Approve lists allow messages from approved senders to bypass IP-level filtering. Approve lists are not applied to your MTA, but you can set up additional approved or blocked senders, or perform additional filtering at your MTA. The trade-off for bypassing IP filtering is the additional resources that are needed to process, filter, and store the higher levels of spam messages that would otherwise have been blocked.
In the case of a standard reputation (Known Spam Source List) service lookup, the order of the evaluation hierarchy is:
-
Approved IP
-
Blocked IP
-
Approved country
-
Blocked country
For dynamic reputation (QIL) service lookup, the customer-defined “blocked policy lists” (IP, Country) are ignored and only the Approved lists are checked. Otherwise, the order of policy lookup (first IP, then country) is the same as for standard reputation (Known Spam Source List) service.
Avoid specifying overlapping CIDR ranges in the Approved and Block lists because the Block list might take priority over the Approved list.