SAT - Curricula | Google - Simulated Phishing Campaigns - Allow List SAT Emails

The Allowlisting guide for Google

https://support.huntress.io/hc/en-us/articles/10962619872787-Allow-list-SAT-Emails-in-Google

Adding HSAT's IP addresses to Gmails Allowed list

Step 1:    Sign in to your Google Admin Console with an administrator account.

Step 2: Apps > G Suite > Gmail > Advanced settings

Tip: To see Advanced settings, scroll to the bottom of the Gmail page.

Step 3: On the left, select the top-level organization, which should be your company domain.

Step 4: Scroll to the Email allowlist setting in the Spam section. Or, in the search field, enter email allowlist.

Step 5: Enter the following IP addresses:

  • 18.205.140.116 (Phishing Server)
  • 168.245.36.66 (Training Server)

Step 6: At the bottom of the Gmail Advanced settings page, click Save.

Allowlisting Domains 

It's also important to Allow HSAT Phishing domains to prevent campaigns from ending up in your spam folder. You can access the full list of domains by logging into your Admin account. Select 'Settings' and then 'Phishing' from the vertical menu on the left-hand side to navigate to the 'Phishing' tab or visit our Generic Mail Server allowlisting Guide

  1. Go into your Admin console Home page, go to Appsand thenGoogle Workspaceand thenGmailand thenSpam, Phishing and Malware.
    Note: You might find this setting at Appsand thenGoogle Workspaceand thenGmailand thenAdvanced Settings.
  2. On the left, select an organizational unit.
  3. Point to Spam and click Configure.
    If the setting is already configured, point to the setting and click
    Edit or Add Another.
  4. For a new setting, enter a unique name or description.
  5. Check the Bypass spam filters for messages received from addresses or domains within these approved senders lists box.
  6. Click Use existing list or Create or edit list to select an existing list, or create a list of approved senders. To add a new list:
    1. Click Create or Edit list.
    2. Scroll to the bottom of Manage address lists and click Add address list.
    3. Enter a name for the new list.
    4. Click Add address.
    5. Enter email addresses or domain names. Use a space or comma between each entry.
    6. To receive mail from approved senders that don’t have authentication, turn off Authentication required for each user. This bypasses SPF and DKIM authentication.
    7. Click Save to save the new address list.
  7. (Optional) To turn on other spam filter options, check the box next to each option.
  8. At the bottom of the settings page, click Save to save the new spam setting.
  9. It can take up to 24 hours for your changes to take effect. You can track changes in your Google Admin console audit log.