Important change: Releasing a message no longer allow-lists the sender

Releasing a message from quarantine used to do something you didn’t ask for: it quietly added the sender to your allow list. As of this week, Release just releases. Allow-listing is now a separate choice you make deliberately.

The old behavior was meant as a convenience — you clearly wanted this message, so presumably you’d want the next one from the same sender. In practice that assumption was wrong often enough to cause problems. A newsletter you wanted to read once earned a permanent pass. A spoofed sender you released in order to inspect it got exactly the same treatment. Allow lists filled up with entries nobody chose, and because none of it was announced, the usual way people found out was when something got through that shouldn’t have.


What Changed

The Release button is now a split button. Click the main part of the button to release a message and nothing else. Click the small arrow beside it for two new options:

  • Release & allow sender
    Delivers the message and adds that exact email address to the allow list
  • Release & allow sender domain
    Delivers the message and adds the entire sending domain to the allow list

Both options confirm exactly what was added when they finish. The same two options are available from the menu on each individual message, and from the Options menu when you open a message to read it.


Domain Administrators: Domain-Wide Allow Lists

Clearing your own quarantine and working through a domain’s message list are two different jobs. An allow entry you add while doing the second should apply to everyone on the domain — not land in your personal list, where nobody else benefits from it.

So the destination now follows the page you’re working from:

  • From the domain messages page → the domain-wide allow list
  • From your own quarantine → your personal allow list
  • From an individual user’s message list → that user’s allow list

This carries through to messages you open from the domain list as well — release and allow from there and the entry still goes domain-wide. The confirmation message always tells you which list it landed in. Adding to a domain-wide allow list requires technical administrator rights on that domain.


A Few Details Worth Knowing

  • Your spam filter still learns from every release
    Releasing a message still tells the filter it got that one wrong, and that hasn’t changed. Only the allow-list entry is gone, so you keep the training benefit without the standing exception.
  • Failures are visible now
    If an allow-list entry can’t be created — most commonly because the sender is on your own domain — you’ll be told. Previously this failed silently.
  • Outbound messages don’t offer these options
    There’s no allow list to add an outbound sender to, so the options simply aren’t shown.

What You Should Do

Nothing is required. The change is already live, and everything keeps working as before.

That said, it’s worth reviewing your allow list. Anything that accumulated under the old behavior is still there, and some of those entries are probably ones you would never have added on purpose. You’ll find it under Allow List for your own account, or on the Domain Settings page for a domain-wide list.


Why We Made This Change

An allow list is a standing instruction to skip filtering for a sender. That’s a meaningful decision, and it shouldn’t be a side effect of clearing out your quarantine.

Releasing one message and trusting a sender forever are different intentions, and the old behavior collapsed them into a single click. Now each one has its own button, and your allow list contains what you put in it.


If you have questions about how this affects your environment, or you’d like help reviewing your allow lists, feel free to reach out. We’re happy to help.