Security Awareness Safelisting US

Safelisting On The US (North American) Platform

Proofpoint Security Awareness Training uses a variety of systems to communicate to devices within your network and deliver email messages to your end users. This guide documents the IP addresses, domains and URLs used to deliver this information. This document should be provided to your email or security administrators to ensure reliable communications.

Note:

  • Only perform safelisting for your licensed Proofpoint Security Awareness Training products.
  • Only safelist the IPs and domains for your hosted location. If you aren’t sure of your hosted location, please contact Customer Support.

Training Notifications

Proofpoint recommends that Training Notifications are sent with a “From:” address that uses your organization’s domain name. This email address will be more familiar to the user and allow the user to easily reply to the message, should they have questions. Before we can send emails using your domain name, you must contact your mail administrator as most email systems restrict email using your organization’s domain name to authorized mail servers. To allow email from our servers using your organization’s domain name, we recommend asking your email administrator to make the following changes:

  • Add the appropriate IP addresses to your SPF records and your email filter safelist
  • securityeducation.com is a domain that can also be safelisted for web filtering

Training Notifications

Proofpoint recommends that Training Notifications be sent with a “From:” address that uses your organization’s domain name. This email address will be more familiar to the user and allow the user to easily reply to the message, should they have questions. Before we can send emails using your domain name, you must contact your mail administrator as most email systems restrict email using your organization’s domain name to authorized mail servers. To allow email from our servers using your organization’s domain name, we recommend asking your email administrator to make the following changes:

  • Add the appropriate IP addresses to your SPF records and your email filter safelist
  • securityeducation.com and ws01-securityeducation.com are domains that can also be safelisted for web filtering

Training Platform

  • 107.20.210.250 
  • 52.1.14.157 

In order to have the uploaded images from the Training Platform automatically downloaded within Outlook, we recommend safelisting the following domain and adding it to the Trusted Sites:

  • platform.securityeducation.com

The following URL can be safelisted to ensure proper delivery of all assets including text content, graphics, photographs, videos, audio files, and databases:

  • d1fbefs0dyob6i.cloudfront.net

Phishing

Phishing will send simulated phishing attacks to your end users. To ensure users are provided a realistic assessment, we recommend safelisting the following IP addresses:

  • 107.23.16.222 
  • 54.173.83.138 

Phishing stock images are hosted at tslp.s3.amazonaws.com.  These images are embedded in Attachments and Teachable Moments.  Safelisting this domain in your firewall or proxy server will ensure these images are displayed to your end users.

Custom images are images that the Phishing Admin has uploaded to personalize their Phishing campaign and are stored at the following domain:   

  • tslp.s3.amazonaws.com
  • ts-uploads.s3.amazonaws.com 
  • s3.amazonaws.com

Note: Phishing emails will come from whatever from address you chose when creating a campaign. You can add the from address to your safe sender list to ensure that the message arrives to the end user’s inbox and the tracking pixel is downloaded without having to click download images. Clicking on the download images prevents proper tracking of email opensThis will also prevent the message from ending up in your junk folder

Phishing Domains

Below is a list of phishing domains you may utilize in your Phishing campaigns. We recommend that you provide this list to your IT or security administrators to ensure that your users will be able to access the Teachable Moment seamlessly from within your organization’s network.

Many default phishing templates include a subdomain, so if you are safelisting by domain, you may wish to wildcard it (Ex. Safelist *.proofpoint.com, instead of safelisting proofpoint.com to ensure all subdomains are included)

Phishing will also make calls to the following URLs: 

  • https://tslp.s3.amazonaws.com
  • https://java.com
  • https://ajax.googleapis.com
  • https://fonts.googleapis.com
  • https://tscontent.s3.amazonaws.com
  • https://d2wy8f7a9ursnm.cloudfront.net
  • https://dp4eiskq7iesj.cloudfront.net
  • https://fontawesome.com

Phishing North American

The following DMARC (Policy Reject) domains are available for NA-hosted environments.

US Landing Domains List (CSV File)

 

Resources:

Security Awareness Safelisting EU

Security Awareness Safelisting in Microsoft 365

Why is Security Awareness Training Needed?