Whitelist Simulations in Google Workspace
To allowlist Nimblr's simulated phishing attacks in Google Workspace (Gmail), add Nimblr's IP addresses to both the Email Allowlist and the Inbound Gateways in your Google Admin console. This prevents Gmail from blocking or flagging Nimblr simulations as spam. Complete both parts below in order, then verify your configuration with a delivery test. For additional reference, see: https://support.google.com/a/answer/60751?hl=en
Part 1 - Add Nimblr's IP addresses to Email Whitelist
1. Login to https://admin.google.com and click Apps > Google Workspace > Gmail. Scroll down and click Spam, Phishing and Malware.

2. Click the pen in the Email allowlist box to edit the allowlist.
3. Add the following Nimblr IP addresses to the allowlist field, separating each entry with a comma, then click Save.
|
78.47.225.98 |
| 116.203.167.208 |
| 95.326.276.28 |
Then click SAVE.

Part 2 - Add Nimblr's IP addresses to Inbound Gateways
Configuring Nimblr's IP addresses as an inbound gateway suppresses Google warning banners that would otherwise appear in your users' inboxes when they receive a simulated attack. This method disables most Gmail warnings for Nimblr simulations; note that Google does not officially document this as an allowlisting feature.
1. Login to https://admin.google.com and click Apps > Google Workspace > Gmail. Scroll down and click Spam, Phishing and Malware.
2. Scroll down to the Inbound Gateway and click the pen to edit the gateway settings.
3. Check the Enable box, then click Add and enter each of Nimblr’s IP addresses one at a time: 78.47.225.98, 116.203.167.208, 95.216.176.28. Verify these IP addresses are current with your Nimblr account representative if needed.
4. Leave the first three boxes unchecked. Check the box for “Message is considered spam if the following header regexp matches” and enter a phrase that is unlikely to appear in an email header. For example sdfsdf343. Choose “Message is spam if regexp matches” and check the box for “Disable Gmail spam evaluation on mail from this gateway; only use header value”
5. Click Save.
Verify Whitelist configuration
Send a test simulation to confirm your allowlist configurations are working:
- Log in to your Nimblr portal at https://nimblr.net.
- Navigate to Settings > Delivery test.
- Click Send Email to send a test simulation to your inbox.
