Spam filtering Email Security

Always allow or always block a sender

Use the trusted and blocked lists to override the filter for one address or a whole domain, and learn when not to use them.

The filter scores every incoming message. The two lists here override that score for senders you name explicitly.

Before you start

What the two lists do

Go to Email Security → Filter lists.

The Filter lists page: an add-address button top right, two tabs for trusted senders and blacklist, and a three-column table of sender address, notes and an action column with a delete button on each row

TabMail from a sender on this list
Trusted senders (whitelist)skips spam scoring and goes straight to the inbox — malware scanning and the attachment filter still run
Blacklistis blocked outright — no inbox, no quarantine

The two lists are independent. The search box, the table and the add button all act on the tab you have open.

Check which tab you are on before clicking add

The add button sits in the page header and does not change colour with the tab. Clicking it while the whitelist tab is open puts the address on the trusted list — the exact opposite of blocking it.

The dialog title tells you where the address is going: Add to Whitelist (Trusted) or Add to Blacklist (Blocked).

Open the dialog

Select the right tab first, then click Add address at the top right.

Fill in two fields

FieldRequiredWhat goes in it
Sender email or domainYesa full address, or @ followed by a domain
Note / CommentNothe reason, the partner's name — whatever helps you six months later

Click Save. The list reloads immediately.

Do fill in the note: it is the only column that answers "who added this row, and why".

The add to whitelist dialog: a sender email or domain field hinting that a leading @ applies to the whole domain, a comment field, and cancel and save buttons

One address or a whole domain

The leading @ is what decides.

You enterApplies to
partner@example.comthat one address
@example.comevery address at that domain

Anything that is neither a valid address nor a valid domain is rejected on the spot.

The whole-domain form is convenient but broad: @example.com on the trusted list means anyone who can forge that domain reaches your inbox unfiltered.

Remove an entry

Click the bin button in the Action column. The confirmation dialog shows the exact value about to be removed — read it before confirming.

Removing from the whitelist does not block the sender: their mail goes back through normal filtering. To block them, add them to the blacklist.

When not to use the whitelist

Check your work

List changes take effect immediately — no waiting, unlike DNS records.

Ask that sender to send a test message, then search the address you just added in Email tracking:

  • Added to the whitelist → the new row reads Delivered
  • Added to the blacklist → the new row reads Rejected

No row at all means the message never reached the gateway — an MX record problem, not a list problem. See Point MX through the filtering gateway.