INKY bypasses, or whitelisting, allow trusted senders or specific email types to skip INKY’s security analysis to reduce unnecessary warnings on automated or safe messages. The way you set up bypasses depends on your email platform.
Bypassing INKY in Google Workspace:
- Use the Authenticated Email Bypass List to exempt automated messages (e.g., newsletters, ticketing alerts) from bannering.
- Important: Messages must pass DMARC authentication (SPF or DKIM) to bypass INKY; unauthenticated mail is still analyzed.
- To create the bypass list:
- Go to Google Admin Console > Apps > Google Workspace > Settings for Gmail > Routing > Manage address lists.
- Add an address list named IPW-Auth-Bypass with sender addresses to bypass.
- Ensure "Authentication required" is selected.
- Then apply this list to the existing INKY mail routing rule under Compliance > Content compliance.
- Review your bypass list quarterly to remove outdated entries.
More details and step-by-step instructions are available in the Bypass INKY in Google Workspace article.
Category: Authenticated Email Bypass List
Extreme Scenarios:
- Use only for automated messages from trusted sources (e.g., ticketing systems, newsletters, check-in notices) that do not require security warnings.
- Messages must pass DMARC authentication (SPF or DKIM). Unauthenticated email will still be analyzed.
- Apply when legitimate business systems are being flagged or modified by INKY, causing workflow disruption.
- Never bypass unauthenticated or unknown senders; this is a security risk.
- Review bypass lists quarterly to remove outdated entries.
How to Apply:
- Create an address list in Google Admin Console and require authentication.
- Apply the list to your INKY routing rule for content compliance.
Only authenticated, trusted senders are exempt from INKY banners and scanning [please refer to https://feedback.inky.com/en/help/articles/6567030-bypass-inky-in-google-workspace for more info].
Bypassing INKY in Microsoft 365
- Set up Exchange transport rules that add the header X-IPW-Ignore: True to messages that should bypass INKY analysis.
- Common use cases include calendar invites, internal newsletters, or trusted automated notifications.
- Create rules in Exchange Admin Center > Mail Flow > Rules:
- Name the rule following your INKY installation conventions.
- Set conditions to match the intended emails (by sender, message type, etc.).
- Modify message properties to add the X-IPW-Ignore header with value True.
- Set rule priority directly after the base INKY bypass rule.
- Use envelope-based sender matching to minimize spoofing risks.
- Test by sending matching emails to confirm no banners and no link rewriting.
- Review rules quarterly to minimize security blind spots.
For full guidance, see the Bypass INKY Protection for Specific Email in Microsoft 365 article.
Category: Exchange Transport Rule (Header-based Bypass)
Extreme Scenarios:
- Use for calendar invitations from scheduling tools (Calendly, Zoom), internal newsletters, automated notifications, encrypted email, or service accounts sending legitimate bulk mail.
- Apply when INKY modification causes rendering issues, breaks workflows, or interferes with critical business systems (e.g., calendar delegate functionality, system notifications).
- Only bypass verified, trusted sources. Each bypass reduces protection—minimize and review regularly.
- Prefer envelope matching for external senders to prevent spoofing.
How to Apply:
- Create an Exchange transport rule that sets the header X-IPW-Ignore: True for matching emails.
- Set rule priority just after the INKY base bypass rule.
- Test and monitor bypassed traffic to ensure legitimacy [please refer to https://feedback.inky.com/en/help/articles/2911338-bypass-inky-protection-for-specific-email-in-microsoft-365 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7093220 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7065141 for more info].
Calendar Invites Bypassing INKY
Category: Special Message Type/Transport Rule
Extreme Scenarios:
- Apply when INKY processing breaks calendar invite functionality (e.g., delegate invites, meeting requests) or causes rendering issues in clients.
- Use for trusted scheduling tools or internal calendar systems only.
- If INKY banners or modifications disrupt calendar workflows, bypass calendar-type messages via transport rule.
- Alternatively, adjust INKY’s “Special Message Types” setting to banner all calendar invites, but this may add banners to legitimate meeting requests.
How to Apply:
- In Microsoft 365, create a transport rule for messages with type “Calendaring” to set X-IPW-Ignore: True.
- Set rule priority after the main INKY bypass rule.
- In INKY Admin Center, adjust “Special Message Types” to “Modify all messages” for broader banner coverage if needed.
- Limit calendar bypasses to trusted sources to avoid blind spots [please refer to https://feedback.inky.com/en/help/articles/8383738-calendar-invites-bypassing-inky for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7030528 for more info] [please refer to https://kaseya.zendesk.com/agent/tickets/7016578 for more info].
Best Practices Across All Categories
- Minimize bypass rules; each creates a potential blind spot.
- Use specific sender addresses, not broad domains.
- Require authentication for Google Workspace bypasses.
- Document and audit bypass rules regularly.
- Monitor bypassed traffic for abuse or compromise.
- Coordinate whitelisting in both INKY and your mail platform (Microsoft/Google) for consistent delivery [please refer to https://feedback.inky.com/en/help/articles/6567030-bypass-inky-in-google-workspace for more info] [please refer to https://feedback.inky.com/en/help/articles/2911338-bypass-inky-protection-for-specific-email-in-microsoft-365 for more info] [please refer to https://feedback.inky.com/en/help/articles/8383738-calendar-invites-bypassing-inky for more info] [please refer to https://help.graphus.kaseya.com/help/Content/07_Configuring_whitelisting/Graphus_whitelisting_options_bp.htm for more info].
Summary Table
| Category | When to Apply (Extreme Scenarios) | How to Apply |
|---|---|---|
| Google Workspace Bypass | Trusted, authenticated automated messages disrupting workflow | Authenticated bypass list in Admin Console |
| Microsoft 365 Bypass | Trusted sources, calendar invites, critical notifications | Exchange transport rule with X-IPW-Ignore: True |
| Calendar Invite Bypass | Calendar functionality breaks, delegate issues | Transport rule for “Calendaring” or adjust INKY settings |
Important Security Notes Across All Categories:
- Bypasses should only be used for highly trusted, authenticated sources and reviewed regularly. Each bypass reduces INKY’s protection and can create blind spots if misapplied.
- Bypass rules reduce your protection layer; only trusted, authenticated senders should be included.
- Even with bypass rules, unauthenticated or spoofed messages will be analyzed or blocked.
- Regularly review and prune bypasses to maintain good security hygiene.
- If you're managing calendar invites, be aware that some bypass rules or settings may cause those messages to skip banners; you can adjust how calendar invites are handled by INKY as needed.