Creating block and allow rules
What are block and allow rules?
Block and allow rules are configurable rules that can be added in your Paubox dashboard, to ensure or prevent delivery from specific senders or domains.
How the block / allow rules work
A block rule will hold an incoming email from a blocked sender/domain to the quarantine, rather than deliver to the recipient's inbox.
An allow rule will permit emails from specific senders or domains to reach the recipient even if the email is flagged as spam (note that allow rules do not override malware or phishing filters).
Why a message might still be quarantined even with an allow rule
An allow rule doesn't exempt a message from every check Paubox runs on inbound mail. It bypasses:
- Spam classification, including AI scoring and sender or URL blacklist reputation checks
- Executive impersonation and display-name spoofing protection (ExecProtect)
- Behavioral geofencing and anomaly scoring
Every message, allowed or not, still goes through:
- Virus and malware scanning: detection of malicious code, infected attachments, or phishing signatures
- Basic message validation: structural anomalies, multiple From headers, or spoofing validation failures
- Data Loss Prevention (DLP): content that violates active DLP compliance rules
Note: An allow rule doesn't guarantee delivery. If a message trips one of the checks above, it can still be quarantined even from an allowed sender.
How to set up block and allow rules
To create a block rule:
- Sign in to your Paubox dashboard.
- Click Rulesets the left navigation column (in the "Inbound Security" section).
- Click the Add button.
- Select your domain in the "Customer" field.
- Select Block from in the "Rule type" field.
- In the Match enter the email address (or addresses) you would like to block going forward.
- Click the Save button to finish adding the new rule.
Note: you can use the wildcard to block an entire domain in Step 6, for example "*@baddomain.com"
To create an allow rule:
- Sign in to your Paubox dashboard.
- Click Rulesets the left navigation column (in the "Inbound Security" section).
- Click the Add button.
- Select your domain in the "Customer" field.
- Select Allow from in the "Rule type" field.
- In the Match enter the email address (or addresses) you would like to allow going forward.
- Click the Save button to finish adding the new rule.
Note: you can use the wildcard to allow an entire domain in Step 6, for example "*@baddomain.com"