Mimecast Allowlisting
To successfully allowlist our phishing and training-related emails when using Mimecast, you should create a new Permitted Sender policy to allow our phishing and training-related emails through to your users' inbox.
Permitting Simulations and Emails
To allow a specific static IP address (in this case, 23.249.219.118/32) through Mimecast, please follow these steps:
- Log in to your Mimecast Administration Console.
- Click the Administration toolbar button.
- Select the Gateway | Policies menu item.
- Select Permitted Senders from the list of policies displayed.
- Select the New Policy button.
- Select the appropriate policy settings under the Options, Emails From, Emails To, and Validity sections. For more information on these settings, see Mimecast's Configuring a Permitted Senders Policy article.
Web Security- Configuring Block or Allow List Policy (mimecast.com)
- In the Source IP Ranges field (Shown below), enter 23.249.219.118/32 again.
- Save your new policy.
Removing URL Protection
Mimecast scans URLs within emails to ensure they aren't malicious. This will sometimes cause clicks to be generated when the user hasn't clicked the simulation themselves.
Below is a short guide on how to remove this for Boxphish Simulations:
- Select the Gateway | Policies menu item.
- Select URL Protection Bypass
- Click 'New Policy'
- Complete the policy following the below settings:
- Save the Policy.
We hope you have found this guide useful. If there are any other areas you would like to be explained that have not been, or you have any questions or issues regarding this guide, please contact us at support@boxphish.com.