing Tests to your clients and prospects, you will need to enable all of CyberHoot’s Email Relays shown below:

DNS DOMAIN Names: IP Addresses:
docunotice.com 23.20.251.170/32
messagecenters.net 52.7.191.238/32
securedinbox.net 52.6.6.155/32
notificationhub.net 18.213.175.22/32
secure-access.info 18.210.65.168/32
login-updates.com 54.159.125.85/32
updateportals.com 54.225.129.23/32
accountverifies.com 3.234.113.11/32
auth-check.page 54.175.87.114/32

Looking for a downloadable copy of the table above in CSV format?

And here we have  a comma separated list with just the domain names:
docunotice.com,messagecenters.net,securedinbox.net,notificationhub.net,secure-access.info,login-updates.com,updateportals.com,accountverifies.com,auth-check.page

Another list, this time just the IP addresses:
23.20.251.170/32,52.7.191.238/32,52.6.6.155/32,18.213.175.22/32,18.210.65.168/32,54.159.125.85/32, 54.225.129.23/32,3.234.113.11/32,54.175.87.114/32

*As of May 12th, 2026 all of CyberHoot’s Phish testing will be sent from these IP addresses.

Related Allow-Listing Articles:

How to Allow-List in Barracuda SPAM Gateway and Cloud Solution

How to Allow-List in your own Personal Gmail Account

How to Allow-List in your Google Workspace

How to Allow-List in Microsoft’s M365

How to Allow-List in Mimecast

How to Allow-List in ProofPoint

How to Allow-List in Sophos Central (Website Management)

How to Allow-List in Microsoft O365 – Avanan

How to Allow-List in Google Workspace – Avanan

Powershell script for avoiding SPAM, Clutter, Junk in M365.

Powershell script for adding CyberHoot’s phishing domains to Safe Senders List

How to Allow-List in MailProtector

How to Allow-List in BitDefender

How to Allow-List in DNS Filter

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

AI Found Your Weaknesses. Let’s Fix Them First.

AI Found Your Weaknesses. Let’s Fix Them First.

New benchmark data names MDASH and Claude Mythos Preview are the top AI agents finding zero-day vulnerabilities...

Read more
Your Identity Is Not Only a Front-Door Problem, It is an Internal Risk Too

Your Identity Is Not Only a Front-Door Problem, It is an Internal Risk Too

One Forgotten Password, Almost a Catastrophe A single Windows machine at a retail store location had a cached...

Read more
Why Your Clients’ Routers Are Now a National Security Conversation

Why Your Clients’ Routers Are Now a National Security Conversation

You now have five important reasons to start a router security conversation with your small business clients this...

Read more