Articles on: E-Mail Setup

How to make sure Campaign E-Mails are received well

Campaign e-mails are deliberately built to look like real phishing, so your e-mail security stack will often catch them. Allowlist the values below so simulations reach the inbox and your results reflect real user behaviour rather than your spam filter.


AutoPhish sending details


Sending server / IP



FROM domains and addresses


  • *@booyah.click
  • *@qads.at
  • *@trustlnk.eu
  • *@linksecure.at
  • *@securemail.info
  • noreply@autophish.io (for transactional e-mails)


More FROM addresses and domains are coming soon.


Microsoft 365 / Exchange Online


Use the Advanced delivery policy. It is Microsoft's purpose-built mechanism for non-Microsoft phishing simulations and is preferable to mail flow rules, the Tenant Allow/Block List or the connection filter IP allow list.


  1. Open the Advanced delivery page in the Defender portal (Email & collaborationPolicies & rulesThreat policiesAdvanced delivery).
  2. Select the Phishing simulation tab, then Add (or Edit if entries already exist).
  3. Domain: add booyah.click, qads.at, trustlnk.eu, linksecure.at and securemail.info.
  4. Sending IP: add 45.84.100.46
  5. Simulation URLs to allow: leave empty – this field is only needed for non-e-mail simulations such as Teams messages.
  6. Click Add, then Close.


A domain and an IP must both match, so please fill in both fields.


Once configured, EOP and Defender filtering is skipped for our messages, ZAP will not retro-remove them, Safe Attachments will not detonate, Safe Links will not block the click, and user reports will not raise incidents.


Good to know


  • Required permissions: Security Administrator plus Organization Management in Exchange Online, or Global Administrator.
  • Advanced delivery does not switch off Outlook's own Junk filter, the external-sender tag or the first-contact safety tip. Those are separate settings and can normally stay enabled.
  • Safe Links still rewrites URLs. Please do not add our links to Do not rewrite the following URLs – it is unnecessary and can trigger spurious click alerts.
  • If your MX record does not point to Microsoft (mail arrives via Mimecast, Proofpoint, Barracuda or similar first), allowlist us in that product as well and enable Enhanced Filtering for Connectors so Exchange Online sees our real sending IP.


Microsoft documentation



Google Workspace


Google has no dedicated phishing-simulation setting, so two steps are combined in the Admin console. Both live under AppsGoogle WorkspaceGmail.


Step 1 – create an address list


  1. Go to RoutingManage address listsAdd address list.
  2. Name it, for example AutoPhish Simulation Senders.
  3. Add our sending domains: booyah.click, qads.at, trustlnk.eu, linksecure.at, securemail.info and autophish.io. Enter them as plain domains – wildcard entries such as *@booyah.click are accepted by the interface but are not evaluated.
  4. Leave Require sender authentication enabled and Save.


Step 2 – bypass spam filtering and warnings


  1. Go to Spam, Phishing and MalwareSpamConfigure (or Add another rule).
  2. Select Bypass spam filters and hide warnings for messages from senders or domains in selected lists and choose the list from step 1.
  3. Save.


Pick that exact option: the shorter Bypass spam filters for messages from senders or domains in selected lists leaves Gmail's yellow warning banner visible.


Optional – add our sending IP


Under Spam, Phishing and MalwareEmail allowlist, add 45.84.100.46. This setting always applies to the whole domain and cannot be scoped to an organisational unit.


If that IP is already present in your Inbound gateway configuration, adding it to the e-mail allowlist has no effect – Gmail resolves the true source IP differently. In that case rely on steps 1 and 2, and enable Automatically detect external IP in the inbound gateway settings so Gmail evaluates our real sending IP.


Good to know


  • Changes can take up to 24 hours to apply, though usually less than an hour.
  • The settings under GmailSafety (advanced phishing and malware protection) work independently of spam allowlists. If any of them is set to Quarantine, simulations can still be held back – set those to Keep email in inbox and show warning, or scope them per organisational unit.


Google documentation



Other e-mail security products


If a third-party secure e-mail gateway or endpoint product sits in front of your mailboxes, apply the same values there: sending IP 45.84.100.46 and the FROM domains listed above. Most vendors call this a safe sender list, an allow list or a phishing simulation exclusion.


Verify before you roll out


Run a small pilot campaign to a handful of test recipients first. If a message is still filtered, open the raw headers of the delivered or quarantined message, check the source IP and the authentication results, and send them to support@autophish.io – we will help you narrow it down.

Updated on: 06/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!