Always allow or always block a sender
Use the trusted and blocked lists to override the filter for one address or a whole domain, and learn when not to use them.
The filter scores every incoming message. The two lists here override that score for senders you name explicitly.
Before you start
- The domain is live. See Point MX through the filtering gateway
- The sender address or domain you want to handle
What the two lists do
Go to Email Security → Filter lists.

| Tab | Mail from a sender on this list |
|---|---|
| Trusted senders (whitelist) | skips spam scoring and goes straight to the inbox — malware scanning and the attachment filter still run |
| Blacklist | is blocked outright — no inbox, no quarantine |
The two lists are independent. The search box, the table and the add button all act on the tab you have open.
Check which tab you are on before clicking add
The add button sits in the page header and does not change colour with the tab. Clicking it while the whitelist tab is open puts the address on the trusted list — the exact opposite of blocking it.
The dialog title tells you where the address is going: Add to Whitelist (Trusted) or Add to Blacklist (Blocked).
Open the dialog
Select the right tab first, then click Add address at the top right.
Fill in two fields
| Field | Required | What goes in it |
|---|---|---|
| Sender email or domain | Yes | a full address, or @ followed by a domain |
| Note / Comment | No | the reason, the partner's name — whatever helps you six months later |
Click Save. The list reloads immediately.
Do fill in the note: it is the only column that answers "who added this row, and why".

One address or a whole domain
The leading @ is what decides.
| You enter | Applies to |
|---|---|
partner@example.com | that one address |
@example.com | every address at that domain |
Anything that is neither a valid address nor a valid domain is rejected on the spot.
The whole-domain form is convenient but broad: @example.com on the trusted list means anyone
who can forge that domain reaches your inbox unfiltered.
Remove an entry
Click the bin button in the Action column. The confirmation dialog shows the exact value about to be removed — read it before confirming.
Removing from the whitelist does not block the sender: their mail goes back through normal filtering. To block them, add them to the blacklist.
When not to use the whitelist
Check your work
List changes take effect immediately — no waiting, unlike DNS records.
Ask that sender to send a test message, then search the address you just added in Email tracking:
- Added to the whitelist → the new row reads Delivered
- Added to the blacklist → the new row reads Rejected
No row at all means the message never reached the gateway — an MX record problem, not a list problem. See Point MX through the filtering gateway.
Point MX to gateway
Point MX at the Email Security filtering gateway so inbound mail is filtered before reaching your server, then verify it really goes through.
Block by extension
Add dangerous file extensions to the block list so the filter rejects the whole message, and learn why the trusted list cannot override it.