---
title: How do I safelist by IP Address in Exchange 2013, 2016, or Office 365?
description: The following details the process of safelisting our simulated phishing IPs on your Exchange 2013, 2016, or Office 365 platforms.
---

[Skip to content](https://support.hooksecurity.co/safelisting-by-ip-address-in-exchange-2013-2016-or-office-365#main-content)

English

Show submenu for translations

[Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new?hsLang=en) [Customer Portal](https://support.hooksecurity.co/tickets-view?hsLang=en)

[![Hook\_Logo (3)](https://support.hooksecurity.co/hs-fs/hubfs/Hook_Logo%20(3).png?width=150&height=113&name=Hook_Logo%20(3).png)](https://www.hooksecurity.co/welcome)

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)

Open main navigation

Close main navigation

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)
- English
  
  Show submenu for translations
- [Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new)
- [Customer Portal](https://support.hooksecurity.co/tickets-view)
- [Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

[Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.hooksecurity.co/?hsLang=en)
2. [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en)
3. [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)

# How do I safelist by IP Address in Exchange 2013, 2016, or Office 365?

## The following details the process of safelisting our simulated phishing IPs on your Exchange 2013, 2016, or Office 365 platforms.

Mail filters will sometimes block the emails originating from our IP, but there is a way to resolve this issue with safelisting. Safelisting allows for phishing emails sent from PhishingBox's IP to bypass any mail filters, junk, or spam and clutter folders. We recommend to safelist by IP if possible (for example if you are using a cloud security system). When safelisting by IP is not applicable, safelisting by header is an effective way to make sure that phishing emails are delivered.  Below we will show you how to set up an IP allow list as well as rules for Spam and Clutter and the Junk folder. 

In addition to safelisting, we strongly recommend that you also set up a connector in Office 365. This will prevent Portal emails from being blocked due to [Microsoft greylisting](https://answers.microsoft.com/en-us/msoffice/forum/all/how-to-prevent-greylisting/c0999c64-8c39-460d-9433-77f2c5a29894).

f you are using Exchange Server 2010, Exchange Server 2013, Exchange Server 2016, or Exchange Server 2019, you can set up an IP allow list using the command line. [See these instructions](https://docs.microsoft.com/en-us/powershell/module/exchange/antispam-antimalware/Add-IPAllowListEntry?view=exchange-ps) for more information.

If you do not wish to use the command line, follow the instructions below to set up an IP allow list using the exchange GUI.

1. Log into your mail server admin portal and click **Admin**.
2. Click on **Exchange**.
3. Click on **connection filter** (beneath **protection** heading).
4. Click on **connection filter** in the **protection** section, then click the ![pencil.png](https://support.phishingbox.com/hc/article_attachments/360092968951/pencil.png)![connection\_filter.jpg](https://support.phishingbox.com/hc/article_attachments/360092860992/connection_filter.jpg)
5. Click on **connection filtering**.
6. Under the **IP Allow list**, click the ![plusSign.png](https://support.phishingbox.com/hc/article_attachments/360092968891/plusSign.png) to add an IP address.
7. On the **Add allowed IP address** prompt, add [our IP addresses](https://support.phishingbox.com/hc/en-us/articles/360024055754) one at a time.
8. Click  **Save**. After setting up an IP allow list, you will want to set up a mail flow rule to permit our mail to bypass spam filtering and the clutter folder.
   
   Completed Connection Filtering
   
   ![completed\_connection\_filtering.PNG](https://support.phishingbox.com/hc/article_attachments/360093189312/completed_connection_filtering.PNG)
   
   **Sending IPs:**  **64.191.166.196** (US) or **64.238.34.10** (EU).  
   We also recommend safelisting the IP addresses below for improved deliverability:  
     - ```
       64.191.166.19664.191.166.197198.61.254.654.80.160.18964.191.166.19854.88.246.21254.240.70.10154.240.70.102
       ```
       
       #### **Bypassing Clutter and Spam Filtering**
       
       To ensure Portal messages will bypass your Clutter folder as well as spam filtering in Microsoft's EOP, follow the steps below.
       
           - Go to **Admin** \> **Mail** \> **mail flow \> rules**
       
       ![mailflowrules.PNG](https://support.phishingbox.com/hc/article_attachments/360092861052/mailflowrules.PNG)
       
           - Click the ![plusSign.png](https://support.phishingbox.com/hc/article_attachments/360092968891/plusSign.png) dropdown under the **Rules** tab. Select **Create a new rule**.
           - Give the rule a name, e.g. "Bypass Clutter and Spam Filtering by IP"
           - Click **More options**
           - Add the condition **Apply this rule if....**
           - Select **The sender** and select **IP address is in any of these ranges or exactly matches**.
           - Specify the sender IP addresses which can be found [in this article](https://support.phishingbox.com/hc/en-us/articles/360024055754), then click **OK**.
           - **Do the following…**  
                   1. Add a second action to **Do the following...** to **Modify the message properties \> Set a message header** to this value **‘X-MS-Exchange-Organization-BypassClutter’** then click **Enter text...** and set to **‘true’**
                   2. Add an additional action under **Do the following** to **Modify the message properties**. Here, click on **Set the spam confidence level (SCL) to...** and select **Bypass Spam Filtering**.
           - Click **Save**.
     - ![IPSPAMANDCLUTTER\_.gif](https://support.phishingbox.com/hc/article_attachments/360092988672/IPSPAMANDCLUTTER_.gif)

#### **Bypassing the Junk Folder**

Setting this rule will permit only simulated phishing emails from Portal to bypass the Junk folder to ensure users are receiving the simulated phishing emails in their inboxes.

