Allow and Deny lists can be used to specify what happens when specific email addresses, domains, or IP addresses send emails to your organization.
Configurable Defend Admin Lists
There are three types of lists that can be configured in the Defend console:
- Allow list
- Emails from senders on this list are still scanned, but Defend will not add a dangerous (red) or suspicious (amber) teachable moment, even if the email is determined to be risky.
- Deny list
- Emails from senders on this list are still scanned, but will always be marked with a dangerous (red) teachable moment, regardless of Defend's analysis. Depending on your quarantine settings, these emails may also be sent directly to quarantine or purged.
- Productivity allow
- Prevents graymail (newsletters, bulk mail) and spam teachable moments from being added to emails, overriding both Defend's default filters and individual user preferences.
Configured entries for these lists are displayed with the date of their creation and the option to edit or delete them. Entries can be created on the Allow/Deny lists or Recent Emails pages.
Create Entries on the Allow/Deny List
To create entries on the Allow/Deny lists page, follow the steps below:
- Navigate to Allow/Deny lists.
- Select the Allow list, Deny list, or Productivity allow tab.
- Select Add item.
- Select to create the entry By Email Address or Sender, By Domain, or By IP Address.
- Complete the Rule Name and the Email Address / Fully Qualified Domain / IP Address Range fields.
- For email address and domain entries, use the drop-down menu to select the level of Required Authentication.
- Select to Hide External Banner if required.
- Select Save.
Create an Entry on the Recent Emails Page
To create an entry on the Recent Emails page, follow the steps below:
- Navigate to the Recent Emails page.
- Select an email entry. A side panel will open.
- Select the Add email to deny list or Add email to allow list button.
- An entry for the selected list will be automatically created for the email sender.