How to Whitelist or Blacklist Email Senders in ISPConfig

This guide shows you how to whitelist or blacklist email senders in the ISPConfig control panel on your Noiz hosting account. A whitelist entry (sometimes called an allow list or safe senders list) tells the spamfilter that mail from a sender must never be tagged as spam. A blacklist entry (sometimes called a block list) tells the spamfilter that mail from a sender must always be treated as spam. You will learn how to add entries for a single sender or a whole sending domain, and how the Priority field decides which rule wins when a whitelist and a blacklist entry both match the same message.

Last reviewed: 27 July 2026, against ISPConfig 3.3.1p1. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.

Official Documentation Reference

Prerequisites

  • You can log in to the ISPConfig control panel.
  • At least one mailbox exists on your account. If not, first create an email mailbox in ISPConfig.
  • You know the exact sender address (for example [email protected]) or sending domain (for example @example.com) that you want to allow or block. These are placeholders; substitute the real sender details.
  • The spamfilter is enabled for the mailbox or domain the rule should protect. A mailbox whose Spamfilter setting is Uncensored is not filtered, so whitelist and blacklist entries have no effect on it.

How the Whitelist and Blacklist Work

Both lists live under the Email module in ISPConfig and act on the sender of incoming mail:

  • A whitelist entry means mail from that sender is never tagged as spam for the recipient you choose.
  • A blacklist entry means mail from that sender is always treated as spam for the recipient you choose.

Every entry is scoped to a recipient through its User field: it applies only to the mailbox or mail domain you select there, not to your whole account. The User list is built from the spamfilter records ISPConfig creates automatically for each mail domain and each mailbox, so email aliases and domain aliases do not appear in it. Scope the entry to the underlying mailbox or to the mail domain instead. Each entry also carries a Priority value from 1 to 10, which matters only when more than one whitelist or blacklist entry matches the same message; see the precedence section below.

Whitelist an Email Sender

Open the whitelist

  1. Log in to ISPConfig and click the Email module in the top navigation bar.
  2. In the left-hand menu, under the Spamfilter section, click Whitelist. A list of your existing whitelist entries appears.
  3. Click the Add Whitelist record button.

Complete the Whitelist form

The form opens on the Whitelist tab and has the following fields:

  1. User: select the recipient mailbox, or the whole recipient mail domain, that this rule protects. The entry applies only to the mailbox or domain you pick here.
  2. Email: enter the sender you want to allow.
    • For a single sender, enter the full address, for example [email protected].
    • For every sender at a domain, leave out the part before the @ sign, for example @example.com.
  3. Priority: a drop-down of 1 to 10 that defaults to 5 - medium. Leave it alone unless this entry needs to override a blacklist entry (see the precedence section below); 10 - highest is the strongest and 1 - lowest the weakest.
  4. Active: make sure this checkbox is ticked, otherwise the entry is saved but ignored.
  5. Click Save.

The new entry now appears in the list under Email > Spamfilter > Whitelist. Allow a minute or two for the change to be applied on the mail server before testing.

Blacklist an Email Sender

Open the blacklist

  1. In the Email module, under the Spamfilter section of the left-hand menu, click Blacklist.
  2. Click the Add Blacklist record button.

Complete the Blacklist form

The form opens on the Blacklist tab and mirrors the whitelist form:

  1. User: select the recipient mailbox or whole recipient mail domain that this rule protects.
  2. Email: enter the sender you want to block. Use a full address such as [email protected], or block every sender at a domain with @example.com.
  3. Priority: leave the default of 5 - medium unless you are combining this entry with a whitelist exception (see below).
  4. Active: make sure this checkbox is ticked.
  5. Click Save.

The entry now appears under Email > Spamfilter > Blacklist, and mail from that sender to the selected recipient is treated as spam from then on. Depending on how the spamfilter is configured on the mail server, blacklisted mail may be refused at delivery rather than filed in the junk folder, in which case the sender receives a bounce message.

