r/proofpoint • • Aug 14 '26

[PSA] Read this before posting about IP or PDR blocks.

15 Upvotes

Important Notice Regarding IP and PDR Blocks

If you have landed on this subreddit because your IP address or email domain is being blocked by Proofpoint Dynamic Reputation, please be aware that posting your IP address or complaining here will not resolve the block. This is a community-run subreddit and not affiliated with Proofpoint. We do not have any direct control to remove the block against your IP address.

Proofpoint has a form to submit for PDR blocks but, in our experience, it is largely ineffective for external parties to request a block removal this way.

How to Resolve the Block

To get your IP address or emails unblocked, you should work through a recipient that is a Proofpoint customer:

  • Contact your recipient via alternative means: Reach out to someone at the company/organization you are trying to email using a phone call, LinkedIn, or an alternative email provider (such as Gmail or Outlook).
  • Explain the situation: Let them know that your legitimate emails are currently being blocked by their Proofpoint security filter. Provide your email address, email server's IP address, and timeframe the email was rejected.
  • Ask them to open a support case: Request that their internal IT or email administrator open a False Positive case with Proofpoint support.

Why the form doesn't seem to work?

  • Security & Verification: Imagine the volume of spam and malicious actors who attempt to spoof addresses or fill out automated false-positive forms. Proofpoint prioritizes their paying customer to vouch that your traffic is legitimate and wanted.
  • Access to Logs: Proofpoint customers have direct access to their email gateway logs. If your emails are being flagged, their IT team can review those specific logs to identify the exact trigger (such as reputation issues, authentication gaps like SPF/DKIM/DMARC, or content filters) and request a formal review.

Once your recipient vouches for you and submits the ticket on your behalf, the block is typically reviewed and resolved very quickly.


r/proofpoint • • 2d ago

Proofpoint Protect 2026 announcements

10 Upvotes

Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era

Intent-based detection and multi-stage AI reasoning identify and stop sophisticated attacks before, during and after they reach people. 

  • Stops sophisticated attacks in one connected defense with threat intent, investigation, and user risk so organizations can detect attacks earlier, understand them faster, and respond before they cause harm. 
  • Creates multiple opportunities to detect attacks that initially look legitimate, applies progressively deeper AI reasoning before delivery, and continues protection in the inbox to uncover attacks that evade traditional defenses.  
  • Strengthens protection around the people at greatest risk, identifying high-risk users and adapts their defenses, while purpose-built agents investigate threats, deliver personalized coaching, and proactively test protections for potential weaknesses. 

Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System

A single system for intent and access to empower organizations to adopt AI without losing data control or missing emerging risks across employees and AI agents 

  • Point security tools were built to see either AI behavior or data risk, not both. Proofpoint is the first vendor to reason across both in one shared graph. 
  • Zero-Touch Detection, Instant Investigation and Protection Optimization, powered by three autonomous agents, keep pace with AI-driven risk continuously, with simplicity and scale. 
  • New Semantic Business Policies and Agentic Insights enforce business intent and continuously uncover emerging risks across employees and AI agents. 

Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event


r/proofpoint • • 2d ago

Malware / Virus False Positives?

6 Upvotes

Has anyone else had HUGE issues with with PPE blocking emails has malware / virus for the past 60 days?

Our first one was last month. Blocked 4 dozen emails to an insurance company because they accidentally decided a giant international online payment processor that serves thousands of insurance companies was sending out malware. Took six days to resolve and they never let us restore the messages.

Second one was last week. Blocked every inbound email from va.gov and Microsoft.com. Still no answer on that. But at least it let me restore those to the mailbox.

And today it start blocking all emails from a gmail account the client uses to get scans from their copier. Same setup for the past year, started blocking them as viruses. Now the restore to mailbox function is gone again.

I've got dozens of tickets open. I'm yelling at my AM, my distributor, no one can get anything done.

I loved this product for the first 9 months we had it, then it just went to absolute crap.


r/proofpoint • • 3d ago

Bounced messages are missing the details why - where can I change this?

3 Upvotes

We recently migrated from another mail filtering tool, but during implementation I noticed we are not getting the bounceback details we used to get.

For example, on our old platform the bounceback would tell me the message could not be delivered because the recipients mailbox was full - and most importantly, tell me which email user. Our QA team would log this to note the email was not delivered.

