Note on email deliverability
Info
Deliverability — the ability of an email to reach the recipient's main inbox — depends on many factors that are largely beyond the solution's control: quality of recipient lists, domain reputation, blacklists, the recipient's anti-spam filters, the email client and server used, SPAM reports by recipients, and so on.
BCdiploma makes every effort to optimize the deliverability of emails sent from the solution, but cannot be held responsible for their non-delivery given these many external factors.
Improving Email Deliverability to Business Domains (B2B)
Depending on your institution's security policy, it is possible that you, or recipients of certificates from your institution, may not receive emails from the BCdiploma solution. These deliverability issues are often caused by the recipient institution's firewall. If you notice these issues and/or wish to improve email deliverability, we recommend asking the technical support team of the recipient institution to follow the procedure provided by our email service provider.
For organizations using Microsoft 365 / Exchange Online, a detailed procedure is provided below.
Improving Email Deliverability in Microsoft 365 / Exchange Online
Intended audience
Microsoft 365 / Exchange Online administrators (IT teams of recipient organizations).
BCdiploma sends its transactional emails through the sending infrastructure of the Brevo solution (formerly Sendinblue). These emails are properly authenticated (SPF, DKIM, DMARC), but the Exchange Online / Microsoft Defender filters may still mistakenly place them in quarantine or in the "Junk Email" folder. These are false positives.
Important
BCdiploma recommends that recipient organizations perform the following three complementary operations on their Microsoft 365 / Exchange Online tenant:
- Allow (whitelist) Brevo's sending IP ranges through a mail flow rule;
- Allow the BCdiploma sender domains in the Tenant Allow/Block List;
- Release quarantined emails and report them as false positives to Microsoft.
Preliminary Check: No Block Entries
Before performing the operations below, check in the Tenant Allow/Block List (security.microsoft.com/tenantAllowBlockList) that no block entry targets the BCdiploma sender domains or the URLs contained in its emails (Domains & addresses and URL tabs, Block action). A block entry takes precedence over all allow entries: delete it if any.
Operation 1: Allow Brevo's IP Ranges (Mail Flow Rule)
IP whitelisting is done through a mail flow rule. To do so:
- Open the Exchange admin center
- Go to Mail flow → Rules
- Click + Add a rule
- Name:
Brevo (BCdiploma) - Bypass spam filtering - Apply this rule if the sender → IP address is in any of these ranges → enter the 10 CIDR ranges from the list below one by one
- Do the following: select Modify the message properties → Set the spam confidence level (SCL) → choose "Bypass spam filtering"
- "Set rule settings" step: the default values are fine
- Next → Finish
- In the rule list, enable the rule (it is created disabled by default).
The rule usually takes effect within 30 minutes to 1 hour (propagation).
List taken from Brevo's official SPF record (spf.brevo.com, as of 2026-07-29):
185.41.28.0/22
94.143.16.0/21
185.24.144.0/22
153.92.224.0/19
213.32.128.0/18
185.107.232.0/22
77.32.128.0/18
77.32.192.0/19
212.146.192.0/18
172.246.0.0/18
Security recommendation: restrict to BCdiploma sender domains
It is recommended to combine the authorization of all Brevo IPs with a condition on the sender domains (bcdiploma.com and your custom sending domain if you have one configured). The rule then only applies to emails coming from Brevo IPs AND sent by BCdiploma.
Operation 2: Allow the Sender Domains (Tenant Allow/Block List)
In addition to the IP-based mail flow rule, create allow entries for the sender domains in the Tenant Allow/Block List:
- Open the Tenant Allow/Block Lists page of the Microsoft Defender portal: security.microsoft.com/tenantAllowBlockList (Policies & rules → Threat policies → Rules section)
- On the Domains & addresses tab, click Add → Allow
- Enter the sender domains, one per line:
bcdiploma.comand your custom sending domain if you have one configured - Remove allow entry after: keep 45 days after last used date
- Optionally add a note (e.g.
BCdiploma - legitimate transactional emails), then click Add
Important
Make sure to also add your own sending domain (e.g. certificate.myschool.com) in addition to the bcdiploma.com domain at step 3.
Operation 3: Release Quarantined Emails and Report False Positives
If BCdiploma emails are already in quarantine, they must be released and reported as false positives to Microsoft. This operation remains necessary even when operations 1 and 2 are in place. Indeed, messages classified as high confidence phishing by Microsoft are quarantined regardless of the rules in place. The classification is visible in the Quarantine view, Quarantine reason column.
Important
The false positive report, integrated directly into the quarantine release action, is decisive to stop encountering the problem in the future: each submission trains Microsoft's filters at the service level and makes the blocking disappear over time, without having to maintain allow lists manually. Make sure to check this option in the steps below.
- Open the Quarantine page of the Microsoft Defender portal: security.microsoft.com/quarantine?viewid=Email
- Filter on the BCdiploma messages and select them (100 messages maximum per batch; repeat if needed)
- Click Release
- In the release panel, check Submit the message to Microsoft to improve detection (false positive)
- Then check Allow this message: Microsoft creates allow entries (sender and URLs) in the Tenant Allow/Block List. Only allow entries created through a submission override the high confidence phishing verdict (the ones created manually in operation 2 cannot)
- Keep the default duration 45 days after last used date (the longest-lasting value), optionally add a note (e.g.
BCdiploma - legitimate transactional emails), then click Release message