HowTo: Whitelisting CyberHoot’s Mail-Relays in O365

High Level Instructions:

This HowTo video walks you through whitelisting CyberHoot’s Mail-Relay by either Domain Name or IP Addresses in Microsoft’s O365 environment.  This process is very similar whether you use the domain names shown below or the IP addresses in O365.

CyberHoot Training Assignments Relay:

CyberHoot assignments are delivered through a single mail relay.  This is all you need to allow in O365 (white-list) if you are only sending training assignments, policies, or surveys to targeted email accounts.

 

Phishing Test Mail Relays

If you are planning on sending Phishing Tests to your clients and prospects, you will need to have them white-list all four of the Email Relays shown below either by Domain Name OR IP Address (don’t do both).

DNS Name: 

  1. relay.lockout-appie.com
  2. relay.admin-googie.support
  3. relay.server33-arnazon.com
  4. relay.admin-rnicrosoft.services

IP Address: 

  1. 108.52.60.135
  2. 108.52.60.139
  3. 108.52.60.140
  4. 108.52.60.142

While List the Entire Network for CyberHoot:

Optionally, you can white-list the entire network in one fell swoop using this network address:
  • 108.52.60.128/28

White-listing Using a Domain Name in O365

Whitelisting by IP Address in O365

Detailed Instructions with Screen Shots:

To whitelist emails sent from CyberHoot for training or phishing testing in your Office 365 environment, follow these steps below:

  1. Log in to your mail server Admin portal. Then, navigate to Admin centers > Exchange.
  2. Select mail flow and click on the + sign located in the top-left.
  3. Select Bypass Spam Filtering… from the drop-down. This will open the new rule screen.
  4. Give the rule a name, such as Training Notifications Bypass Clutter and Spam Filtering by Email Header.
  5. Select Apply this rule if… and then choose The sender… > domain is from the drop-down. This will open the specify domain screen.
  6. Enter mail.cyberhoot.com on the specify domain screen and click the + sign. Then, click the OK button.
  7. Alternatively, you can Whitelist by IP or Network if you select the option right above “Domain Is” by selecting “IP address is in any of the following ranges or exactly matches” and end these IP Addresses or address range:
 
108.52.60.132/32  <== Phishing
108.52.60.135/32  <== Phishing
108.52.60.138/32  <== this is for Training Assignments
108.52.60.139/32  <== Phishing
108.52.60.140/32  <== Phishing
108.52.60.142/32  <== Phishing
CyberHoot’s network rande is 108.52.60.128/28
 

8. Verify the Do the following… field is set to Set the spam confidence level (SCL) to… and Bypass spam filtering is set on the right.

9. Scroll down the screen to the Match sender address in message option. Here, select Envelope from the drop-down.

10. Click the Save button. 

 
Share this on your social networks. Help Friends, Family, and Colleagues become more aware and secure.