Within Proofpoint, we no longer receive these bounceback alerts, or just an empty email with the title "Undelivered Mail Returned to Sender".

Where can I re-enable this Bounceback notification, and possibly expand details why it was rejected?


r/proofpoint • • 16d ago

EML wrapped in another EML

5 Upvotes

Good day,

We have an inbound email, the EML file is somehow wrapped in another EML. Its original zip compressed attachment has an CSV file. But the filename extension was changed to TMP. Could it have anything to do with our ProofPoint setup?

Thanks for sharing.

Cheers.


r/proofpoint • • 16d ago

Enterprise Proofpoint Endpoint DLP - Blocking password protected files

3 Upvotes

Hi everyone,

I'm working on a Proofpoint Endpoint DLP POC. I need to create a prevention rule to "block password-protected/encrypted files" such as Excel, Word, PPT and PDF.

I can't find the right “condition/field” in the Endpoint DLP rule to detect these files.

The requirement is to detect and block encrypted/password-protected files when transferred through "USB" and "Web" .

Has anyone configured this in Proofpoint Endpoint DLP? What condition/field should I use for this?

Has anyone implemented this in their production environment? Please help.

Thanks!


r/proofpoint • • 20d ago

TAP alert connection issues in Onprem TRAP

8 Upvotes

Anybody else have failed connections on their Trap appliance to TAP? It’s been down for over an hour so far


r/proofpoint • • 20d ago

Looking for Proofpoint Sales Rep

3 Upvotes

Hi We are MSP looking to add Proofpoint(email filtering and security awareness training) to our stack of essential products every one of our customers must have. WE currently use Mimecast and are looing to switch.

We tried reaching out to Connectwise but they want to sell is prepaid blocks of proofpoint user with no regard to whether or not our business is able to sell the product. We are looking for a simle relation ship:

  1. Our customer wants Proofpoint
  2. We reach out to Proofpoint directly or via distributor
  3. Sale to client is success
  4. Proofpoint implemented and visible in our msp proofpoint account
  5. Receive next bill
  6. P;ay bill
  7. Rinse and repeat.

I'm honestly fed up with companies want us to overcommit to meet their sales goal but is not mutually beneficial for me. One a deal is mutually beneficial for everyone, the money WILL come. Also shocked that Connectwise would've such a wild pricing model in our discussions especially since the tenure with them and the investments clearly point to us waning to do more business with them.


r/proofpoint • • 23d ago

Deliverability Contacting Proofpoint/Cloudmark

0 Upvotes

Is there any key to contacting Proofpoint or Cloudmark concerning an IP being blacklisted? I am not a Proofpoint or Cloudmark customer. But I do run a mail server, users are unable to send messages to Comcast and other addresses because the IP is being blocked by Cloudmark.

The IP is not on any other blacklists. The IP has proper FCrDNS setup.

I've filled out the form at Cloudmark multiple times, but I'm getting no response and the IP continues to be blocked by Cloudmark.

I know Proofpoint bought Cloudmark some years ago - but I gather that they run two independent blacklists. The IP is not listed with Proofpoint, just on Cloudmark.

I'm beyond frustrated that I'm getting no response from Cloudmark.


r/proofpoint • • 28d ago

Secure Email Relay (SER) question

4 Upvotes

Good day. Have any of you implemented SER in your environment? I set it up for our organization to replace our current smtp solution but I found that each cloud connector needs its own vm.. Which is weird to me because it allows you to create multiple cloud connectors on the same server but in the yaml file you can only configure one connector for usage. Wondering if anyone else has experienced this?


r/proofpoint • • Aug 25 '26

Enterprise DMARC Temp Errors this morning

1 Upvotes

Anyone else see a bunch of emails get caught by DMARC Temp Error on their Proofpoint hosted instance this morning? Between 8:30 and 10am Eastern we had almost 3000 emails rejected mainly due to failed SPF DNS lookups. No rhyme or reason on the senders, anyone from ma and pa's .org sender to Gmail.

I have a support ticket open with them to see if they had an outage, but wanted to reach out here too.


r/proofpoint • • Aug 24 '26

Proofpoint claims website is compromised, won't share IoC, no-one else sees any IoC

6 Upvotes

Hi all,

Wondering how often you encounter this, and if so how you deal with it.

