This procedure describes how to manually whitelist Arsen phishing simulation traffic in Microsoft 365 so that simulation emails bypass spam filters, avoid quarantine, and reliably reach employee inboxes.
1 – Objectives
Authorize Arsen simulations using dedicated IP addresses.
Bypass anti-spam filtering to avoid false positives.
Prevent simulation emails from being quarantined.
Improve deliverability using a Microsoft 365 connector.
2 – Prerequisites
Administrator access to the Microsoft 365 tenant.
Ability to access Microsoft 365 Defender and the Exchange Admin Center.
Permissions to modify mail flow and anti-spam policies.
3 – Add Arsen IP Addresses to the Allowed IP List
Steps:
Sign in to
Microsoft 365 Defender.Go to
Policies & Rules→Threat Policies.
Open Connection Filter Policy (Default) → Edit connection filter policy.
Under Always allow messages from the following IP addresses, add:
161.38.204.14185.211.123.249
Check
Turn on safe listand clickSave.
4 – Bypass Anti-Spam Filtering
Open the Microsoft 365 Admin Center.
Navigate to
Exchange.
Go to
Mail Flow→Rules.Click
+→Create a new rule.
Configure the rule:
Name: Arsen Simulation Access
Apply this rule if…
The sender → IP address is in any of these ranges or exactly matches
Add:
161.38.204.14,185.211.123.249
Actions:
Modify the message properties → Set a message header
Header:
X-MS-Exchange-Organization-BypassClutterValue:
true
Add another action:
Modify the message properties → Set the spam confidence level (SCL) toValue:
-1 (Bypass Spam Filtering)
Click Next, review, and Save.
5 – Prevent Emails from Being Quarantined
In
Mail Flow→Rules, create another new rule.
Configure:
Name: Arsen Quarantine Avoidance
Condition:
The sender → IP address is in any of these ranges or exactly matchesAdd:
161.38.204.14,185.211.123.249
Action:
Modify the message properties → Set a message header
Header:
X-Forefront-Antispam-ReportValue:
SFV:SKI;CAT:NONE;
Click Save.
You should now see two rules in the Mail Flow Rules list.
6 – Configure a Connector to Avoid Delivery Delays
In the Exchange Admin Center, go to
Mail Flow→Connectors.Click
+ Add a connector.
Configure:
From: Partner organization
To: Office 365
Name:
Arsen Training ConnectorEnable
Turn it on
IP settings:
Choose:
By verifying that the IP address of the sending server matches one of the following IP addresses…
Add:
161.38.204.14185.211.123.249
Click
Next.
Security:
Check
Reject email messages if they aren’t sent over TLS
Finally, click Create Connector.

















