HowTo: Allow-List CyberHoot’s Domain Name and IP Addresses – Google Workspace
New CyberHoot businesses need to allow our training and phishing emails to reach their user’s inboxes directly. This article describes the two steps needed to make this happen.
Note: Google WOrkspace does not allow Allow-Listing by IP Address for individual IPs, only the entire domain.
7. Click Save.
Important Note:If you’re using a 3rd party SPAM provider you will need to Allow-list the domain and/or IP Address in that solution which filters all email before forwarding it to Google Mail accounts.
Part 2: Add CyberHoot’s IP addresses as Inbound Gateways
This method of allow-listing is to prevent the following Google banners from appearing in your user’s inbox when they receive a simulated phishing test from CyberHoot:
This message seems dangerous
Be careful with this message
We have found that this process exempts CyberHoot simulated phishing emails from the Gmail banner warnings. However, this is not documented by Google as an allow-list recommendation.
Under Apps > Google Workspace > Gmail > Spam, Phishing, and Malware, click on Inbound Gateway.
Configure the Inbound gateway using the settings below:
Gateway IPs Add CyberHoot’s IP addresses. Click here for the list of updated IP addresses.
IMPORTANT: Leave the Reject all mail not from gateway IPs option unchecked. If this is checked, all email will stop flowing to your client.
Check Require TLS for connections from the email gateways listed above.
Message Tagging Enter text for the Spam Header Tag that is unlikely to be found in a PST email. This field is required.
Example: kzndsfgklinjvsdnfioasmnfroipdsmfs
Select the Disable Gmail spam evaluation on mail from this gateway; only use header value option.
What This Script Does Configures Microsoft 365 to allow CyberHoot phishing simulation emails to bypass security filters while maintaining protection for real threats. It handles two critical configurations: Advanced Delivery – Allows CyberHoot simulation emails through spam/phishing filters Safe Links – Prevents Microsoft from rewriting/clicking simulation URLs (eliminates false click reports) Prerequisites…