How to make sure Campaign E-Mails are received well
Campaign e-mails are deliberately built to look like real phishing, so your e-mail security stack will often catch them. Allowlist the values below so simulations reach the inbox and your results reflect real user behaviour rather than your spam filter.
AutoPhish sending details
Sending server / IP
- relay638.mysmtp5.com (45.84.100.46) – all e-mails are sent from this dedicated IP
FROM domains and addresses
- *@booyah.click
- *@qads.at
- *@trustlnk.eu
- *@linksecure.at
- *@securemail.info
- noreply@autophish.io (for transactional e-mails)
More FROM addresses and domains are coming soon.
Microsoft 365 / Exchange Online
Use the Advanced delivery policy. It is Microsoft's purpose-built mechanism for non-Microsoft phishing simulations and is preferable to mail flow rules, the Tenant Allow/Block List or the connection filter IP allow list.
- Open the Advanced delivery page in the Defender portal (Email & collaboration → Policies & rules → Threat policies → Advanced delivery).
- Select the Phishing simulation tab, then Add (or Edit if entries already exist).
- Domain: add booyah.click, qads.at, trustlnk.eu, linksecure.at and securemail.info.
- Sending IP: add 45.84.100.46
- Simulation URLs to allow: leave empty – this field is only needed for non-e-mail simulations such as Teams messages.
- Click Add, then Close.
A domain and an IP must both match, so please fill in both fields.
Once configured, EOP and Defender filtering is skipped for our messages, ZAP will not retro-remove them, Safe Attachments will not detonate, Safe Links will not block the click, and user reports will not raise incidents.
Good to know
- Required permissions: Security Administrator plus Organization Management in Exchange Online, or Global Administrator.
- Advanced delivery does not switch off Outlook's own Junk filter, the external-sender tag or the first-contact safety tip. Those are separate settings and can normally stay enabled.
- Safe Links still rewrites URLs. Please do not add our links to Do not rewrite the following URLs – it is unnecessary and can trigger spurious click alerts.
- If your MX record does not point to Microsoft (mail arrives via Mimecast, Proofpoint, Barracuda or similar first), allowlist us in that product as well and enable Enhanced Filtering for Connectors so Exchange Online sees our real sending IP.
Microsoft documentation
- Configure the advanced delivery policy for non-Microsoft phishing simulations
- Enhanced Filtering for Connectors
Google Workspace
Google has no dedicated phishing-simulation setting, so two steps are combined in the Admin console. Both live under Apps → Google Workspace → Gmail.
Step 1 – create an address list
- Go to Routing → Manage address lists → Add address list.
- Name it, for example AutoPhish Simulation Senders.
- Add our sending domains: booyah.click, qads.at, trustlnk.eu, linksecure.at, securemail.info and autophish.io. Enter them as plain domains – wildcard entries such as *@booyah.click are accepted by the interface but are not evaluated.
- Leave Require sender authentication enabled and Save.
Step 2 – bypass spam filtering and warnings
- Go to Spam, Phishing and Malware → Spam → Configure (or Add another rule).
- Select Bypass spam filters and hide warnings for messages from senders or domains in selected lists and choose the list from step 1.
- Save.
Pick that exact option: the shorter Bypass spam filters for messages from senders or domains in selected lists leaves Gmail's yellow warning banner visible.
Optional – add our sending IP
Under Spam, Phishing and Malware → Email allowlist, add 45.84.100.46. This setting always applies to the whole domain and cannot be scoped to an organisational unit.
If that IP is already present in your Inbound gateway configuration, adding it to the e-mail allowlist has no effect – Gmail resolves the true source IP differently. In that case rely on steps 1 and 2, and enable Automatically detect external IP in the inbound gateway settings so Gmail evaluates our real sending IP.
Good to know
- Changes can take up to 24 hours to apply, though usually less than an hour.
- The settings under Gmail → Safety (advanced phishing and malware protection) work independently of spam allowlists. If any of them is set to Quarantine, simulations can still be held back – set those to Keep email in inbox and show warning, or scope them per organisational unit.
Google documentation
- Allowlists, denylists and approved senders
- Add IP addresses to allowlists in Gmail
- Add custom spam filters to Gmail
- Set up an inbound mail gateway
Other e-mail security products
If a third-party secure e-mail gateway or endpoint product sits in front of your mailboxes, apply the same values there: sending IP 45.84.100.46 and the FROM domains listed above. Most vendors call this a safe sender list, an allow list or a phishing simulation exclusion.
Verify before you roll out
Run a small pilot campaign to a handful of test recipients first. If a message is still filtered, open the raw headers of the delivered or quarantined message, check the source IP and the authentication results, and send them to support@autophish.io – we will help you narrow it down.
Updated on: 06/08/2026
Thank you!