This article is a reference to CyberHoot’s mail relay IP Addresses and Domain names. The process of allowing phishing tests through to your end users inboxes is dependent upon your mail and spam filters. CyberHoot provides instructions and scripts on bypassing Microsofts Spam, Clutter, and Junk filters as well as adding our mail domains to the safe senders lists.
Please note that if you are using multiple filters in series, you will also need to set up X-Headers in addition to allow lists to deliver email to your end users. You may wish to run powershell scripts we have prepared to make your life easier.
CyberHoot assignments are delivered via email. Currently, all assignments flow through AWS SES, as such, there is no need to create an allow list as AWS SES reputation is excellent, but if you choose to, you can add our domain name and the following IP addresses below to the allow list.
If you are planning on sending traditional (attack-based) Phishing Tests to your clients and prospects, you will need to enable all of CyberHoot’s Email Relays shown below:
| DNS DOMAIN Names: | IP Addresses: |
|---|---|
| docunotice.com | 23.20.251.170/32 |
| messagecenters.net | 52.7.191.238/32 |
| securedinbox.net | 52.6.6.155/32 |
| notificationhub.net | 18.213.175.22/32 |
| secure-access.info | 18.210.65.168/32 |
| login-updates.com | 54.159.125.85/32 |
| updateportals.com | 54.225.129.23/32 |
| accountverifies.com | 3.234.113.11/32 |
| auth-check.page | 54.175.87.114/32 |
Looking for a downloadable copy of the table above in CSV format?
And here we have a comma separated list with just the domain names:
docunotice.com,messagecenters.net,securedinbox.net,notificationhub.net,secure-access.info,login-updates.com,updateportals.com,accountverifies.com,auth-check.page
Another list, this time just the IP addresses:
23.20.251.170/32,52.7.191.238/32,52.6.6.155/32,18.213.175.22/32,18.210.65.168/32,54.159.125.85/32, 54.225.129.23/32,3.234.113.11/32,54.175.87.114/32
Note: All phishing test domains listed above resolve to 54.156.140.113, a CyberHoot, LLC operated AWS load balancer. No allowlisting of this address is required. It is documented here for attribution, in case it appears in your security tooling or in a third party threat report.
How to Allow-List in Barracuda SPAM Gateway and Cloud Solution
How to Allow-List in your own Personal Gmail Account
How to Allow-List in your Google Workspace
How to Allow-List in Microsoft’s M365
How to Allow-List in ProofPoint
How to Allow-List in Sophos Central (Website Management)
How to Allow-List in Microsoft O365 – Avanan
How to Allow-List in Google Workspace – Avanan
Powershell script for avoiding SPAM, Clutter, Junk in M365.
Powershell script for adding CyberHoot’s phishing domains to Safe Senders List
How to Allow-List in MailProtector
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and...
Read more
Author: Craig Taylor I cannot visit a coffee shop, go for a round of golf, have a friendly conversation with...
Read more
AI tools moved into our everyday work-life incredibly fast! Someone on your team writes an email with ChatGPT....
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
