Phishing Readiness simulation emails are delivered to Junk folder
search cancel

Phishing Readiness simulation emails are delivered to Junk folder

book

Article ID: 435526

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

This article explains a scenario where you are using Symantec Phishing Readiness simulation tool, However the simulation emails are delivered to your users Junk folder. 

Environment

Email Security.cloud

Cause

The main root cause of the issue is due to recipient using a different security vendor such as, Microsoft or Google which may classify such emails as spam or phishing despite whitelisting our Phishing Readiness simulation sending servers.

Resolution

In order to bypass other security vendors detection while using our Phishing Readiness simulation tool , we recommend the following steps to be performed :

1 - Whitelist these IP addresses and test :   

  • 54.163.249.247 (mx-a.blackfin.io)
  • 54.163.250.3 (mx-b.blackfin.io)

Note :  If your mail gateway and/or servers allow whitelisting by email header content, see how to whitelist specific email headers below.

2 - To whitelist emails that contain a special email header to indicate the email was sent as part of a phishing assessment.If your mail server support header-based whitelisting, you should allow delivery for all mail with the header: X-Blackfin-Assessment present. The value of this header will be unique for every assessment, but its presence indicates that the message was sent by the Symantec Security Platform.

3 - This last step should be considered as an alternative workaround for the above solutions, You can authorize the sending IP/ server in your SPF as some vendors may flag simulation emails as suspicious when an email fails authentication.  

 

Additional Information

Symantec Phishing Readiness FAQ: https://knowledge.broadcom.com/external/article/150736/symantec-phishing-readiness-faq.html