INKY Bypasses (whitelisting)

INKY bypasses, or whitelisting, allow trusted senders or specific email types to skip INKY’s security analysis to reduce unnecessary warnings on automated or safe messages. The way you set up bypasses depends on your email platform.

 

 

Bypassing INKY in Google Workspace:

  • Use the Authenticated Email Bypass List to exempt automated messages (e.g., newsletters, ticketing alerts) from bannering.
  • Important: Messages must pass DMARC authentication (SPF or DKIM) to bypass INKY; unauthenticated mail is still analyzed.
  • To create the bypass list:
    1. Go to Google Admin Console > Apps > Google Workspace > Settings for Gmail > Routing > Manage address lists.
    2. Add an address list named IPW-Auth-Bypass with sender addresses to bypass.
    3. Ensure "Authentication required" is selected.
  • Then apply this list to the existing INKY mail routing rule under Compliance > Content compliance.
  • Review your bypass list quarterly to remove outdated entries.

More details and step-by-step instructions are available in the Bypass INKY in Google Workspace article.

 Category: Authenticated Email Bypass List
Extreme Scenarios:

  • Use only for automated messages from trusted sources (e.g., ticketing systems, newsletters, check-in notices) that do not require security warnings.
  • Messages must pass DMARC authentication (SPF or DKIM). Unauthenticated email will still be analyzed.
  • Apply when legitimate business systems are being flagged or modified by INKY, causing workflow disruption.
  • Never bypass unauthenticated or unknown senders; this is a security risk.
  • Review bypass lists quarterly to remove outdated entries.

How to Apply:

  • Create an address list in Google Admin Console and require authentication.
  • Apply the list to your INKY routing rule for content compliance.

Only authenticated, trusted senders are exempt from INKY banners and scanning [please refer to https://feedback.inky.com/en/help/articles/6567030-bypass-inky-in-google-workspace for more info].

 

 

Bypassing INKY in Microsoft 365

  • Set up Exchange transport rules that add the header X-IPW-Ignore: True to messages that should bypass INKY analysis.
  • Common use cases include calendar invites, internal newsletters, or trusted automated notifications.
  • Create rules in Exchange Admin Center > Mail Flow > Rules:
    • Name the rule following your INKY installation conventions.
    • Set conditions to match the intended emails (by sender, message type, etc.).
    • Modify message properties to add the X-IPW-Ignore header with value True.
    • Set rule priority directly after the base INKY bypass rule.
  • Use envelope-based sender matching to minimize spoofing risks.
  • Test by sending matching emails to confirm no banners and no link rewriting.
  • Review rules quarterly to minimize security blind spots.

For full guidance, see the Bypass INKY Protection for Specific Email in Microsoft 365 article.

 Category: Exchange Transport Rule (Header-based Bypass)
Extreme Scenarios:

  • Use for calendar invitations from scheduling tools (Calendly, Zoom), internal newsletters, automated notifications, encrypted email, or service accounts sending legitimate bulk mail.
  • Apply when INKY modification causes rendering issues, breaks workflows, or interferes with critical business systems (e.g., calendar delegate functionality, system notifications).
  • Only bypass verified, trusted sources. Each bypass reduces protection—minimize and review regularly.
  • Prefer envelope matching for external senders to prevent spoofing.

How to Apply:

 

 

Calendar Invites Bypassing INKY

Category: Special Message Type/Transport Rule
Extreme Scenarios:

  • Apply when INKY processing breaks calendar invite functionality (e.g., delegate invites, meeting requests) or causes rendering issues in clients.
  • Use for trusted scheduling tools or internal calendar systems only.
  • If INKY banners or modifications disrupt calendar workflows, bypass calendar-type messages via transport rule.
  • Alternatively, adjust INKY’s “Special Message Types” setting to banner all calendar invites, but this may add banners to legitimate meeting requests.

How to Apply:

 

 

 

Best Practices Across All Categories

 

Summary Table

Category When to Apply (Extreme Scenarios) How to Apply
Google Workspace Bypass Trusted, authenticated automated messages disrupting workflow Authenticated bypass list in Admin Console
Microsoft 365 Bypass Trusted sources, calendar invites, critical notifications Exchange transport rule with X-IPW-Ignore: True
Calendar Invite Bypass Calendar functionality breaks, delegate issues Transport rule for “Calendaring” or adjust INKY settings

 

Important Security Notes Across All Categories:

  • Bypasses should only be used for highly trusted, authenticated sources and reviewed regularly. Each bypass reduces INKY’s protection and can create blind spots if misapplied.
  • Bypass rules reduce your protection layer; only trusted, authenticated senders should be included.
  • Even with bypass rules, unauthenticated or spoofed messages will be analyzed or blocked.
  • Regularly review and prune bypasses to maintain good security hygiene.
  • If you're managing calendar invites, be aware that some bypass rules or settings may cause those messages to skip banners; you can adjust how calendar invites are handled by INKY as needed.

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section