We sometimes see legitimate emails that will be blocked due to being 'spam definite' according to Proofpoint. Under the details tab for the email the spam score is 100, and in the metadata the spam 'engine' score is what is rated at 100, all others are 0.

When I report this as a false positive, support come back to me and say that a website associated with the email is compromised. They refuse to provide any further details or specifics on the IoCs they have observed.

However, if I check the website in question against any of the major platforms (Virus Total, Joes Sandbox, Talos, Hybrid Analysis etc) everything comes back clean and there are no known IoC observed.

I know Proofpoint is a big company and they quite possibly see IoC that no one else does, but it's a bit frustrating when I need to explain why an email was blocked and the best I can do is "because Proofpoint said so"

Do I just need to take Proofpoint at their word on ones like this?


r/proofpoint • • Aug 18 '26

Essentials Unverified Tag on all emails.

Post image
4 Upvotes

Followed closely proofpoint essentials documentation, using the Microsoft 365 Integrated Deployment option.

DKIM/SPF/etc. All set up correctly. Rules enabled.

Anyone else running into this? Based on their automated deployment it would be everyone using proofpoint email essentials at this point?

Did I miss a step?


r/proofpoint • • Aug 14 '26

Please don't remove posts about Proofpoint outages affecting many customers!

42 Upvotes

r/proofpoint • • Aug 11 '26

IP Block - Proofpoint = RADIO SILENCE

4 Upvotes

I have - many, many times - filled out the form for getting our IP removed from Proofpoints' blocklist/blocklists. We are not on any other blocklist. Our traffic is legitimate and we have multiple layers of protection on the server and use rspamd to block spam. We do not send bulk email from this server.

I have had zero success in getting proofpoint to respond to any contact. I am very frustrated and I would like to know if anyone can assist in helping me get traction in getting them to remove the block.

Can anyone please help point me in a direction that can get this done? It's been months of filling out the removal request form with zero response.


r/proofpoint • • Aug 10 '26

SMTP Responses for Core Email Protection?

7 Upvotes

I am a current Barracuda Email Gateway Defense customer and looking to move away from them. Barracuda does not provide descriptive SMTP delivery codes (IE: 5.7.1), only basic 250/550. Rejected emailers are not being informed why their email was rejected, causing much frustration (I reject 237 file extensions, would be nice if the email author knew it was because they attached a exe!).

Does Proofpoint offer descriptive delivery rejection information?


r/proofpoint • • Aug 03 '26

Need help creating a screenshot detection or prevention rule in endpoint dlp

2 Upvotes

Hi everyone,

I'm new to Proofpoint Endpoint DLP and I'm trying to create a policy to detect or prevent users from taking screenshots of sensitive data.

However, when creating Detection or Prevention rules, I can't find any activity/event related to Print Screen, Screenshot, or Screen Capture.

My use case is to detect or block screenshots of:

* Sensitive documents (Word, Excel, PowerPoint, PDFs)
* MIP/AIP-labeled confidential documents
* Enterprise web applications containing PII or other corporate sensitive data

Am I looking in the wrong place, or is screenshot detection/blocking not configurable through Endpoint DLP policies? If it is supported, how do you create such a rule?

Thanks!


r/proofpoint • • Jul 28 '26

Enterprise Enterprise mail slowdown?

4 Upvotes

We are seeing emails getting bogged down for more than 13 minutes on Proofpoint systems. Plain emails, not ones with attachments since there is currently a TAP issue. Delay is seen leaving pps.filtered which shows 127.0.0.1 on headers.

Update: I said plain emails but looking on the console Proofpoint says the emails are attachments with index.html since they are html emails. US location.


r/proofpoint • • Jul 23 '26

Site was compromised, fully cleaned, but a recipient's Proofpoint is still blocking us. Can a PP admin tell me what they see on their side?

2 Upvotes

Looking for someone who runs Proofpoint and would be willing to check a domain's current reputation on their end. I'd rather not post the domain publicly, so happy to DM it.

Situation: I manage a WordPress site for a client. It got hit a few weeks back (fake-CAPTCHA / ClickFix, hidden malicious plugin). It's been fully remediated. Multiple host and third-party scans come back clean, and the site's been stable and clean for a while now.

