Understanding the Risky allow-list policies detected for intuit.com risk
If you don’t have Barracuda Email Gateway Defense (EGD) working properly in your environment, the following risks are not tested or displayed in BarracudaONE:
Risky allow-list policies detected for intuit.com
Risky allow-list policies detected for docusign.net
BarracudaONE displays this risk when it detects, through Barracuda Email Gateway Defense, that intuit.com is included in one or more allow-list policies. This configuration bypasses email filtering controls and exposes your organization to impersonation attempts, domain spoofing, malware delivery, and unwanted email.
Why this is a risk
Adding intuit.com to an allow-list policy means that emails appearing to come from that domain bypass normal email security filtering. Attackers commonly spoof legitimate-looking domains like intuit.com to impersonate trusted brands such as QuickBooks, TurboTax, and other Intuit services. When intuit.com is allow-listed, these malicious emails are not filtered and can reach users' inboxes, increasing the risk of:
Phishing attacks—Emails designed to steal credentials or sensitive information by impersonating Intuit services.
Business Email Compromise (BEC)—Spoofed invoices or payment requests that appear to come from Intuit.
Malware delivery—Malicious attachments or links disguised as legitimate Intuit communications.
Domain spoofing—Attackers can send emails that appear to originate from intuit.com without proper authentication.
Allow-listing broadly used domains like intuit.com significantly weakens your email protection and creates an exploitable gap in your security posture.
Identifying this risk
To help you identify the policies affected, BarracudaONE displays:
the number of policies containing the unsafe domain
the names of policies with the risk
the types of policies with the risk (Account-level, Domain-level, or User-level)
Resolving this risk
To resolve this risk, review and remove intuit.com from allow-list policies in Barracuda Email Gateway Defense.
For more information, see Risky Policies Detection and Remediation.
To resolve the Risky allow-list policies detected for intuit.com risk
In the left navigation menu, select Home
.
In the Start mitigating risks section, do one of the following:
Select the Risky allow-list policies detected for intuit.com risk.
Select another risk, then use the arrows to navigate to the Risky allow-list policies detected for intuit.com risk.
Review the list of policies containing intuit.com in the Risky policies section.
Select Manage
to open the Email Protection Risky policies page.
Review each policy and follow the steps in Risky Policies Detection and Remediation to do one of the following:
remove intuit.com from the policy
delete the policy if it is no longer needed
When all policies containing intuit.com are removed or updated, the risk auto-resolves within 6 hours.
If intuit.com is added back to any policy, the risk returns.
Once you have resolved this risk
Removing intuit.com from allow-list policies restores full email filtering for this domain and gives your environment:
Stronger phishing protection—Emails spoofing Intuit services are now properly filtered and inspected.
Reduced risk of domain spoofing—Attackers can no longer bypass filtering by impersonating intuit.com.
Better malware detection—All emails from intuit.com are scanned for malicious attachments and links.
Improved filtering effectiveness—Email protection can analyze message content, sender reputation, and authentication for intuit.com emails.
Consistent security enforcement—No gaps in filtering that attackers could exploit.
Better customer experience—Harmful or unwanted emails are filtered, reducing complaints.