Follow the steps below to allow NINJIO training messages and PHISH3D simulations through Mimecast.
Before you begin: Open the NINJIO Allowlisting Guide. Use it for the current NINJIO SMTP IP addresses and domains referenced in the steps below.
Important: Scope all Mimecast exceptions to NINJIO's current SMTP IP addresses and your internal recipients. Do not create unrestricted sender-domain or global security bypasses.
1. Create a Permitted Senders policy
- In the Mimecast Administration Console, go to Policies > Gateway Policies > Permitted Senders.
- Select New Policy.
- Configure:
- Policy Narrative: NINJIO - Permitted Sender IPs
- Permitted Senders Policy: Permit Sender
- Addresses Based On: Both
- Applies From: Everyone
- Applies To: Internal Addresses
- Enable / Disable: Enable
- Set Policy as Perpetual: Always On
- Policy Override: Enabled
- Bi-Directional: Disabled
-
Source IP Ranges: Enter each current NINJIO SMTP IP address as a single-host
/32range.
- Save the policy.
2. Create an Anti-Spoofing bypass
- Go to Policies > Gateway Policies > Anti-Spoofing.
- Select New Policy.
- Configure:
- Policy Narrative: NINJIO - Authorized Simulation Anti-Spoofing Bypass
- Select Option: Take No Action
- Addresses Based On: Both
- Applies From: Everyone
- Applies To: Internal Addresses
- Enable / Disable: Enable
- Set Policy as Perpetual: Always On
- Policy Override: Enabled
- Bi-Directional: Disabled
-
Source IP Ranges: Current NINJIO SMTP IP addresses as
/32ranges
- Save the policy.
3. Create a URL Protection bypass
- Go to Policies > Gateway Policies > URL Protection Bypass.
- Select New Policy.
- Configure:
- Policy Narrative: NINJIO - PHISH3D URL Protection Bypass
- Select Option: Select the URL Protect definition that applies to your inbound users
- Addresses Based On: Both
- Applies From: Everyone
- Applies To: Internal Addresses
- Enable / Disable: Enable
- Set Policy as Perpetual: Always On
- Policy Override: Enabled
- Bi-Directional: Disabled
-
Source IP Ranges: Current NINJIO SMTP IP addresses as
/32ranges
- Save the policy.
4. Create an Attachment Protection bypass
- Go to Policies > Gateway Policies > Attachment Protection Bypass.
- Select New Policy.
- Configure:
- Policy Narrative: NINJIO - Attachment Protection Bypass
- Select Option: Disable Attachment Protection
- Addresses Based On: Both
- Applies From: Everyone
- Applies To: Internal Addresses
- Policy Override: Enabled
- Bi-Directional: Disabled
-
Source IP Ranges: Current NINJIO SMTP IP addresses as
/32ranges
- Save the policy.
5. Create an Attachment Management bypass
- Go to Policies > Gateway Policies > Attachment Management Bypass.
- Select New Policy.
- Configure:
- Policy Narrative: NINJIO - Attachment Management Bypass
- Select Action: Disable Attachment Management
- Addresses Based On: Both
- Applies From: Everyone
- Applies To: Internal Addresses
- Policy Override: Enabled
- Bi-Directional: Disabled
-
Source IP Ranges: Current NINJIO SMTP IP addresses as
/32ranges
- Save the policy.
6. Create an Impersonation Protection bypass
- Go to Policies > Gateway Policies > Impersonation Protection Bypass.
- Select New Policy.
- Enter NINJIO - Impersonation Protection Bypass as the policy narrative.
- Select the Impersonation Protection definition that applies to your inbound users.
- Set Applies From to Everyone and Applies To to your internal recipients.
- Enable Policy Override.
- Enter the current NINJIO SMTP IP addresses as
/32ranges under Source IP Ranges. - Save the policy.
7. Add NINJIO domains to Managed URLs
- Go to Email Security > URL Protection.
- Select URL Tools > Managed URLs > Add Managed URLs.
- Set Override Type to Permitted.
- Set Match Type to Domain.
- Add the current NINJIO domains from the NINJIO Allowlisting Guide.
- Select Disable Rewriting For This Entry so PHISH3D links are not rewritten.
- Save the entries.
8. Configure recipient validation
Mimecast recipient validation is separate from the Permitted Senders policy. To avoid rejecting newly created Microsoft 365 users before they have synchronized into Mimecast, configure SMTP Call Forward for the applicable internal domain.
- Go to Users & Groups > Internal Directories.
- Open the applicable internal email domain and select Edit Domain.
- Under Check Inbounds, select Use SMTP Call Forward to check recipient addresses.
- Select the appropriate Microsoft 365 / Exchange Delivery Route for SMTP Call Forward.
- Save the domain configuration.
SMTP Call Forward validates recipients against Microsoft 365 / Exchange instead of relying only on Mimecast's synchronized directory. This allows newly created recipients to be validated before they appear in Mimecast directory synchronization.
Important: Exchange recipient filtering must be enabled for SMTP Call Forward. Do not use Accept Any Address as a NINJIO allowlisting workaround, because that disables recipient validation for the entire domain.
9. Configure your downstream email platform
Mimecast allowlisting does not automatically bypass protections in Microsoft 365, Exchange, or Google Workspace. Complete the applicable downstream steps in the NINJIO Allowlisting Guide.
10. Test the configuration
- Wait for the Mimecast policies to propagate.
- Send a test to one or two authorized recipients.
- Confirm the message reaches the Inbox.
- Confirm PHISH3D links open without being rewritten and clicks are recorded correctly.
- Confirm attachment-based simulations arrive as sent.
- Review Mimecast Message Tracking and verify the NINJIO policies matched the message.
Troubleshooting
- Invalid Recipient / 550 rejection: Confirm SMTP Call Forward is enabled for the applicable internal domain and points to the correct Microsoft 365 / Exchange delivery route. If the domain still relies on directory-based validation, run Sync All under Users & Groups > Directory Synchronization and verify the recipient appears in Mimecast.
-
Policy does not match: Confirm the connecting IP in Mimecast Message Tracking and verify each NINJIO IP was entered as a
/32range. - Message is still held or rejected: Review Blocked Senders, DNS Authentication, content policies, and any other Mimecast controls applied to the message.
- Links are rewritten or pre-clicked: Confirm the URL Protection bypass and Managed URL entries are applied.
- Attachments are modified or blocked: Confirm both Attachment Protection and Attachment Management bypasses are applied.
Comments
0 comments
Article is closed for comments.