Skip to main content

How do I whitelist in Proofpoint?

K
Written by Karthek S
Updated over a week ago

If Proofpoint Essential's spam filtering or Proofpoint Enterprise's Allowlist is part of your setup, whitelisting Right-Hand enables our simulated phishing test emails and training notifications to be delivered to your end users.

For whitelisting in Proofpoint, refer to the external software's guidelines. If you encounter any issues, we recommend you to contact Proofpoint directly for specific instructions.

Whitelisting in Proofpoint Essentials

Add IPs to Safe Senders

  1. Log in to your Proofpoint Essentials admin console.

  2. Navigate to:​ Security Settings > Email > Sender Lists​

  3. In the Safe Senders section, add Right-Hand’s IP addresses.

  4. Click Save.

Whitelisting in Proofpoint Enterprise

Add IPs to the Organizational Safe List

  1. Log in to the Proofpoint Enterprise Admin Console.

  2. Navigate to:
    Email Protection > Spam Detection > Organizational Safe List

  3. Click Add.

  4. In the "Global Safe List" window, enter:

  5. Click Save Changes.

Add IPs to TAP URL Defense (If Used)

If you use Targeted Attack Protection (TAP) and URL Defense is enabled, whitelist the RH IPs to avoid URL rewriting:

  1. Navigate to:
    Email Protection > Targeted Attack Protection > URL Defense > URL Rewrite Policies

  2. Scroll to the Exceptions section.

  3. Add the IP addresses used by Right-Hand.

  4. Click Save Changes.

Prevent Emails from Going to Spam or Quarantine

  1. In the Admin Console, go to:
    Email Protection > Spam Detection > Organizational Safe List

  2. Add the hostnames or IP addresses from Right-Hand.

  3. This ensures the emails aren’t marked as spam or quarantined.

Advanced Whitelisting

Use these advanced steps if you're doing phishing simulations and want fine-grained control with Proofpoint’s custom policy routes.

Step 1: Create a Custom Policy Route (Mandatory)

This identifies phishing emails based on the sender's IP.

  1. Navigate to: System > System > Policy Routes

  2. Click Add and name the route:
    Right-Hand_Phishing

  3. Add Condition:

Step 2: Add Custom Spam & Phish Rules

These rules stop the simulation emails from being flagged as spam or phishing.

Go to: Email Protection > Spam Detection > Custom Rules

Create the following two separate rules:

Rule 1:

a. Right-Hand_Spam_Safelist

  • Condition: Policy Route equals Right-Hand_Phishing

  • Disposition: Classify as Not Spam

Rule 2:

b. Right-Hand_Phish_Safelist

  • Condition: Policy Route equals Right-Hand_Phishing

  • Disposition: Set Classifier Score > Phish > 0

Step 3: Bypass SMTP Rate Limiting

Add the RH's IP address to avoid delivery delays.

  1. Navigate to: Email Firewall > SMTP Rate Control > Non-throttled Hosts

Step 4: Skip IP Reputation (PDR) Checks

Skips IP reputation (PDR) checks for simulation emails, preventing blocks like "554 Blocked" while still allowing other security filters to apply.

  1. Go to: Email Protection > Spam Detection > Reputation Service > Settings

  2. Under Disable For Any Of, add Right-Hand_Phishing.

💡 Alternatively, if you already have a pdrsafe policy route, just add Right-Hand’s IPs to it and make sure it’s included in Disable For Any Of.

Step 5: Bypass TAP Attachment Defense (If Used)

This allows simulation attachments (like PDFs or ZIPs) to arrive unmodified.

  1. Go to: Email Protection > Targeted Attack Protection > Attachment Defense > Settings

  2. Enable: ​Disable processing for selected policy routes

  3. Select: Right-Hand_Phishing

Step 6: Exclude from Traffic Stats (Optional)

This keeps simulation traffic out of analytics/stats.

  1. Go to: ​System > System > Settings > Send Feedback from Agent Directly

  2. Add Right-Hand_Phishing to Disable processing for selected policy routes.

Step 7: Bypass Antispoofing (Optional)

If simulation emails are being blocked due to spoofing your own domain:

  1. Go to: ​Email Firewall > Rules

  2. Edit the pp_antispoof rule.

  3. Move Right-Hand_Phishing to Disable.

If Proofpoint-related steps are unclear or unsupported in your current setup, reach out directly to Proofpoint Support for detailed guidance.

Did this answer your question?