What is a Whitelist?

Email Operations 4 min read
Learn what allow-list rules change—and what they cannot guarantee—then apply the narrowest safe exception in Mailcow or DirectAdmin. Resolve false positives without disabling malware scanning.

What a whitelist really does

A whitelist is an allow rule that changes spam-filter evaluation for a sender, domain, or IP. It does not prove that a message is harmless, prevent compromise of the sender's account, or automatically bypass every receiver-side security layer. Whitelisting is therefore a controlled exception for false positives, not a delivery guarantee.

Investigate the root cause first

  1. Keep the sample in Junk and inspect its complete headers before deleting it.
  2. Confirm that visible From, Reply-To, and Return-Path belong to the expected organization.
  3. Read SPF, DKIM, and DMARC results. Ask the sender to repair DNS authentication instead of hiding failure with a whitelist.
  4. Identify suspicious attachments, links, subjects, or a high score that triggered filtering.
  5. Verify the sender through an independent channel such as a known phone number or website.

Principle of narrowest scope

ScopeRiskRecommendation
One sender addressLowest; that account can still be compromisedPreferred starting point
Entire domainEvery account in the domain gains trustOnly with strong verification and justification
Sending IPA shared IP includes other customersOnly when static and truly dedicated
Subject/wordEasily imitatedNever use alone as proof of trust

Document who created the rule, its business reason, covered identity, and review date. Use expiring rules for temporary vendors and projects. Unnecessary allow entries become an invisible attack surface over time.

Mailcow SOGo/webmail approach

Sign in at https://mail.YOURDOMAIN.com/user. Mark the false positive as “Not junk” and, if needed, create a narrowly targeted move rule for the verified sender in webmail settings. Confirm that the rule does not disable malware scanning or all security checks. Menu names can vary by interface version.

DirectAdmin SpamAssassin approach

Open https://SERVER:2222 or https://DOMAIN:2222 → Email Management → SpamAssassin Setup / Spam Filter. Allow one address first; use a full domain or wildcard only when necessary and verified. Limit the exception to that sender instead of weakening the spam score for everyone.

Test after whitelisting

  • Ask for a new harmless test message; forwarding the old sample is not equivalent.
  • Confirm Inbox delivery, continuing attachment/link scanning, and SPF/DKIM/DMARC results.
  • Verify that a look-alike domain cannot benefit from the rule.
  • Review the rule within 30–90 days or when the business relationship changes.

When not to whitelist

Do not create an exception when identity cannot be verified, the domain is commonly spoofed, attachments are malicious, or the sender asks you to disable all security. Repairing the sender's SPF/DKIM/DMARC and delivery is the lasting solution. Follow the spam safety guide for suspicious mail.

EuroVDC product note and shared technical reference

First confirm which product hosts the mailbox. Corporate Email (Mailcow) uses securemail.eurovdc.eu for incoming and outgoing mail. Hosting email (DirectAdmin) uses mail.yourdomain.com or the server hostname supplied in the service activation details. Using one product's hostname for the other can cause connection or certificate-name errors even when the password is correct.

ProtocolSecure portEncryptionPurpose
IMAP993SSL/TLSRecommended; synchronizes folders between devices
SMTP587STARTTLSRecommended outgoing connection
SMTP465SSL/TLSAlternative outgoing connection
POP3995SSL/TLSOnly for specific download requirements

The username is always the full email address. SMTP authentication is mandatory; use the same full username and mailbox password as incoming mail. Do not select Microsoft 365 or Outlook.com, and do not use Microsoft-hosted server names. Corporate webmail is https://mail.YOURDOMAIN.com/user; replace YOURDOMAIN.com with your domain.

Client area and DirectAdmin path

  1. Sign in to the EuroVDC client area.
  2. Open the relevant product, then view Connection Settings and the DNS wizard.
  3. Record the server name, account-specific DKIM text, and displayed DNS status.
  4. For Hosting email, sign in at https://SERVER:2222 or https://DOMAIN:2222. Open Email Accounts, create or locate the mailbox, then use “+” → Configure Email Client on its row to obtain the exact hostname and ports.

Corporate Email DNS summary

NameTypeTarget/value
mailCNAMEsecuremail.eurovdc.eu
@MXsecuremail.eurovdc.eu, priority 10
@TXTv=spf1 mx ip4:45.84.90.12 -all
dkim._domainkeyTXTAccount-specific DKIM value from the DNS wizard
_dmarcTXTCommonly v=DMARC1; p=reject; adkim=r; aspf=r; pct=100
autodiscover and autoconfigCNAMEsecuremail.eurovdc.eu

Autodiscover and autoconfig help compatible applications propose server settings; they do not remove password security or SMTP authentication. Always compare discovered values with the product screen. DNS changes may appear differently across networks until cached records expire.

Quick checklist

  • Corporate Email and Hosting email have been distinguished.
  • The full email address is entered as the username.
  • 993/SSL-TLS and either 587/STARTTLS or 465/SSL-TLS are paired correctly.
  • SMTP authentication is enabled and its password is not blank.
  • Webmail, receiving, and sending have been tested separately.
  • DNS matches the wizard, and the exact error and test time are recorded.

For a visual reference, download the Email Setup Card from PDF help files. If the issue remains, send the mailbox address, device/application version, complete error, and screenshot to support@eurovdc.eu. EuroVDC services operate from Sofia, EU; never include your password in a support request.

Share on Social Media

What is a Whitelist?