Allowlisting Zscaler proxy solutions

Overview

If your organization is using Zscaler proxy solution, you might need to perform additional allowlisting to make sure Hoxhunt works properly.

 

There are multiple symptoms that may be caused by Zscaler:

  • Hoxhunt add-in is experiencing sluggish performance
  • Hoxhunt add-in is forced to run in Compatibility Mode and/or Intranet security zone
  • Hoxhunt add-in's Task pane doesn't load properly or it's loaded in a separate browser window
  • Hoxhunt Results pop-up window doesn't load properly
  • Hoxhunt add-in works only on second attempt
  • User must access any URL with Edge browser before Hoxhunt add-in works
  • End users are unable to click through links in Hoxhunt's simulated threat emails
  • All fail links used in Hoxhunt training emails are inspected by Zscaler and blocked, preventing the user from failing the training email

 

Bypass Hoxhunt around Zscaler proxy

As a rule of thumb, Zscaler should not handle Hoxhunt's traffic. If possible, simply exempt *.hoxhunt.com. If this is not possible, exempt the following:

  • officejs.hoxhunt.com
  • api.hoxhunt.com
  • game.hoxhunt.com
  • app.hoxhunt.com
  • auth.hoxhunt.com

 

Exempt Hoxhunt from Cloud apps authentication

https://help.zscaler.com/zia/exempting-urls-cloud-apps-authentication

NOTE: This an important step. Skipping this step may result in SSO login issues to Hoxhunt platforms (if SSO is configured for your organization at Hoxhunt).

Exempt Hoxhunt from SSL inspection

https://help.zscaler.com/zia/skipping-inspection-traffic-specific-urls-or-cloud-apps
 

Create a Custom URL Category

You can download the up to date list of lookalike and training domains used in the Hoxhunt training from Admin Portal  -> Settings -> Email Delivery or fetch it via Hoxhunt's external GraphQL API. For more information, see article: Hoxhunt sender domains

Once you have received the list of domains:

  1. Go to Zscaler Cloud Portal - URL Categories
    (or navigate to Zscaler Cloud Portal > Administration > URL categories)
  2. Click on the pencil icon to edit your allowlist.
  3. Copy and paste the entire list of Hoxhunt training domains to “Add items” in URLs Retaining Parent Category.
    (TIP: You can use ".domain.com" syntax to ensure that subdomains are also allowlisted)
  4. Click Save.
  5. Select Activation > Activate.

Security Exceptions

You need to add the same list of domains (see above) to the Security Exceptions, otherwise malware scanning might affect the user's access to the fail links. For example, they might see the following error:

ERR_SSL_PROTOCOL_ERROR


The security exceptions can be found through the path below in Zscaler Cloud Portal:

Policy > Malware Protection > Security Exceptions


Cloud Firewall IPS Control & Advanced Threat Protection 
 

Note: This section applies only to organizations using Zscaler's Advanced Firewall or Advanced Threat Protection.

 

URL filtering allowlisting permits access to Hoxhunt domains even when they are classified as suspicious. However, it does not bypass Zscaler's IPS (Intrusion Prevention System) or Advanced Threat Protection layers, which inspect the behavior of network traffic using signature-based detection — not just the destination URL. Hoxhunt simulation templates that use credential harvesting pages can trigger blocks because their on-page behavior (simulating a login form, collecting input) matches known attack signatures, even when the domain is fully allowlisted in URL filtering.

Symptom: Users who click a fail link in a Hoxhunt simulation reach the page initially, but are then blocked mid-session with a security block page — typically matched against credential harvester or phishing-page behavior signatures. This most commonly appears when credential harvesting simulations are enabled, as basic simulations may not trigger these protections.

Fix: Add Hoxhunt simulation domains to Security Exceptions

Note: Creating an IPS Control allow rule alone is not sufficient to clear this block. The fix that resolves it is adding Hoxhunt domains to the Security Exceptions exclusion list in Advanced Threat Protection. The same exclusion set applies to Malware Protection.

In the Zscaler Cloud Portal, navigate to Policies > Cybersecurity > Inline Security > Advanced Threat Protection Policy > Security Exceptions.

Under Do Not Scan Content from these URLs, add Hoxhunt's simulation and lookalike domains. The current domain list is available in Admin Portal > Settings > Email Delivery, or via the Hoxhunt external API (see: Hoxhunt sender domains).

Save and activate the policy.

Note: This same Security Exceptions exclusion list is also referenced in Hoxhunt's general Allowlisting for Zscaler proxy solutions documentation. If your organization only recently enabled credential harvesting simulations, this step may have been completed during initial setup but not applied to the new simulation type — verify the domain list is current and complete.

 



For more information about Zscaler allowlisting:

https://help.zscaler.com/zia/adding-urls-allowlist

 

Was this article helpful?

8 out of 8 found this helpful

Have more questions? Submit a request