Skip to main content

Riot in Libraesva

Configure Libraesva for Riot phishing simulations

1️⃣ Before you start :

This article explains how to whitelist Riot's phishing simulation and training emails in Libraesva, so they reach your employees' inboxes and clicks are tracked correctly.


First essential check: make sure you have administrator (super admin) access to your Libraesva console. If you purchased Libraesva through a partner, your permissions are often limited. In that case, the request will have to go through your partner (see section 3).

☝️ Pre-requisites:

  • Administrator (superadmin) access to Libraesva, or a partner able to make the change.

  • The list of your Riot sending domains, available under Settings > Domains in your Riot workspace.

2️⃣ If you are an administrator:


👉 Whitelist the sending domains

Step 1: Log in to the Libraesva admin console.

Step 2: Go to Admin Area > Content Analysis > Whitelists & BlocksLists.

Step 3: Click the New button to create a new whitelisting rule.

Step 4: In the From Address/Sender field, enter Riot's sending domains (retrieve them under Settings > Domains in your Riot workspace).

Step 5: Do not tick the Check Envelope Only box, so the system checks both envelope and header data for a more robust whitelist.

⚠️ Important: Leave the Check Envelope Only box unchecked.

👉 Bypass URL sandboxing (URL Sandbox)

Step 6: Go to Content Analysis > Sandbox Filters > URLSand tab > Exceptions > New, then add your domain in both forms: *.yourdomain.com/* and yourdomain.com.

👉 Save and test

Step 7: Click Save/Apply. Changes can take up to 10 minutes to take effect. Then send a test campaign to 2 or 3 users to confirm emails land in the inbox and clicks are tracked correctly.

☝️ Good to know: Changes can take up to 10 minutes to apply. Always test on 2 or 3 users before launching a larger campaign.

3️⃣ If you are not an administrator:

If you do not have superadmin rights (common when Libraesva was purchased through a partner), forward the request to your partner or IT team. You can use the template below.

"Hello,

I'm writing to request whitelisting of our sending domains on our Libraesva ESG. These domains are used to send phishing simulation and training emails:

  • (list here the domains shown under Settings > Domains in your Riot workspace)

Could you please:

  1. Authorize them as senders in the Whitelists & BlocksLists section (From Address/Sender field), so the emails pass through the security filters.

  2. Also add the same domains to the URL Sandbox exception rule (Content Analysis > Sandbox Filters > URLSand > Exceptions), to prevent training links from being blocked or delayed.

Please let me know if you need any further information to complete the setup.

Thank you and best regards,"


4️⃣ Key takeaways:

  • First check whether you are a Libraesva administrator (superadmin). If not, the request goes through your partner.

  • Whitelist your Riot sending domains in Whitelists & BlocksLists, without ticking Check Envelope Only.

  • Also add these domains to the URLSand exceptions to avoid links being blocked or delayed.

  • Allow up to 10 minutes for propagation, then test on 2 or 3 users.

Did this answer your question?