PhishProof Prerequisites

Written By Marissa Fegan (Super Administrator)

Updated at September 11th, 2025

Table of Contents

To ensure our simulated phishing campaigns and training notifications reach your users, it's essential to add our IP addresses, domains, and URLs to your allow list in your email security and network filters (IDS, firewall, client-side email filters, third-party Cloud email filters). This guide provides the prerequisites and instructions to do just that. We've tailored the process for your specific environment, with dedicated sections at the bottom of the page for organizations using only Microsoft Email Services, Microsoft Email Services with a third-party cloud filter (such as VIPRE Email Security Cloud), or VIPRE Email Security Cloud exclusively

We will be sending simulated phishing emails from outside your network. Notifying your IT department and ensuring successful email delivery is essential by completing the tasks listed below.

Add Exceptions for Phishing Simulations

There are two options for routing PhishProof emails to your organization. Select the appropriate tab below for details. 

VIPRE Recommends

If your organization uses Microsoft 365 as your email platform, we strongly recommend using the Direct-to-Inbox option below.

 

Conventional Email Delivery

The following lists have been formatted for easy copying from here and pasting into a CSV for importing.

Sending IP Addresses used for email delivery

69.72.47.208
69.72.47.209
69.72.47.21
69.72.47.210
69.72.47.211
69.72.47.3
69.72.47.30
69.72.47.31
69.72.47.56
159.135.234.148

159.112.248.122

PhishProof Landing Page and Template Domains

*.phishproof.com

accountsecurity.online
amznbks.com
bankameriica.com
certifyjob.com
clickweb.solutions
faceboookfriendster.com
filescanners.org
formsmail.com
funitgames.org
googllesecurity.net
ibsbanks.com
mailsystems.online
securityadmin.net
securityalert.org
starrwood.net
systemadsmin.org
twitttersocialpage.com
upssite.com
uspostallservice.com
wallgreenspharm.com
web-access-alerting.com
boxfilesshare.com
docutransfers.com
employee-rewards.net
hr-rewardscenter.com
hq-administrators.com
itpatching-installs.com
corp-addmin.com
admin-tokenalert.com
sso-server.com
login-microsoft.com

SMTP Relay used by PhishProof smtp.mailgun.org
 
 

Direct-to-Inbox (DTI) - Microsoft 365 Only

If your organization uses an Integrated Cloud Email Security (ICES) solution, additional configuration may be required. Contact your vendor for additional assistance. 

 

 

The following lists have been formatted for easy copying from here and pasting into a CSV for importing.

IP addresses needed to configure Inbound Connector in Microsoft 365

If you have a dedicated instance of iLMS/PhishProof, or do not see your access URL listed below, contact Technical Support.

Region/Access URL IP Address for DTI Email Service

Asia 

https://asia.inspiredlms.com/

13.215.236.136

Europe 

https://europe.inspiredlms.com/

176.34.82.119

54.72.119.208

52.211.103.221

EMEA

https://emea.securityawarenesstraining.com/

34.253.128.215

54.72.119.208

52.211.103.221

North America

https://www.inspiredlms.com/

34.229.36.22

52.54.239.51

100.29.131.89

54.91.86.36

Partners

https://securityawarenesstraining.com/

54.156.131.219

52.54.239.51

100.29.131.89

54.91.86.36

Domains needed for allow-listing in your email security solution

PhishProof Landing Page and Template Domains

*.phishproof.com

accountsecurity.online
amznbks.com
bankameriica.com
certifyjob.com
clickweb.solutions
faceboookfriendster.com
filescanners.org
formsmail.com
funitgames.org
googllesecurity.net
ibsbanks.com
mailsystems.online
securityadmin.net
securityalert.org
starrwood.net
systemadsmin.org
twitttersocialpage.com
upssite.com
uspostallservice.com
wallgreenspharm.com
web-access-alerting.com
boxfilesshare.com
docutransfers.com
employee-rewards.net
hr-rewardscenter.com
hq-administrators.com
itpatching-installs.com
corp-addmin.com
admin-tokenalert.com
sso-server.com
login-microsoft.com

Important

Please navigate to PhishProof Direct-to-Inbox for complete details on how to configure DTI, including configuring an Inbound Connector in Microsoft 365 and configuring Mail Flow Rules. 

 
 
 

Requirements for organizations using Microsoft Email Services

 

Requirements for Organizations Using Microsoft Email Services AND Third-Party Secure Email Gateway (including VIPRE Email Security Cloud) - Not Required for DTI

 

Requirements for Organizations Using VIPRE Email Security Cloud - Not Required for DTI

 
 

These steps are not related to email delivery and should be followed regardless of whether or your organization uses DTI or Conventional Email Delivery.

The following action is needed to prevent Microsoft Defender SmartScreen from misidentifying safe PhishProof educational landing pages as malicious:

  1. Update Group Policy settings for SmartScreen

These steps are required only for Conventional Email Delivery.

If your organization uses Microsoft Email Services, the following configuration is required to ensure seamless email delivery and proper functionality of your phishing simulations.

  1. Configure Allow-Listing in Microsoft 365 Defender: Set exceptions in the Microsoft 365 Defender portal to allow simulated phishing emails to bypass filtering
  2. Bypass ATP Link and Attachment Processing: Create rules in Microsoft 365 to bypass Advanced Threat Protection (ATP) processing for links and attachments in simulated phishing emails
 

Additional configuration is required if your organization uses Microsoft Email Services AND a third-party secure email gateway (including VIPRE Email Security Cloud). Without these adjustments, email flow issues may occur.

Why Configuration is Needed: Due to intermediary routing, Microsoft 365 may not correctly recognize simulation emails as coming from PhishProof when using a third-party cloud filter.

  1. Create a Receive Connector in Office 365: A Receive Connector allows emails processed by your third-party filter to enter Microsoft's email service securely
  2. Enable Enhanced Filtering for the Receive Connector in Exchange Online: This ensures that Microsoft recognizes emails routed through your third-party filter as trusted

If your organization uses VIPRE Email Security Cloud, you don't need to make any changes within your VIPRE account. However, you must still perform the allow-listings from the previous step on your organization's mail server.