Sender lists in Proofpoint control which emails bypass spam filtering (Safe Senders) and which are automatically blocked (Blocked Senders). Properly managing these lists ensures legitimate emails are delivered while known bad actors are blocked.
Prerequisites
Before managing sender lists, ensure you have:
- Administrator access to Proofpoint Essentials (for organization/group lists)
- End user access to Proofpoint (for personal lists)
- List of trusted senders or domains to allowlist
- List of known spam sources to blocklist
Understanding Sender List Hierarchy
Proofpoint processes sender lists in this order:
| Level | Managed By | Scope | Priority |
|---|---|---|---|
| User | Individual users | Personal email only | Highest |
| Group | Administrators | Specific teams/departments | Medium |
| Organization | Administrators | All company users | Lowest |
Key Points:
- User settings override group settings
- Group settings override organization settings
- Entries can be email addresses, domains, or IP addresses
Step 1: Access Sender Lists (Administrator)
Organization-Level Lists
- Log in to the Proofpoint Essentials Admin Console
- Navigate to Security Settings in the left sidebar
- Click Email
- Select Sender Lists
- You'll see two sections:
- Blocked Senders List (top)
- Safe Senders List (bottom)
Group-Level Lists
- Navigate to Users & Groups > Groups
- Select the group to modify
- Click Sender Lists in the group settings
- Manage Safe and Blocked lists for that group
Step 2: Add Entries to the Safe Senders List
Adding Individual Addresses
- In Sender Lists, scroll to Safe Senders List
- Enter email addresses in the text box, one per line:
- Click Save to apply changes
Adding Domains (Wildcards)
To allow all emails from a domain:
*@trustedcompany.com
*@vendor-notifications.com
Warning: Adding entire domains is less secure than individual addresses. Only use for highly trusted sources.
Adding IP Addresses
For server-level allowlisting:
192.168.1.100
203.0.113.0/24
IP Format Options:
| Format | Example | Description |
|---|---|---|
| Single IP | 192.168.1.100 | One specific server |
| CIDR Range | 203.0.113.0/24 | IP range (256 addresses) |
| Wildcard | 10.0.. | Partial IP matching |
Step 3: Add Entries to the Blocked Senders List
Blocking Individual Senders
- Scroll to Blocked Senders List
- Enter addresses to block:
- Click Save
Blocking Entire Domains
*@spam-domain.com
*@known-malicious.net
Blocking IP Ranges
For blocking mail servers:
198.51.100.0/24
Step 4: Manage User-Level Sender Lists
Admin View of User Lists
Administrators can view and modify individual user lists:
- Navigate to Users & Groups > Users
- Search for and click on the user
- Click the Sender Lists option
- Review and modify their personal lists
- Click Save
User Self-Management via Portal
End users can manage their own lists:
- Log in to the Proofpoint User Portal
- Click Lists in the navigation
- Select Safe Senders List or Blocked Senders List
- Add or remove entries
- Click Save
User Self-Management via Digest
Users can add senders directly from quarantine digests:
- Allow Sender - Adds sender to Safe list
- Block Sender - Adds sender to Blocked list
- Release and Allow Sender - Releases email AND adds to Safe list
Step 5: Import Bulk Entries
For large-scale list management:
Prepare Import File
Create a CSV or text file with entries:
# safe_senders.txt
[email protected]
[email protected]
*@trusted-supplier.com
[email protected]
Import Process
- In Sender Lists, look for Import or Bulk Add option
- Upload your file
- Select the target list (Safe or Blocked)
- Review the import preview
- Click Import to apply
Note: Import options vary by Proofpoint version. Contact support if bulk import isn't visible.
