Skip to main content

Barracuda Allowlisting - AI

If you are using Barracuda Email Protection (including Premium or Premium Plus with AI features), you may need to configure allowlisting across multiple layers to ensure Boxphish phishing simulation…

Meg Bird
Updated by Meg Bird

If you are using Barracuda Email Protection (including Premium or Premium Plus with AI features), you may need to configure allowlisting across multiple layers to ensure Boxphish phishing simulation emails are delivered successfully. 

A standard IP exemption alone is no longer sufficient. Barracuda's AI and Intent Analysis features evaluate email content independently of gateway-level IP rules and may quarantine or retract Boxphish emails after they have been accepted at the gateway. 

Below is a short guide on how to allow Boxphish simulation emails through Barracuda.

  1. IP Address Exemption (Gateway) 
    • Log in to Barracuda Cloud Control 
    • Go to Email Security > Inbound Settings > IP Address Policies 
    • In the IP Blocking / Exemption section, add each Boxphish IP address listed on the Boxphish portal (Settings > Deliverability > Sending Information)
    • Set the Netmask to 255.255.255.255 
    • Set the Policy to Exempt 
    • Click Add and repeat for each IP 
  2. Intent Analysis Exemption 
    This prevents Barracuda from rewriting or flagging URLs in Boxphish simulation emails. 
    • Log in to Barracuda Cloud Control 
    • Go to Email Security > Inbound Settings > Anti-Phishing 
    • Under the Intent section, add Boxphish sending/phishing domains 
    • Set the Policy drop-down to Ignore 
    • Click Add and repeat for each domain 
  3. Impersonation Protection / Allowed Senders 
    This prevents Barracuda's AI engine from quarantining Boxphish emails based on content analysis. 
    • Log in to Barracuda Cloud Control 
    • Go to the Impersonation Protection / Sentinel settings 
    • Add Boxphish sender domains to the Allowed Senders list 
    • If applicable, also add the envelope-from domains 
  4. ATP Exemption (if simulations include attachments) 
    • Log in to your Barracuda Email Security Gateway web interface 
    • Go to the ATP Settings tab 
    • Add each Boxphish IP address to bypass attachment scanning 
  5. SPF Exemption (if spoofing your own domain) 
    Only required if Boxphish simulations are configured to spoof your organisation's domain. 
    • Log in to Barracuda Cloud Control 
    • Go to Email Security > Inbound Settings > Sender Authentication 
    • Add each Boxphish IP address to the SPF Exemptions table

If emails are still being blocked after completing all steps, check the Barracuda message log to identify which layer is quarantining the messages.

For further assistance, contact Boxphish support at support@boxphish.com. 

How did we do?

Contact