Setting Up Google Workspace Allow List

Allow Trend Vision One phishing simulations on Google Workspace.

  1. Copy the Phishing Simulation sending IPs.
    1. In Trend Vision One, go to Assessment > Security Assessment.
    2. Under Phishing Simulation Assessment click Start Assessmentand go to Step 3 Delivery.
    3. Under Allow List Settings click Settings to view and copy the Phishing Simulation sending IPs.
    Important:

    The sending IPs change over time. Check the list before launching a new campaign.

  2. Configure your Google Workspace allow list.
    Note:

    The following instructions are up-to-date as of December, 2022.

    For more information, refer to the Google Workspace Admin Help.

    1. Sign in to your Google admin console using an administrator account.
    2. Go to Apps > Google Workspace > Gmail > Spam, Phishing and Malware.
    3. In the Email whitelist section, paste the sending IPs separated by commas.
    4. (Optional) Disable Enhanced pre-delivery message scanning temporarily to ensure that the connection will not time out while reaching out to your server.
      Note:

      Trend Micro recommends you do not disable Enhanced pre-delivery message scanning until your campaign delivery rate hits 100%.

    5. Select Bypass spam filters for messages received from addresses or domains within these approved senders lists.
    6. Create a new list and call it Trend Micro Vision One Sender.
    7. Specify the Trend Vision One sender domain name and disable Require sender authentication.
    8. Click Save.
  3. (Optional) Add the Phishing Simulation server IPs to your inbound gateway.

    A warning banner may appear in your user's Gmail inbox when they receive your campaign emails. Complete the following this step to prevent this banner from appearing.

    1. Under Spam, phishing, and malware section, Add a new inbound gateway.
    2. Enter the Trend Vision One phishing simulation server IP addresses on the Gateway IPs.
    3. Select Message is considered spam if the following header regexp matches.
    4. Specify text for the spam header tag that is unlikely to be found in your phishing simulation email. (For example, "uyrghskfeoafkgoeonghgh".)
    5. Enable Disable Gmail Spam Evaluation for mail from this gateway using the header value option.
    6. Click Save.
    Note:

    Trend Micro recommends only enabling the above settings for the duration of your campaign.