The Safelist/Blocklist tab in Browser Defender allows you to mark a domain or specific URL as trusted or dangerous for your entire company, even before an alert is generated. It also collects, in a single searchable table, the policies applied from this page. To access it, open Browser Defender > Setup from the side menu and select the Safelist/Blocklist tab.
Prerequisites
- Browser Defender active for your company: otherwise, Setup displays the activation screen instead of the Safelist/Blocklist tab.
- Platform Administrator role — this is the only permission that grants access to this page.
- Policies created here apply to your entire company: you cannot limit them to a single group or department (for group-specific settings, see the Setup > Preferences page).
Detailed Procedure
The tab contains a table of all configured policies, with a search box, filters, and an Add Policy button.
1. Add a policy for a domain
Click Add Policy. Leave the Domain / URL selector at its default value Domain and enter the domain.
Set one or more of the four policy fields (leaving them all at their default value is equivalent to creating no policy):
- Navigation — Default - Apply general settings · Block - Prevent navigation to this site · Trust - Allow navigation without restrictions.
- Downloads — Default - Apply general settings · Block - Prevent downloads from this site · Allow - Always allow downloads from this site.
- Phishing Detection — Default - Apply general settings · Trust - Disable phishing detection for this site.
- Password Reuse — No enforcement - user can decide how to handle alerts · Enforced - always alert on password reuse · Disabled - never alert on password reuse.
Click Save configuration, which is available only after you have changed at least one of the four fields from its default value.
2. Add a policy for a specific URL
Click Add Policy and set the Domain / URL selector to URL, then enter the complete URL. If you paste a complete URL while remaining at the default value Domain, it is automatically truncated to the main domain only when you exit the field.
NOTE: at this scope level, the Downloads field is not available — it appears only for Domain-scoped policies.
Set the other fields (Navigation, Phishing Detection, Password Reuse) as in the previous step, then click Save configuration.
3. Use Site Classification presets
Instead of setting the four fields individually, you can click a preset in the Site Classification section of the dialog to fill them all in one step. Manually changing a field after applying a preset cancels the preset, leaving a custom combination.
Safe sets all four fields to the most permissive (trusted) values.
Dangerous instead sets Navigation and Downloads to block, Password Reuse to enforced, and leaves Phishing Detection at its default value (Default - Apply general settings).
The preset fills in only the fields: click Save configuration to apply the policy.
4. Edit or delete an existing policy
In the table, click the pencil icon on a row to reopen its policy for editing, or click the trash icon to delete it.
WARNING: for rows with Domain scope, deletion asks for confirmation; for rows with URL scope, deletion is immediate, with no confirmation request. Verify the row carefully before clicking the trash icon.
A row showing only a grayed-out pencil icon, with no delete icon, indicates that the domain has no policy of its own: only one of its URLs does. Click the pencil to assign an explicit policy to the domain as well.
5. Filter and search existing policies
The Search box filters the table by domain name and does not find matches in the text of URL-scoped policies nested under a domain: to view them anyway, click the expand arrow on the corresponding domain row.
The chip filters — Navigation Blocked, Downloads Blocked, Phishing Whitelisted, Password Reuse Blocked, Fully Trusted — further restrict the list. When you select more than one, the table shows only rows that meet all active chips; Clear All resets both the chips and the search.
6. Open the same configuration from an alert page
From the Browsing Alerts, Dangerous Downloads, or Password Reuse pages, the Advanced options action available on a single alert opens this same dialog, already pre-filled with the domain or URL of the alert.
Expected Results
The table now updates immediately after each save or deletion, as do search and filter results. The effect for end users is not immediate, however: a policy becomes active the next time a user's browser checks that domain or URL, typically the next visit or download attempt. There is no separate propagation time to wait for.
Troubleshooting
| Symptom | Probable Cause | Solution | Escalation |
| The Save configuration button remains disabled | No field has been changed from its default value yet | Set at least one of the four fields (Navigation, Downloads, Phishing Detection, Password Reuse) | — |
| The Downloads field does not appear when editing an entry | The entry is URL-scoped: Downloads is available only for Domain-scoped policies | Move the entry to Domain scope, or set Downloads on the main domain | — |
| A row shows only a grayed-out pencil, with no delete icon | It is a "virtual" row: only a URL of that domain has its own policy, the domain does not | Click the pencil to assign an explicit policy to the domain as well | — |
| A policy does not seem to apply to a subdomain as expected | Domain policies apply to subdomains; a more specific policy takes precedence | Check whether a conflicting policy exists that is closer to the exact page in question | Support |