Whitelisting PhishGuard in Trend Micro

Modified on Thu, 11 May 2023 at 11:39 AM


Whitelisting in Trend Micro

If you're using Trend Micro, you can whitelist PhishGuard to allow our phishing emails reach the targets in a phishing campaign. 

The whitelisting process in Trend Micro consists of five steps. Each step has its own configuration and must be completed to successfully whitelist PhishGuard. In this article, we discuss Whitelisting by Domain in Trend Micro, steps as:

  • Advanced Spam Protection
  • Malware Scanning
  • File Blocking
  • Web Reputation
  • Virtual Analyzer

Advanced Spam Protection

  1. Navigate to the Advanced Threat Protection tab > Add.
  2. Select the policy to create based on the service:
    • Exchange
    • OneDrive
    • SharePoint
    • Box
    • Dropbox
    • Google
  3. On the left, select Advanced Spam Protection.
  4. Check the Enable Advanced Spam Protection option.
  5. Select the Approved/Blocked Sender List section.
  6. Check the box next to the Enable the approved sender list option.
  7. Enter *senderName@... in A, as you specified in your custom sender in the campaign launching settings -for example if the campaign sender address is Hello@cerebra.sa, enter here *@cerebra.sa- and click the Add > button.


  1. Select the Rules configuration section.
  2. Under the Apply to: drop-down, select the Incoming messages option.
  3. For Detection Level:, select the Medium option.

Malware Scanning


  1. On the left, select Malware Scanning.

  2. Select the Rules configuration section.

  3. Under the Apply to: drop-down, select the All messages option.

  4. Under Malware Scanning, select Scan all files and check the box next to Scan message body and Enable IntelliTrap.

  1. Select the Action configuration section.

  2. For Action:, select the Trend Micro recommend actions option from the drop-down.

  3. For Notification:, select the Notify option from the drop-down.



File Blocking


  1. On the left, select File Blocking and select Enable File Blocking. We recommend keeping File Blocking on because you cannot limit this option to PhishGuard messages. Turning off File Blocking could allow potentially malicious attachments through to your users.


 



Web Reputation


  1. On the left, select Web Reputation.

  2. Check the Enable Web Reputation option.

  3. Select the Rules configuration section.

  4. Under the Apply to: drop-down, select the All messages option.

  5. For Security Level:, select the Medium option.

  1. Select the Approved/Blocked URL List section.

  2. Check the box next to the Enable the approved URL list option.

  3. Check the box next to the Add internal domains to the approved URL list option.

  4. Enter our domains in the text field. 

  5. Then, click the Add > button. You can click the Import button to import URLs in batches.


Virtual Analyzer


  1. On the left, select Virtual Analyzer.

  2. Check the Enable Virtual Analyzer option.

  3. Click the Save button.

Once all steps in each section are completed, your new policy will appear under the Advanced Threat Protection tab.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select atleast one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article