0

We are a medium-sized company planning to switch our spam filter service. Right now, our computing solution provider hosts a Barracuda service on its server. Our emails are routed there and filtered before being sent to Microsoft 365.

Our plan is to switch to Defender for Office 365. We could just change our MX records right away to send everything straight to Microsoft 365, but I'd rather do a smoother transition by first having only a couple of email addresses bypassing the Barracuda. This way we'll see how Defender reacts to unfiltered emails.

Is there any way to bypass spam filtering in Barracuda for only specific email addresses? Our provider says it's impossible, but somehow I feel like that should be doable. Or is there any other way to have emails go straight to Microsoft 365 for some addresses?

Edit: Or can Barracuda not filter emails for specific email addresses?

Thanks in advance for your answers (and patience, this is my first question here)

3 Answers3

1
  • Log in to your Barracuda Cloud Control. Go to Email Security > Inbound Settings > IP Address Policies.
  • In the IP Blocking / Exemption section, use the top line to enter the IP addresses.
  • This process will need to be repeated for each IP address.
    In the Netmask field, type the subnet mask -Set the Policy field to Exempt. -If you'd like, add a note in the Comment field. -Click Add to whitelist the IP address.

https://campus.barracuda.com/product/emailsecuritygateway/doc/93197312/allow-list-and-block-list/?sl=AYHd5r5GQDjjXPjRc2Ag&so=8

If you are using Barracuda's Email Security Gateway (on-premises), follow these steps to whitelist Barracuda by IP address:

  1. Log in to your Barracuda Email Security Gateway web interface.
  2. Go to the BLOCK/ACCEPT > IP Filters page. In the Allowed IP/Range section, use the top line to enter the IP addresses
  3. This process will need to be repeated for each IP address.
  4. In the Netmask field type the subnet mask
  5. Set the Policy field to Exempt. If you'd like, add a note in the Comment field. Click Add to whitelist the IP address.
Ace
  • 478
  • 1
  • 6
  • Thanks! So if that's for IP addresses, can it be done for email adresses as well? I'll edit my question to specify it. – SenseiRalph Jul 08 '22 at 12:55
  • Check Barracuda Sentinel Allow Senders.https://campus.barracuda.com/product/sentinel/doc/79468265/how-to-allow-senders – Ace Jul 08 '22 at 12:55
0

The normal approach would be to use a separate rule for the bypassed source/destination address with relaxed filtering. If your SP doesn't support for a managed service that then that's pretty much it. For a hosted service it should always be possible.

However, for mail sources to send to different MXes specifically, you'd have to talk to the sources themselves, or create an intermediate relay to forward (by destination NAT) to your MXes depending on source address. That would massively complicate source-based mail filtering though...

Zac67
  • 10,320
  • 2
  • 12
  • 32
0

On Microsoft Exchange in mail flow - Connectors - Outbond Baracuda connectors - You can chose the specific domain to by pass from baracuda