Step 6: Export Current Lists
For backup or audit purposes:
- Navigate to Sender Lists
- Click Export (if available)
- Select the list to export
- Download the file
Manual Export
If no export feature exists:
- View the sender list
- Select and copy all entries
- Paste into a spreadsheet
- Save for records
Common Safe Sender Scenarios
Business Partners
# Trusted vendors and partners
*@primaryvendor.com
[email protected]
[email protected]
SaaS Applications
# Business applications
*@salesforce.com
*@slack.com
*@zoom.us
[email protected]
[email protected]
Marketing and Newsletter Platforms
# Opted-in marketing sources
*@mailchimp.com
*@constantcontact.com
[email protected]
Internal Systems
# Internal automated systems
[email protected]
[email protected]
Common Block List Scenarios
Known Spam Sources
# Persistent spam senders
*@spam-domain.com
*@mass-mailer-spam.net
Competitor Domains (Optional)
Some organizations block competitor communications:
# Competitive blocking (use cautiously)
*@competitor.com
Former Employee Domains
After acquisitions or separations:
# Legacy domains no longer trusted
*@old-company-domain.com
Best Practices for Sender Lists
Safe Senders Best Practices
- Prefer specific addresses over domains - More secure
- Document why entries were added - Track business justification
- Review quarterly - Remove outdated entries
- Verify legitimacy first - Confirm sender identity before adding
- Don't over-whitelist - Each entry is a potential security gap
Blocked Senders Best Practices
- Block domains for persistent spam - More effective than individual addresses
- Use for confirmed threats only - Avoid blocking legitimate senders
- Document source of block decision - Track why addresses were blocked
- Review for false positives - Check if legitimate mail is affected
- Coordinate with IT security - Align with broader threat intelligence
What NOT to Add to Safe Senders
| Entry Type | Why It's Risky |
|---|---|
| Public email domains (gmail.com, outlook.com) | Spammers use free email |
| Large shared domains | Too broad, reduces security |
| Unverified senders | Could be spoofed |
| Domains you don't recognize | Investigate before adding |
Troubleshooting Sender List Issues
Emails Still Being Quarantined
Symptoms: Added sender to Safe list but emails still quarantined.
Solutions:
- Verify exact address/domain spelling
- Check for conflicting entries at other levels
- Allow 15-30 minutes for propagation
- Verify entry was saved (refresh the page)
- Check if message is blocked for malware (bypasses Safe list)
Emails From Blocked Sender Delivered
Symptoms: Blocked sender emails are still arriving.
Solutions:
- Verify exact address/domain in block list
- Check for conflicting Safe entries at user/group level
- Verify domain wildcards are correct (*@domain.com)
- Check if sender is using different addresses/domains
Cannot Modify Sender Lists
Symptoms: Unable to add or remove entries.
Solutions:
- Verify you have administrator permissions
- Check if your role allows sender list management
- Try logging out and back in
- Contact your Proofpoint administrator or support
Auditing Sender Lists
Regular audits ensure lists remain effective:
Monthly Audit Checklist
- Review all organization-level entries
- Remove entries for departed vendors/partners
- Verify block entries are still relevant
- Check for overly broad domain wildcards
- Document any changes made
Audit Report Template
| Entry | Type | Added By | Date Added | Reason | Still Needed? |
|---|---|---|---|---|---|
| *@vendor.com | Safe | Admin | 2024-06-15 | Vendor emails | Yes |
| [email protected] | Blocked | Auto | 2024-07-01 | Spam | Review |
Processing Order Reference
When an email arrives, Proofpoint checks lists in this order:
- User Blocked List - If matched, quarantine/reject
- User Safe List - If matched, skip spam filter
- Group Blocked List - If matched, quarantine/reject
- Group Safe List - If matched, skip spam filter
- Organization Blocked List - If matched, quarantine/reject
- Organization Safe List - If matched, skip spam filter
- Standard spam filtering - If no list match
Next Steps
After configuring sender lists:
- Configure email filtering - Set up filter policies
- Manage quarantine - Handle quarantined messages
- Enable URL Defense - Protect against malicious links
- Configure DLP - Prevent data loss
Additional Resources
Need help managing your Proofpoint email security? Inventive HQ provides expert email security configuration and ongoing management services. Contact us for a free security assessment.