Here you can see the domains and IP addresses that LibraCyber Phishing Tester uses to send campaign emails.
You must allow email and web traffic to and from these domains and related IPs on your email gateway, web proxy, firewall appliance, or anywhere else in your environment where email and web filtering is done.
You can also find out more about how Office 365 ATP Safe Link and Safe Attachments interact with Phish Threat V2.
This list updates when we add new IPs and domains.
IP addresses
Directory services
- 194.39.109.79
- 5.57.208.26
- 85.159.115.100
Sending services
- 94.237.24.12
- 209.227.220.90
- 194.21.34.110
Domain names
- a2a.email
- agenziadelleentrate.co
- applehb.com
- auditmessages.eu
- awazon.com.de
- awazon.eu
- awstrack.co
- bankfraudalerts.limited
- buildingmanagement.cloud
- corporate-realty.cloud
- courts-notices.com
- e-billinvoics.com
- e-documentsign.cloud
- e-faxsent.email
- e-recepts.co
- emailhubapp.com
- epromodeals.business
- facebok.me
- global-hr.company
- gmal.cloud
- go-vip.eu
- googl.download
- governoitaliano.co
- hr-benefits.center
- huawe.org
- libraesva.co
- linkedn.eu
- memberaccounts.center
- microsft.org
- myhr.center
- online-statements.center
- outlok.org
- payqal.co
- secure-alerts.agency
- secure-banks-alerts.com
- shippings-updates.com
- support-desk.co
- support-desk.us
- tax-official.co
- tolls-citations.cloud
- trackshipping.center
- trylinkedin.com
- voicemailbox.cloud
- phishingtester.com
- phishbrain.net
LibraCyber ESG Customers
All LibraCyber ESG customers that are using the LibraCyber Phishing Tester don't need to create any whitelisting rule, as these are managed automatically by LibraCyber ESG.
Microsoft 365 ATP
Microsoft 365 Defender Advanced Threat Protection (ATP) offers security features such as Safe Links and Safe Attachments.
ATP Safe Links can help protect the organization by providing time-of-click verification of web addresses (URLs) in email messages and Office documents. The ATP Safe Attachments feature checks to see if email attachments are malicious, and then takes action to protect the organization.
If LibraCyber Phishing Tester IP address and domain names are not included in the allow list, Office 365 executes the links.
If you are using Advanced Threat Protection (ATP) in your mail environment and have experienced false clicks or false attachment opens, it is because ATP has link processing and attachment processing rules that are causing this.
To ensure the proper execution of LibraCyber Phishing Tester with Microsoft 365, set up an exception for the phish threat in your Office 365 tenant. For instructions on how to set up these exceptions, see Microsoft documentation.
Other 3rd party mail scanning products
Similar to the above features in Office 365, other 3rd party mail security products may also apply their own scanning techniques to open links and attachments in emails as they are processed. If this is the case you may also receive reports indicating that your users have clicked links.
In such cases please ensure that the above IPs and domains are allowed within the 3rd party product.