Precedence: When a Whitelist and a Blacklist Entry Both Match

If only one entry matches a message, the Priority field does not matter and you can leave it at its default. It comes into play when more than one whitelist or blacklist entry matches the same message, typically a domain-wide rule in one list and a single-address rule in the other. The entry with the higher priority number wins (10 is highest, 1 is lowest).

A worked example using placeholder domains:

  • You blacklist the whole domain @example.com with priority 5, so all mail from that domain is treated as spam.
  • One correspondent at that domain is legitimate, so you whitelist [email protected] with priority 6.
  • Because 6 is higher than 5, mail from [email protected] is delivered normally while the rest of the domain stays blocked.

The same technique works the other way around: whitelist a whole domain and blacklist one troublesome address from it with a higher priority. As a rule of thumb, give the more specific entry the higher number.

Edit, Disable or Delete an Entry

  • To edit an entry, open Email > Spamfilter > Whitelist or Blacklist, click the entry in the list, change the fields and click Save.
  • To disable an entry temporarily without losing it, open the entry, untick Active and click Save.
  • To delete an entry permanently, click the delete button on the entry's row in the list view and confirm.

Troubleshooting

Symptom: mail from a whitelisted sender still lands in the junk folder. Open the entry and check three things: the Active checkbox is ticked, the User field points at the correct recipient mailbox or domain, and the Email value exactly matches the sender address shown in the message. Also allow a minute or two after saving for the change to reach the mail server.

Symptom: you whitelisted a domain but some of its mail is still flagged. Many senders use subdomains, for example news.example.com instead of example.com. An entry for @example.com does not automatically cover @news.example.com. Check the exact From address of an affected message and add a separate entry for the subdomain.

Symptom: mail from a blacklisted sender is still delivered to the inbox. Confirm the entry is Active and scoped to the right recipient in the User field. Check the whitelist for an entry that also matches the sender with an equal or higher Priority; if one exists, lower its priority or remove it. Finally, confirm the recipient mailbox actually has the spamfilter enabled: a mailbox set to Uncensored is not filtered at all, so blacklist entries are ignored for it.

Symptom: a whitelisted sender's mail is rejected outright rather than tagged as spam. A whitelist entry only changes what the spamfilter does with a message. It does not override checks that happen outside the spamfilter, so mail can still be refused for reasons such as an unknown recipient address or a mailbox that is over quota. Ask the sender for the exact wording of the bounce, or open a support ticket with it.

Symptom: ISPConfig refuses to save a new entry and reports that the maximum number of white- or blacklist records for your account has been reached. Your hosting account allows a set number of entries shared between the two lists. Delete entries you no longer need, or contact the Noiz support team about raising the limit. If the Spamfilter section is missing from the Email module menu altogether, that allowance is set to zero on your account, so ask the Noiz support team to enable it.

If you get stuck at any point, open a support ticket with the Noiz support team and include the sender address or domain you are trying to allow or block, the recipient mailbox it applies to, and a copy of an affected message's headers if delivery is not behaving as expected.

  • 0 Users Found This Useful
  • email, ispconfig, spam
Was this answer helpful?

Related Articles

How to Create an Email Mailbox With an Autoresponder and Forwarding in ISPConfig

This guide shows you how to create an email mailbox in ISPConfig that replies to every sender...

How to Migrate Maildir Emails from a Plesk Server to an ISPConfig Server

This guide walks you through migrating Maildir email accounts from a Plesk source server to an...

How to Create an Email Mailbox in ISPConfig

This guide walks you through creating a basic email mailbox in the ISPConfig control panel on...

How to Create an Email Alias in ISPConfig

This guide shows you how to create an email alias in the ISPConfig control panel on your Noiz...

How to Set Up Email Forwarding in ISPConfig

This guide shows you how to set up email forwarding in the ISPConfig control panel on your Noiz...