Allow EasyLlama Emails For Phishing Simulator (Microsoft Outlook)
To be sure you are set up for success with our Phishing Simulator, you need to allowlist our messaging in Microsoft 365. Without this, Microsoft Defender and Exchange Online Protection can block or quarantine our simulated phishing emails, and your learners will not receive them.
Microsoft has moved away from recommending mail flow rules alone for this use case. We now recommend setting up the Advanced Delivery policy in Microsoft Defender as your primary method, in addition to the Exchange mail flow rule below. If you only configure the mail flow rule, Defender can still scan, score, and quarantine our emails as high confidence phishing even though the rule matched.
Before you start :
You need the Security Administrator role active in Exchange Online. The Global Administrator role alone is not enough to access the Advanced Delivery settings.
If your organization does not have a full Defender for Office 365 subscription, go directly to security.microsoft.com/advanceddelivery after activating the Security Administrator role. You should see a Phishing Simulation tab.
Method 1: Set up the Advanced Delivery policy (recommended)
This is the method Microsoft currently recommends for third-party phishing simulators, and the method most likely to resolve quarantine issues.
- Sign in to security.microsoft.com/advanceddelivery using an account with the Security Administrator role.
- Select the Phishing simulation tab.
- Add a new entry for EasyLlama and enter the following:
- Sending domains:
- account-checker.com
- accountreset.cloud
- auth-identity.co
- auth-notify.tech
- easyllama.com
- login-alerts.co
- psm.easyllama.com
- reset-account.co
- secure-loginhub.com
- secureauthaccess.com
- verify-account.co
- Sending IP address: 134.128.67.27
- Save the policy.
Limit to be aware of: Microsoft's Advanced Delivery policy allows a maximum of 20 domains and 10 IP ranges. Our list above uses 11 domains and 1 IP address. If your organization uses other phishing simulation or security tools that also need entries in this policy, keep this ceiling in mind.
Method 2: Create an Exchange mail flow rule
Set this up in addition to the Advanced Delivery policy above. It is not a substitute for it.
- Log in to your Microsoft 365 Admin Center (admin.microsoft.com) using an administrator account.
- Navigate to the Exchange Admin Center.
- From the Admin Center home page, select Admin centers from the left-hand menu.
- Click on Exchange to open the Exchange Admin Center.
- Create a mail flow rule.
- In the Exchange Admin Center, find and select mail flow from the features pane on the left.
- Click on the rules tab in the top menu.
- Set up a new rule to bypass spam filtering.
- Click + to create a new rule.
- From the drop-down menu, select Bypass spam filtering.
- Configure the rule.
- Give the rule a name.
- Under Apply this rule if..., select the conditions to identify EasyLlama's phishing simulator emails:
- The sender's domains are the same list in Method 1 above.
- The sender's IP address is 134.128.67.27.
- Specify additional settings.
- Scroll down to add more conditions or exceptions if needed.
- Under Do the following..., set the action to Modify the message properties > Set the spam confidence level (SCL) to... > Bypass spam filtering.
- Save the rule.
Microsoft's reference article for this step: https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/use-rules-to-set-scl#use-the-eac-to-create-a-mail-flow-rule-that-sets-the-scl-of-a-message
Method 3: Add EasyLlama to your anti-spam allowed senders list
If simulations are still landing in quarantine after Methods 1 and 2, add EasyLlama's sending domains to your anti-spam policy's allowed senders or allowed domains list. This is a separate setting from the mail flow rule and from Advanced Delivery, and some organizations need all three configured.
- In the Microsoft 365 Defender portal, go to your anti-spam inbound policy.
- Add the sending domains listed in Method 1 to the allowed domains list.
- Save the policy.
Changes to anti-spam policies can take up to one hour to apply. Wait at least an hour before retesting.
Microsoft's reference article for this step: https://learn.microsoft.com/en-us/defender-office-365/create-safe-sender-lists-in-office-365#use-allowed-sender-lists-or-allowed-domain-lists-in-anti-spam-policies
Testing your setup
Single Email Test
To test just the email delivery mechanism:
- Set up a campaign. See Setting Up a Single Campaign.
- Under Emails and Trainings, click Manual Selection.
- A template sequence list should appear.
- Click Preview Template on any template.
- Use Send Test Email and enter the address to test.
Full Campaign Test
We recommend testing with a full campaign as well, not just a single test email. A single test email does not always trigger the same scanning path as a live campaign send, especially for EasyLlama to detect the phishing simulation result correctly (whether the person or the scanner “clicked” and “failed” a simulation).
- Set up a short, targeted single campaign with one or two test learners. See Setting Up a Single Campaign.
- Confirm the test learners receive the simulation email and that it is not quarantined.
- If it is quarantined, use the troubleshooting steps below before contacting us.
Troubleshooting
If emails are still being blocked or quarantined after completing all three methods above:
- Check Message Trace in the Exchange Admin Center to see the delivery path of the specific message. Look for whether it was marked as overridden by the phishing simulation rule, or whether it was still scanned and scored by Defender. https://learn.microsoft.com/en-us/exchange/monitoring/trace-an-email-message/message-trace-modern-eac
- Check your Advanced Delivery rule directly with PowerShell:
- Get-ExoPhishSimOverrideRule to view your current configuration
- Set-ExoPhishSimOverrideRule to update it
- Confirm the message was overridden, not just bypassed. A message that only matched a mail flow rule can still be scanned by Defender and quarantined. It needs to show as overridden by the Phishing Simulation rule specifically.
- Check for additional email security tools. If your organization uses a third-party email security tool in addition to Microsoft Defender, that tool needs its own allowlist entry for EasyLlama's sending domains and IP address. Whitelisting in Microsoft alone will not be enough.
If you are still seeing quarantine issues after working through all of the above, contact Support@easyllama.com with:
- The email security tools you use in addition to Microsoft Defender, and which version (Microsoft Defender for Office 365 Plan 1, Plan 2, or Microsoft Defender XDR)
- A screenshot or export of the quarantine log for the affected message
- Confirmation of which of the three methods above you have completed
For your reference, Microsoft's overview article on exceptions for phishing simulations: https://learn.microsoft.com/en-us/defender-office-365/secure-by-default#exceptions
If you have any issues, please reach out to Support@easyllama.com