Known vs. unknown sender classification
← All help articles · General / operational
Every source IP in a report is classified as known or unknown by matching it against the known-senders allowlist, scoped per domain: rules that apply globally (no specific domain) or to that exact domain are checked by CIDR match, in the order they were added, first match wins; anything left over is unknown.
This distinction drives which recommendation rules can even fire — R1-R3 (known-sender hygiene: fix your SPF/DKIM/alignment) only apply to known senders, while R5/R6 (possible spoofing) only apply to unknown ones. The same raw auth-failure data means something very different depending on which bucket the sender falls in.