Skip to main content

Phishing IP Addresses

Phishing, Training, and System emails all originate from separate IPs. US and EU have separate mail servers for Phishing and System emails, but both use the same Training email server.

Vincent Priestley avatar
Written by Vincent Priestley
Updated over 2 weeks ago

Note: System emails include new account user emails, domain authorization emails, and School emails. Any emails generated in CyberPhish that are not simulated phishing / training emails are considered system emails

US

  • 64.191.166.196 (Phishing)

  • 64.191.166.197 (Training)

  • 69.72.47.194 (System)

EU

  • 64.238.34.10 (Phishing)

  • 64.238.34.11 (Phishing)

  • 64.191.166.197 (Training)

  • 161.38.205.202 (System)

Note: Some email security software, such as Mimecast, will require you to safelist by CIDR range. The phishing mail server's CIDR range is 64.191.166.0/24 (US), 64.238.34.10/24 (EU).

Landing Page Servers

CyberPhish landing page servers and image assets are hosted on the following IP addresses. In some cases you may need to safelist our landing page server(s) to allow images to display in emails, and allow targets to access landing pages.

US

  • 64.191.166.198

  • 64.191.166.201

  • 64.191.166.205

  • 64.191.166.220

  • 64.191.166.221

  • 64.191.166.222

  • 64.191.166.223

  • 64.191.166.224

EU

  • 64.238.34.20

Portal and School IPs

Under certain circumstances (e.g. if you are trying to connect an LDAP integration to CyberPhish, connecting to SMTP Relay, etc.) you may need to safelist the CyberPhish portal IP address, Cron server address, and/or API server address.

US

  • 54.80.160.189 (Portal)

  • 54.161.73.139 (Cron)

  • 54.158.229.58 (API)

  • 54.88.246.212 (School)

EU

  • 54.93.55.235 (Portal)

  • 3.75.8.204 (Cron)

  • 52.29.89.35 (API)

  • 35.156.216.148 (API)

  • 18.194.154.19 (API)

  • 63.180.59.25 (API)

  • 63.180.52.89 (API)

  • 3.67.53.250 (School)

Safelisting Domains

In some scenarios, it may be necessary to safelist phishing domains. The domains that need to be safelisted are specified by the templates that you are using.

All the Domains are listed below:

notification-center.net

company-meeting.com

banktransfers.org

compliance-central.co.uk

docusiogn.net

Did this answer your question?