Exchange – Create a rule for Whalemate
Add the IP 69.72.38.219
Tell Microsoft not to send it to spam
Add a header that says "skip Safe Links"
Enable phishing simulation
Add the IP and domains of Whalemate
Allow the URLs of our simulations
Allow List
Grant permission to the IP 69.72.38.219
This way you avoid unnecessary blocks
Safe Links Policy
Create a policy for your users or groups
Include Whalemate's URLs
Image Download
Mark Whalemate's domains as "safe"
If you want, you can do this from Powershell for everyone at once
👉 PDF Guide – Whitelisting Microsoft V1.4 (Spanish)
Why do I need to do this whitelisting?
Because if Microsoft blocks our simulations, users will not receive the emails and the campaign metrics will be incomplete.
Does this affect my organization's security?
No. Only emails sent from Whalemate's official IPs and domains are allowed through; everything else continues to be filtered normally.
How long does the configuration take?
Between 10 and 20 minutes. Once the rules are saved, they apply immediately.
What happens if I don't add all the domains?
Some simulations could be blocked or sent to spam, affecting the campaign results.
Can I revert the changes?
Yes. You can edit or delete the rules created from the Microsoft portal at any time.
Do I always need to use PowerShell?
Not necessarily. PowerShell is optional if you want to apply the configuration to all users at once. For testing, you can do it on a single mailbox from the interface.
How do I know if it's working correctly?
If, after whitelisting, you receive a test email from Whalemate in your inbox (not in spam), everything is OK!