Docs / Obsidian Suite / For administrators
Allow and block lists
Allow and block lists override scoring for specific senders. They exist at three levels: global (all customers, maintained by Larström Technologies), organization (yours, managed by your administrators), and user (personal lists each user manages in the user portal).
Entry formats
| You enter | Matches |
|---|---|
[email protected] | Exactly that sender address (header From or envelope sender). |
@partner.com or partner.com | Any address at exactly that domain. |
*.partner.com | That domain and every subdomain (mail.partner.com, eu.partner.com and so on). |
203.0.113.7 or 203.0.113.0/24 | Mail from that connecting IP address or range (organization and global lists only). |
Entries are checked when you save them. Adding a pattern to the allow list removes it from the block list at the same level, and the other way round.
Which entry wins
- The most specific level decides: the recipient's personal list first, then your organization's, then the global list.
- Within one level, block beats allow.
So a user can allow a newsletter your organization blocks, and your organization can block something allowed globally.
What an allow entry does not bypass
- Viruses and malware.
- Attachment rules (blocked file types, macros, password-protected archives).
- A DMARC failure where the sender's domain publishes
p=reject. Allow-listing[email protected]never lets a forged copy of that address through.
Managing lists
Open Protect > Allow & block.
- Search and Level find entries by text and narrow them to organization or user entries.
- Add entry: Sender, domain or IP, List (Block or Allow), and an optional Note - why it was added. You will want this in a year.
- Remove deletes an entry. It takes effect within 30 seconds.
The table shows who added each entry and when. As an administrator you see your organization's entries and your users' personal entries.
Quicker ways to add entries:
- Allow / Block sender and Allow / Block domain on a message page;
- Block on the dashboard's Top unwanted senders and in the message inspector;
- your users' Release and always allow this sender and Report as spam and block sender (personal lists);
- the REST API.