Whitelisting PhishGuard Email Header in Exchange 2013 or 2016

Whitelisting PhishGuard Email Header in Exchange 2013 or 2016

Whitelisting PhishGuard Email Header in Exchange 2013 or 2016


The following is the process of whitelisting phishing email headers on Exchange 2013 or 2016 platforms.

Mail filters will sometimes block the emails our servers send, but there is a way to resolve this issue with whitelisting. Whitelisting allows for phishing emails sent from PhishGuard to bypass any mail filters or junk, spam and clutter folders. We do recommend however to whitelist by IP if possible (for example if you are using a cloud security system). When whitelisting by IP is not applicable, whitelisting by header is an effective way to make sure that phishing emails are delivered. Below we will show you how to set up header rules for Spam and Clutter as well as the Junk folder. 


Bypassing Clutter and Spam Filtering by Email Header (Exchange 2013 or 2016)

  1. Log into your mail server admin portal and select Exchange under Admin center.
  2. Click mail flow from the left-hand menu and then click the + sign and select Bypass spam filtering… from the drop-down.

  3. In the new rule window, give the rule a name, such as "Bypass Clutter & Spam Filtering by Email Header".
  4. From the Apply this rule if… drop-down menu,  select A message header... then includes any of these words.
  5. On the right side of that rule, you will see *Enter text... and *Enter words...
  6. Click *Enter text... and type in PhishGuard header and its value.

  7. Next, under Do the following… ensure that this field is set to Set the spam confidence level (SCL) to… and Bypass spam filtering is set on the right side.
  8. Add a second action by clicking the add action button under Do the following….
  9. From the drop-down menu, select Modify the message properties then set a message header 
  10. Click the first *Enter text.... and type  X-MS-Exchange-Organization-BypassClutter then click the second *Enter text... and type true.
  11. Review all settings to make sure they are correct.
Once you have completed this setup please allow time for the new rule to propagate. Then, set up a test phishing campaign for yourself or a small group to test out your new whitelisting rule. 


    • Related Articles

    • Whitelist by Email Header in Exchange 2010

      Whitelist by Email Header in Exchange 2010 This article will cover how to allow phishing emails to reach the targets by whitelisting the Email Header in Exchange 2010 environment. If you're using a cloud-based spam filter, whitelisting by headers may ...
    • Whitelisting

      Welcome to PhishGuard Email Whitelisting! What Is Email Whitelisting? Whitelisting email addresses means adding the sender to the approved senders list, which will keep emails away from the spam folder. Whitelisting consists of many levels and may be ...
    • Whitelisting PhishGuard by Email Header in Google Workspace/Google Apps

      Whitelisting PhishGuard by Email Header in Google Workspace/Google App The below instructions will show you how to whitelist the phishing emails by email header in your Google Workspace (formerly G Suite) environment. This setting is only recommended ...
    • Whitelisting PhishGuard IPs in Exchange 2013 or 2016

      Whitelisting PhishGuard IPs in Exchange 2013 or 2016 This article shows how to whitelist the phishing email servers in Exchange 2013 or 2016 environment (the process is the same for all mail servers mentioned). The general process can be summarized ...
    • Whitelisting PhishGuard in SonicWall

      Whitelisting PhishGuard In SonicWall Allowing emails coming in from PhishGuard list of IPs in SonicWall services will allow phishing targets to receive phishing emails if they are added in a phishing campaign. This is possible in SonicWall by adding ...