*Note for Office 365 Environments:* *If you safelisted our email servers prior to February 2018, you must add an additional mail flow rule in your Office 365 Admin center. This rule can be found below.*

- Click the ![plusSign.png](https://support.phishingbox.com/hc/article_attachments/360092968891/plusSign.png) dropdown under the **Rules** tab. Select **Create a new rule**.
- Give the rule a name, e.g. "Bypass Junk by IP"
- Click **More options**
- Add the condition **Apply this rule if....**
- Select **The sender** and select **IP address is in any of these ranges or exactly matches**.
- Specify the sender IP addresses which can be found [in this article](https://support.phishingbox.com/hc/en-us/articles/360024055754), then click **OK**.
- Under **Do the following**, click **Modify the message properties** the **Set a Message Header.**
- Set the message header to this value: the header "**X-Forefront-Antispam-Report**" to the value "**SFV:SKI;**". 
    - *Note*: see [this article](https://docs.microsoft.com/en-us/office365/SecurityCompliance/anti-spam-message-headers) to learn more about this header.
- Under **Properties of this rule** set the priority to directly follow the existing rule (see Bypassing Clutter and Spam Filtering) set up for Portal safelisting.
- Click **Save**.  
  ![WVrB6d2L9y.gif](https://support.phishingbox.com/hc/article_attachments/4402242637716/WVrB6d2L9y.gif)
- After following the instructions above, you will want to [safelist by email header](https://support.hooksecurity.co/whitelisting-by-email-header-in-exchange-2013-exchange-2016-office-365?hsLang=en) as well.
  
  After completing the steps above, we recommend that you set up a small test phishing campaign to ensure our simulated phishing emails can reach your users. If the phishing emails can reach your test inboxes, you will know you have successfully safelisted our servers.
  
  ---
  
  **Allow time for propagation of these rules.**

- [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en#main-content)

    - [General](https://support.hooksecurity.co/getting-started?hsLang=en#general)
    - [General Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#general-safelisting)
    - [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)
    - [GSuite Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#gsuite-safelisting)
    - [Firewall/Spam Filter Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#firewall-spam-filter-safelisting)
    - [Creating Groups/Adding Targets](https://support.hooksecurity.co/getting-started?hsLang=en#creating-groups-adding-targets)
    - [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)
    - [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)
    - [Platform Settings](https://support.hooksecurity.co/getting-started?hsLang=en#platform-settings)
- [Hook Academy](https://support.hooksecurity.co/hook-academy?hsLang=en#main-content)

    - [Campaign Ideas](https://support.hooksecurity.co/hook-academy?hsLang=en#campaign-ideas)
    - [Industry Specific Campaigns](https://support.hooksecurity.co/hook-academy?hsLang=en#industry-specific-campaigns)
    - [Course Reviews](https://support.hooksecurity.co/hook-academy?hsLang=en#course-reviews)
    - [Mastering Reporting](https://support.hooksecurity.co/hook-academy?hsLang=en#mastering-reporting)
    - [Becoming Compliant](https://support.hooksecurity.co/hook-academy?hsLang=en#becoming-compliant)
    - [Suggest a Hook Academy Topic](https://support.hooksecurity.co/hook-academy?hsLang=en#suggest-a-hook-academy-topic)
- [Tests/Campaigns](https://support.hooksecurity.co/tests-campaigns?hsLang=en#main-content)

    - [Reseller Only](https://support.hooksecurity.co/tests-campaigns?hsLang=en#reseller-only)
- [School](https://support.hooksecurity.co/school?hsLang=en#main-content)

    - [3rd Party Integrations](https://support.hooksecurity.co/school?hsLang=en#3rd-party-integrations)
    - [Troubleshooting](https://support.hooksecurity.co/school?hsLang=en#troubleshooting)
    - [Branding](https://support.hooksecurity.co/school?hsLang=en#branding)
    - [Course](https://support.hooksecurity.co/school?hsLang=en#course)
    - [Students](https://support.hooksecurity.co/school?hsLang=en#students)
    - [Automations](https://support.hooksecurity.co/school?hsLang=en#automations)
- [Reports](https://support.hooksecurity.co/reports?hsLang=en#main-content)

    - [Generate Reports](https://support.hooksecurity.co/reports?hsLang=en#generate-reports)
- [FAQs](https://support.hooksecurity.co/faqs?hsLang=en#main-content)

    - [Troubleshooting](https://support.hooksecurity.co/faqs?hsLang=en#troubleshooting)
    - [Campaign of the Month](https://support.hooksecurity.co/faqs?hsLang=en#campaign-of-the-month)
- [Reseller Guide](https://support.hooksecurity.co/reseller-guide?hsLang=en)
- [Hook Security Updates](https://support.hooksecurity.co/hook-security-updates?hsLang=en)
- [Onboarding Guides](https://support.hooksecurity.co/onboarding-guides?hsLang=en)
- [Managed Services](https://support.hooksecurity.co/managed-services?hsLang=en)

- [Default HubSpot Blog](https://hooksecurity-6535385.hs-sites.com/blog)

[![Newsletter\_Logo-08](https://support.hooksecurity.co/hs-fs/hubfs/Newsletter_Logo-08.png?width=250&height=59&name=Newsletter_Logo-08.png "Newsletter_Logo-08")](http://hooksecurity.co)

Proudly Headquartered in Lakeland, Floirda

<https://www.linkedin.com/company/hooksecurity>

Copyright © 2026, Hook Security Inc.