If you use an email security gateway -- such as Proofpoint, Mimecast, or Barracuda -- in front of your M365 environment, we recommend allowlisting by header rather than IP address. Since incoming emails pass through your gateway first, the visible sending IP is altered before reaching Microsoft. Allowlisting your unique NINJIO header provides a reliable alternative, as it is unique to your tenant and applies consistently across both training and simulated phishing emails.
The header can be found in every NINJIO tenant in the Whitelist section. This is found under the Settings module in the top right.
The header consists of two parts, the header identifier and alphanumeric string. Here is a sample:
X-Dcoya-Identification: 7e728247-989b-47f6-a8a8-248cb30aa197
Note: The underlined string in red is the alphanumeric string referred to later in this guide; it will differ from your specific customer string.
M365 Header Allowlisting
1. Login to the Microsoft Exchange Admin Center.
2. On the Admin Center left hand menu toolbar, click: Mail flow > Rules.
3. On the Rules page, you will either have an existing NINJIO Bypass Spam rule or will need to create one:
3a.) If you have an existing NINJIO Bypass Spam Rule, you’ll need to start by editing the rule conditions:
6a.) In Enter Text, put X-Dcoya-Identification
7a.) In Enter Words, put the alphanumeric part of the header string you can find on the NINJIO Platform from the Settings module > Whitelist.
8a.) Under the Do the following section, keep the setting as Modify the message properties then set the spam confidence level (SCL) to Bypass spam filtering (-1).
9a). Click Save
3b.) If you’re starting from scratch:
4b.) Start by clicking + Add a rule and selecting Create a new rule
5b.) Name your rule appropriately (ex: NINJIO Header Rule or NINJIO Bypass Spam)
6b.) In the Mail flow rule condition (Apply this rule if) text box, select The message headers… in the first drop down and Matches these text patterns in the second.
7b.) Under the rule drop downs, you’ll see a conditional statement of Enter text message header matches Enter words.
8b.) In Enter Text, put X-Dcoya-Identification
9b.) In Enter Words, put the alphanumeric part of the header string.
10b.) Under the Do the following section, select the first dropdown to be Modify the message properties then, in the second dropdown, set the spam confidence level (SCL) to Bypass spam filtering (-1).
11b.) Click Next > Next > Finish to create the rule
12b.) Now, you’ll need to ensure this rule is enabled. Once the rule has saved, select it again from your list of rules. It should be at the bottom.
13b.) With the rule open, toggle the switch from Disabled to Enabled. This will take a few moments – please keep the rule open until you see that the rule status has updated successfully:
Immediately after toggling:
After the rule has been enabled:
Congratulations! You’ve succeeded in creating a NINJIO header rule to facilitate delivery of our training and simulated phishing emails.
Please wait 12-24 hours for the rule to replicate throughout your environment and then run a test to ensure its working as intended before launching to a large quantity of users.
Comments
0 comments
Please sign in to leave a comment.