IP/Domain Whitelist in Google Workspace

Note: Please get in touch with Sophos Professional Services if you require direct assistance with your specific environment.



Add IP addresses to the Email allowlist

To add the relevant IPs to the Email allowlist, do as follows:

  1. Sign in to your Google Admin Console.
  2. In the Admin console, go to Menu Apps Google Workspace Gmail Spam, Phishing and Malware.
  3. On the left, select your top-level organization. This is usually your domain.
  4. In the Email allowlist setting, click Edit Email allowlist.
  5. Add the relevant IPs to the allow list.
    Note: IPs are different for Sophos Phish Threat and Sophos Email.
  6. Click SAVE.

Add IP addresses and other settings in the Inbound gateway

To add the relevant IPs and other settings in the inbound gateway, do as follows:

  1. Sign in to your Google Admin Console.
  2. In the Admin console, go to Menu Apps > Google Workspace > Gmail Spam, Phishing and Malware.
  3. On the left, select your top-level organization. This is usually your domain.
  4. In Spam, Phishing and Malware, scroll to the Inbound gateway setting and click Edit inbound gateway.
  5. Turn on the inbound gateway settings.
  6. Configure Gateway IPs.
    1. Click Add, then add the Sophos Phish Threat or Email IPs to be allowed.
    2. Select Automatically detect external IP (recommended).
    3. Deselect Reject all mail not from gateway IPs.
    4. Select Require TLS for connections from the email gateways listed above.
  7. Configure Message Tagging.
    1. Select Message is considered spam if the following header regexp matches.
    2. In Regexp, enter a random text that is unlikely to match the header content. For example, 349834hjedjsfkds==-0sdfee3.
    3. Select Message is spam if regexp matches.
    4. Select Disable Gmail spam evaluation on mail from this gateway; only use header value.

  8. Click SAVE.

Add domains and configure spam settings

Note: This procedure is only applicable to Sophos Phish Threat.

To add the relevant domains and configure spam settings, do as follows:

  1. Sign in to your Google Admin Console.
  2. In the Admin console, go to Menu Apps > Google Workspace > Gmail > Spam, Phishing and Malware.
  3. On the left, select your top-level organization. This is usually your domain.
  4. In Spam, Phishing and Malware, scroll to the Spam setting and click CONFIGURE.
  5. Enter a name for the spam setting. For example, PT bypass.
  6. Select Bypass spam filters for messages from senders or domains in selected lists and do as follows:
    1. Click Create or edit list to create a new list for Sophos Phish Threat domains or modify an existing list.
      This will take you to the Manage address lists.
    2. Click ADD ADDRESS LIST.

    3. Enter a name for the address list. For example, Sophos PT.
    4. Add the domain names.
      For more information on the list of sender domains, see Sending domains and IPs.
    5. Turn the authentication requirement off for all the domains, then click SAVE.
    6. Go back to the Spam settings page.
    7. Click Use existing list and select the list created for Sophos Phish Threat.
  7. Select Bypass spam filters and hide warnings for messages from senders or domains in selected lists and do as follows:
    1. Click Use existing list.
    2. Select the lists you created for Sophos Phish Threat.
  8. Click SAVE.

Add IP addresses and turn on whitelisting in the Content Compliance

Note: This procedure is only applicable to Sophos Phish Threat.

To add the relevant IPs and turn on whitelisting in the Content Compliance, do as follows:

  1. Sign in to your Google Admin Console.
  2. In the Admin console, go to Menu Apps > Google Workspace > Gmail > Compliance.
  3. In Compliance, scroll to the Content compliance setting and click CONFIGURE.
  4. Enter a name for the Content Compliance setting. For example, PT content compliance.
  5. Configure your Content Compliance settings.
    1. In Email messages to affect, select Inbound.
    2. In the If ANY of the following match the message drop-down list, create an expression with the following steps:
      1. Click ADD.
      2. Select Metadata match from the drop-down list.
      3. In the Attribute drop-down list, select Source IP.
      4. In the Match type drop-down list, select Source IP is within the following range.
      5. In the Source IP is within the following range text field, enter one of the Sophos Phish Threat IPs for whitelisting.
      6. Click SAVE.
    3. Repeat the steps above for the other IPs.
    4. In the If ANY of the following match the message drop-down list, add another expression with the following steps:
      1. Click ADD.
      2. Select Advanced content match from the drop-down list.
      3. In the Location drop-down list, select Full headers.
      4. In the Match type drop-down list, select Contains text.
      5. In the Content text field, enter "X-PT-TOKEN".
      6. Click SAVE.
    5. In the If the above expressions match section, do as follows:
      1. In Spam, select Bypass spam filter for this message.
      2. In Encryption (onward delivery only), select Require secure transport (TLS).
    6. Click SAVE.

Note: If, during the implementation of the IP/Domain Whitelist, a test email bounces, you would need to remove the email address from the Bounced Mailboxes list (Phish Threat > Settings > Bounced Mailboxes)  before testing again, or no emails will be sent.  All the Mailboxes where emails failed to be sent can be found here. 


Added ingo about Bounced Mailboxes
[edited by: emmosophos at 10:21 PM (GMT -7) on 9 Apr 2024]