Allowlist and Blocklist entries work by matching email addresses from the right against certain headers (Xref) What headers are checked? . The email address and the allowlist entry are deconstructed into "words" on the . (dots)and @ (at) characters. These words are then matched right to left. This means that an entry of will match, and , but not The leftmost character of the entry should not be @ (at) or . (dot) or the entry will not work.

The safest entry to put in the allowlist is the full user@domain.ext but if you communicate with many different people from the same company, you might want to just add domain.ext to your allowlist.

If you want to block an entire domain, you can just add domain.ext to your blocklist.

Some examples of allowlist and blocklist matching