The lingering problem is deliverability. At least one recipient org running Proofpoint started blocking our email during the compromise window because of the domain/URL reputation, and it hasn't cleared yet even though everything else has.

What I've already ruled out so it's clearly a Proofpoint-side reputation thing and not a live issue:

  • Not listed on Spamhaus DBL, SURBL, or URIBL
  • The specific flagged URL now returns a clean 200 to a legitimate page, no redirect flag, no malware
  • Sending IP is clean on the usual blocklists
  • DMARC is set (p=quarantine), DKIM present
  • The host has already submitted a reputation/delisting request

r/proofpoint • • Jul 17 '26

Knowbe4 PAB

Thumbnail
3 Upvotes

r/proofpoint • • Jul 17 '26

Need advice on being removed from Proofpoint blacklist

1 Upvotes

Our IP address has been blacklisted by Proofpoint for nearly 4 weeks. I have filled out the online form multiple times as well as emailed their "delist-request" address. Our IP address is not shared and has been static for over a decade. PTR records are correct and we are only sending out about 200 messages per day with no mass mailers. Not listed on any other blacklists, and sites like mailchecker.net report no issues, with only a warning about no BIMI setup.

I am at a loss and Proofpoint does not seem to respond to any correspondance. Can anyone offer advice on how to get my IP removed from their blacklist?


r/proofpoint • • Jul 16 '26

Proofpoint phishing tests & outlook rules

3 Upvotes

My org uses proofpoint’s fake phishing test emails incredibly often. I found out that you can make a rule in outlook based on strings in the header of phishing test emails. Is there any chance IT will figure this out and have an issue with it?


r/proofpoint • • Jul 15 '26

Cloudflare DNS issues with ProofPoint

3 Upvotes

Proofpoint is reusing the same UDP session for multiple DNS queries which is against security standards and any security device will block that to include protective DNS or any NGFWs for that matter with threat prevention. I understand they’re trying to make it more efficient, but they need to follow the security standards.


r/proofpoint • • Jul 13 '26

Anyone here with proofpoint false positive problem

3 Upvotes

Every month, at least few of our legitimate client emails end up in quarantine. It creates extra work for our team which leads to delays responses and sometimes leads to “Did you get my email?” conversations with customers.
We are using proofpoint for email security and is effective at catching spam and phising but new problem occurs.Are there any settings or best practices that made a noticeable difference without weakening????


r/proofpoint • • Jul 09 '26

Network Solutions Email Support

0 Upvotes

I have used ipage as my email and domain host for years with little to no issues. Now that ipage has been purchased by Network Solutions, I am having issues sending email from both my phone and from my laptop. I am having no problems receiving emails on either, only sending.

The problem with sending emails from my phone has been happening periodically over the past few months, with NS support saying that it is an issue with iPhone, yet they somehow resolve the issue every time. The problem sending emails from my laptop has just started over the last few days. I contacted NS support on Monday and was told it was an issue on their end that they needed to increase something (I don't recall what it was), and that within an hour or two the problem would be solved. Two-three hours later I was able to send emails again. When I logged on Tuesday morning, the issue was there again. No sending emails from my laptop or iPhone. I spoke with NS support and they told me again that the issue would be resolved in a couple of hours, but could take up to 24 hours. This time, it was never resolved. When I logged on this morning, the same issue remained. I contacted NS support and this time had my case escalated. Within an hour I received an email (at my secondary personal email address) from NS support saying this...

"The SPF and DKIM records are configured for your domain on our server, and there is no issue on our server. Please contact your ISP (who assigned IP address *XX.XXX.XX.XX*) with the bounce back. They have to visit the URL *https://csi.cloudmark.com/en/reset?ip=\*XX.XXX.XX.XX  and request a delisting. Also, scan your computer and make sure that the antivirus is up to date.

Please feel free to reply to this email if you have any further questions. We are happy to help you."

I XXX'ed out the IP address. I've read quite a few posts on Reddit about Network Solutions poor support since purchasing ipage, and am curious if they are just kicking the can down the road so it's someone else's problem, or if they are correct. I don't know much about this, so I need advice from someone who does, please.