Follow the steps below to allow NINJIO training messages and PHISH3D simulations through Proofpoint.
Before you begin: Open the NINJIO Allowlisting Guide. Use it for the current NINJIO SMTP IP addresses and domains referenced below.
Important: Proofpoint Essentials and Proofpoint Enterprise use different administration consoles and policy models. Complete the section that matches your Proofpoint product. Do not create broad sender-domain or global security bypasses.
Proofpoint Essentials
1. Add NINJIO to the Organization Allowlist
- Sign in to the Proofpoint Essentials administrator portal.
- Go to Security Settings > Email > Allowlist.
- In the legacy interface, go to Security Settings > Email > Sender Lists and use the Safe Sender list.
- Confirm you are editing the Organization allowlist, not an individual user or group list.
- Add each current NINJIO SMTP IP address from the NINJIO Allowlisting Guide.
- If the field requires CIDR notation, enter each address as an individual
/32range.
- If the field requires CIDR notation, enter each address as an individual
- Save the changes.
2. Exclude NINJIO URLs from URL Defense
- Go to Security Settings > Malicious Content > URL Defense.
- Locate the URL Defense exception or safelist settings.
- Under Exclude URLs that contain specified domains/IP addresses, add the current NINJIO domains from the NINJIO Allowlisting Guide.
- Save the configuration.
3. Allow attachment-based simulations
- Open the Proofpoint controls for Attachment Defense.
- If your tenant provides an Attachment Defense Safe Sender List, add the current NINJIO SMTP IP addresses.
- Review any customer-created attachment filters and exclude NINJIO test traffic where needed.
- Save the configuration.
Note: Some executable, script, malware, or prohibited file-type controls cannot be bypassed. If Proofpoint blocks a simulation attachment at one of these controls, use a supported PHISH3D attachment type or contact Proofpoint Support.
4. Configure the downstream email platform
Proofpoint allowlisting does not automatically bypass protections in Microsoft 365, Exchange, or Google Workspace. Complete the applicable downstream configuration in the NINJIO Allowlisting Guide.
If Proofpoint Essentials is integrated with Microsoft 365 through Proofpoint's MX integration, retain the Proofpoint-created connector and bypass rule unless your Proofpoint administrator directs otherwise.
5. Test the configuration
- Allow several minutes for the changes to take effect.
- Send a test to one or two authorized recipients.
- Confirm the message reaches the Inbox.
- Confirm PHISH3D links are not rewritten and click tracking behaves correctly.
- Confirm attachment-based simulations arrive as expected.
- Review the Proofpoint message log and verify the Organization Allowlist and applicable security exceptions matched.
Proofpoint Enterprise / Email Protection
1. Add NINJIO to the Organizational Safe List
- Sign in to the Proofpoint Enterprise Admin Console.
- Go to Email Protection.
- Under Spam Detection, select Organizational Safe List.
- Select Add.
- Create an entry for each current NINJIO SMTP IP address using the sender-IP or sender-host filter available in your Proofpoint version.
- Save the changes.
If your tenant requires CIDR notation, enter each NINJIO SMTP IP address as an individual /32 range. Do not substitute a broad domain allowlist if your version uses a different sender-IP field.
2. Configure URL Defense exceptions
- Go to Email Protection > Targeted Attack Protection > URL Defense.
- Open URL Rewrite Policies.
- Open the applicable inbound rewrite policy and its Exceptions.
- Add the current NINJIO SMTP IP addresses if your tenant supports source-IP exceptions.
- Add the current NINJIO PHISH3D landing domains from the NINJIO Allowlisting Guide.
- Save the changes.
3. Allow attachment and impersonation simulations
- Review the Proofpoint message details for any NINJIO simulation that is modified, tagged, held, or quarantined.
- Identify the specific Attachment Defense, impersonation, warning-banner, or related rule that acted on the message.
- Create the narrowest supported exception using the current NINJIO SMTP IP addresses and the applicable internal recipients.
- Save the changes.
Proofpoint Enterprise controls and entitlements vary by deployment. If your console does not provide a narrowly scoped exception for the control acting on the message, contact Proofpoint Support rather than disabling the control globally.
4. Configure the downstream email platform
Complete the applicable Microsoft 365, Exchange, or Google Workspace configuration in the NINJIO Allowlisting Guide.
5. Test the configuration
- Send a test to one or two authorized recipients.
- Confirm the message reaches the Inbox.
- Confirm PHISH3D links remain unmodified and click tracking behaves correctly.
- Confirm attachment-based simulations arrive as expected.
- Review the Proofpoint message log, sender-list match, URL Defense status, and other applied controls.
Troubleshooting
- Sender allowlist does not match: Confirm Proofpoint sees the original NINJIO connecting IP and check for conflicting user or group Blocklist entries or custom filters.
- Message is still quarantined or rejected: Identify the Proofpoint module that acted on the message and review DNS authentication, attachment, impersonation, malware, and other security results.
- Links are rewritten or pre-clicked: Confirm the destination is included in the URL Defense exception and check downstream Microsoft Defender Safe Links or other security scanners.
- Attachments are removed or blocked: Check whether Attachment Defense, anti-virus, a prohibited extension, or a custom filter caused the action.
Anti-spoofing failures
Do not add a broad anti-spoofing exception as part of the standard allowlisting configuration. If Proofpoint quarantines NINJIO mail for SPF, DKIM, or DMARC, preserve the original message headers and Proofpoint log details, verify the sender against the current NINJIO Allowlisting Guide, and contact NINJIO Support if needed.
Comments
0 comments
Article is closed for comments.