Fortinet white logo
Fortinet white logo
25.1.0

Safelisting FortiPhish in Office 365

Safelisting FortiPhish in Office 365

Perform the following steps to safelist FortiPhish in Office 365.

  1. Go to https://security.microsoft.com/ and sign in using your Office 365 admin credentials.

  2. In the navigation menu, select Email & collaboartion > Policies and rules.

  3. Click Threat policies.

  4. Select Rules > Advanced delivery.

  5. In the Phishing simulation tab, if you have an existing policy for phishing simulations, click Edit. Otherwise, click Create and give the policy a name.

  6. In the Add third party phishing simulations window, configure the following settings.

    Domain

    Enter the sender's email domain specified during campaign creation in FortiPhish. See FortiPhish Administration Guide > Creating campaigns.

    Sending IP Enter the IP address: 154.52.1.119
    Simulation URLs Enter the custom domains specified during campaign creation. See Supported custom domains
    Note

    Add the FortiPhish API endpoint IP address 34.251.104.230 to the browser safelist and to any third-party email scanners or firewalls.

  7. Review your settings and click Save.

    Once you have safelisted FortiPhish, simulated phishing emails should reach your users inbox without being blocked.

Supported custom domains

For Premium Users, the following custom domain values are supported.

  • api.mytrustedpage.com

  • api.securesitepage.com

  • api.securelandingpage.com

  • api.fphpages.com

For Free Users, the following custom domain value is supported.

  • api.fphpages.com

Safelisting FortiPhish in Office 365

Safelisting FortiPhish in Office 365

Perform the following steps to safelist FortiPhish in Office 365.

  1. Go to https://security.microsoft.com/ and sign in using your Office 365 admin credentials.

  2. In the navigation menu, select Email & collaboartion > Policies and rules.

  3. Click Threat policies.

  4. Select Rules > Advanced delivery.

  5. In the Phishing simulation tab, if you have an existing policy for phishing simulations, click Edit. Otherwise, click Create and give the policy a name.

  6. In the Add third party phishing simulations window, configure the following settings.

    Domain

    Enter the sender's email domain specified during campaign creation in FortiPhish. See FortiPhish Administration Guide > Creating campaigns.

    Sending IP Enter the IP address: 154.52.1.119
    Simulation URLs Enter the custom domains specified during campaign creation. See Supported custom domains
    Note

    Add the FortiPhish API endpoint IP address 34.251.104.230 to the browser safelist and to any third-party email scanners or firewalls.

  7. Review your settings and click Save.

    Once you have safelisted FortiPhish, simulated phishing emails should reach your users inbox without being blocked.

Supported custom domains

For Premium Users, the following custom domain values are supported.

  • api.mytrustedpage.com

  • api.securesitepage.com

  • api.securelandingpage.com

  • api.fphpages.com

For Free Users, the following custom domain value is supported.

  • api.fphpages.com