This article explains how to allowlist Arsen in Barracuda so your phishing simulations and training emails are delivered correctly to your users.
This configuration is useful if your Arsen phishing simulations show unexpected clicks, opens, or attachment events and your organization uses Barracuda as its Secure Email Gateway. These events may be caused by Barracuda scanning simulation emails before they reach users. Allowlisting Arsen helps reduce automated security scans that can create inaccurate campaign results.
1 - Objectives
This article explains how to:
Recognize the typical symptom of Barracuda interfering with simulation tracking
Review every Barracuda area where Arsen may need to be exempted
Allowlist Arsen by IP address, Intent Analysis, SPF, ATP, and Sentinel (cloud and on-premises)
Test your configuration and know what to share with Arsen support if issues persist
2 - Prerequisites
Access to your Barracuda administrator console.
Permission to edit inbound email, anti-phishing, sender authentication, machine learning, impersonation protection, and ATP settings.
The list of active Arsen phishing domains from your Arsen account settings.
Optional: if you allowlist Arsen by IP address, the latest Arsen sending IP addresses.
These instructions apply to a third-party product. Barracuda interfaces and labels may change over time. If a setting is not available in your environment, contact Barracuda support or your email security administrator.
3 - Typical Symptom
A campaign email is delivered, but the recipient appears as clicked almost immediately, before a user could realistically interact with the message.
This usually indicates that Barracuda scanned or rewrote the message before delivery.
4 - Export the Full Arsen Domain List
To avoid missing an active simulation domain:
Open Arsen phishing domains.
Use the export button.
Add every active Arsen phishing domain used in your campaigns to the relevant Barracuda exemption lists.
5 - Barracuda Areas to Review
If you are investigating false clicks, review these Barracuda areas one by one. Depending on your Barracuda product and configuration, you may need to allowlist Arsen in several places, not just one.
IP Address Policies or IP Filters
Intent Analysis or URI Exemptions
Sender Authentication / SPF
Advanced Threat Protection (ATP)
Allowed Senders in Barracuda Sentinel
Impersonation Protection
Inbound > Anti-Spam/Antivirus
Inbound > Sender Policies
Inbound > Anti-Phishing
Inbound > Machine Learning
6 - Allowlist Arsen by IP Address
If you use Email Delivery through our API integration (Direct Mail Injection), this step is not relevant.
Use this section if you want Barracuda to allow Arsen simulation emails based on Arsen sending IP addresses.
Cloud: Barracuda Email Security Service
Log in to Barracuda Cloud Control.
Go to Email Security.
Open Inbound Settings.
Select IP Address Policies.
In IP Blocking / Exemption, enter one Arsen sending IP address.
In Netmask, enter
255.255.255.255.Set Policy to Exempt.
Optional: add a comment such as
Arsen phishing simulation IP address.Click Add.
Repeat the process for each Arsen sending IP address.
On-premises: Barracuda Email Security Gateway
Log in to the Barracuda Email Security Gateway web interface.
Go to BLOCK/ACCEPT.
Open IP Filters.
In Allowed IP/Range, enter one Arsen sending IP address.
In Netmask, enter
255.255.255.255.Set Policy to Exempt.
Optional: add a comment such as
Arsen phishing simulation IP address.Click Add.
Repeat the process for each Arsen sending IP address.
7 - Exempt Arsen from Barracuda Intent Analysis
Barracuda Intent Analysis may rewrite or modify links inside emails. For phishing simulations, this can affect tracking, landing pages, and campaign results.
To avoid this, add Arsen domains to the Intent Analysis exemption list.
Cloud: Barracuda Email Security Service
Log in to Barracuda Cloud Control.
Go to Email Security.
Open Inbound Settings.
Select Anti-Phishing.
In the Intent section, add the Arsen phishing domains.
Set the policy to Ignore.
On-premises: Barracuda Email Security Gateway
Log in to the Barracuda Email Security Gateway web interface.
Go to Basic.
Open Spam Checking.
Locate the Intent Analysis section.
Add the Arsen phishing domains to URI Exemptions.
Save your changes.
8 - Exempt Arsen from SPF Checks
Use this section if your Arsen campaigns spoof your own domain or send simulations that need to bypass strict SPF checks.
Cloud: Barracuda Email Security Service
Log in to Barracuda Cloud Control.
Go to Email Security.
Open Inbound Settings.
Select Sender Authentication.
In the Sender Policy Framework section, add the Arsen sending IP addresses to the SPF exemptions table.
Save your changes.
On-premises: Barracuda Email Security Gateway
Log in to the Barracuda Email Security Gateway web interface.
Go to Email Security.
Open Block/Accept.
Select Sender Authentication.
In Sender Policy Framework (SPF) Configuration, select Yes.
Add the Arsen sending IP addresses to the SPF exemption list.
Save your changes.
9 - Exempt Arsen from Advanced Threat Protection (ATP)
Barracuda Advanced Threat Protection (ATP) may scan links or attachments in Arsen simulation emails. This can create false clicks, false attachment opens, or inaccurate campaign results.
If you use Email Delivery through our API integration (Direct Mail Injection), this step is not relevant.
If you use ATP, add exemptions for the Arsen sending IP addresses.
Barracuda Email Security Gateway
Log in to the Barracuda Email Security Gateway web interface.
Open ATP Settings.
Enter the Arsen sending IP address.
Enter the matching subnet mask.
Click Add.
Repeat the process for each Arsen sending IP address.
10 - Add Arsen to Barracuda Sentinel Allowed Senders
If you use Barracuda Sentinel, you can add Arsen senders or domains to the Allowed Senders list.
Log in to your Barracuda admin console.
Open Dashboard.
Click the Settings icon.
Select Allowed Senders.
In Sender Email or Domain, enter one Arsen sender email address or domain.
Optional: add a comment such as
Arsen phishing simulations.Click Save.
Repeat the process for each Arsen sender or domain.
Barracuda Sentinel usually allows only one sender or domain to be added at a time.
11 - Test Your Configuration
After completing the allowlisting steps, run a small test campaign before launching a full simulation.
Recommended test
Create a campaign for 1 or 2 internal test users.
Send the campaign.
Confirm that the email is delivered to the inbox.
Confirm that links are not rewritten unexpectedly.
Confirm that clicks, opens, attachments, and landing-page activity are reported correctly in Arsen.
If delivery or tracking does not work as expected, review your Barracuda rules and confirm that all required Arsen IP addresses, senders, and domains have been added.
12 - If Automatic Clicks Continue After Allowlisting
In Barracuda, a single exemption is often not sufficient. In some environments, automated clicks continued until Arsen was allowlisted in several protection layers, not only in ATP or a single whitelist location.
If the issue persists:
Confirm that the exact phishing domain used in the campaign is included in your Barracuda exemptions.
Confirm that the required Arsen domains, senders, and IP addresses have been added in every relevant Barracuda protection area.
Check whether Barracuda or another security product rewrote the link in the email.
If the link was rewritten, review other security layers as well, such as Microsoft Safe Links.
13 - What to Share with Arsen Support if the Issue Continues
Please provide:
Your Barracuda product type: cloud, on-premises, Sentinel, or ATP.
The affected campaign name.
The affected test recipient.
The exact phishing domain used in the campaign.
Screenshots or details of the Barracuda exemption areas already configured.
Any Barracuda logs or message trace details available.
Whether the email link was rewritten before delivery.
Your technical contact at Barracuda, if available.
