Mimecast whitelisting

Greylisting

Greylisting is an anti-SPAM technique that refuses the first send of a message to a recipient at Mimecast but will then accept it the second time. The logic is that a spammer won't bother retrying but genuine mail will (although this is dubious logic). The problem with this occurs when sending high volumes of emails which immediately cause our sending servers to spike with a large number of "deferred" messages which can hide any problems that might be happening due to being blocked. It will also potentially add a noticeable delay to receiving emails of several minutes or longer, which might or might not be a problem for you.

Anti-Spoofing Policy

Another issue with Mimecast is that when you add a domain to Mimecast, for example, when sending emails for your domain via Mimecast, it automatically adds an anti-sppofing policy, the logic being that if Mimecast are sending your emails, then none should originate from outside of Mimecast. In many cases, this logic doesn't work since many organisations send branded emails from external services like Salesforce, Xero or SmartSurvey and if any of these are directed back to your organisation, Mimecast will block them.

To make it worse, we send un-verified emails as e.g. "luke@somecompany.com" <member@smartsurveyuser.com> where your email address is used as the name part of the email and member@smartsurveyuser.com is the email part. Mimecast would still consider the name to be a spoofing attack and would block these emails.

Other anti-spam measures

As with all other email providers, Mimecast will also use a range of heuristic measures to detect SPAM, although we do not generally have a problem with this on Mimecast.

Whitelisting

Individual Mimecast accounts can whitelist certain senders to bypass these checks but this will only apply to recipients within that account (not everyone using Mimecast) so if your scenario is to send lots of email to your own users within a Mimecast account, you are recommended to whitelist the SmartSurvey email servers for prompt delivery.

https://community.mimecast.com/s/article/Configuring-Permitted-Senders-Policies-1067720131

There are a number of options which you can use, although the easiest would be to specifically whitelist where the "From" address is the sending email you are using on your smartsurvey account e.g. surveys@example.com or member@smartsurveyuser.com, that way you will not need to update the policy if our email servers change, which does happen from time to time. If you are unsure what the from address is, you can look at a previous message sent from SmartSurvey since the exact address will depend on whether you have sending domains setup or not.

All of our servers are named e.g. ms1.ssmx.net, ms7, ms8 etc. but Mimecast doesn't currently support whitelist ing based on the sending server which means if you wanted to whitelist based on IP addresses, you would not only need to specify all of our email servers but it would also mean that if we added a new server, the policy would need to be updated or that new server would potentially suffer the same restrctions at mimecast.

Was this guide helpful?