# Known automated-scanner sources, shipped with Warmbly and applied by the
# tracking service. Set TRACKING_SCANNER_BUILTINS=false to ignore this file,
# TRACKING_SCANNER_NETWORKS / TRACKING_SCANNER_CLICK_NETWORKS to add your own.
#
# Format, one entry per line:   <source> <scope> <label>
#   source  a CIDR (v4 or v6), or asn:<number>
#   scope   all    the source never carries a person's own request
#           clicks the source also carries a mail client's own image fetches,
#                  so only its click tickets may be treated as automated
#   label   what is recorded on the event
#
# An ASN entry does nothing unless TRACKING_SCANNER_ASN_HEADER names a header
# your edge sets with the source ASN (Cloudflare: ip.src.asnum).
#
# A match never changes the response. The pixel is still served and the click
# is still redirected; only the analytics event is labelled as automated.

# Microsoft 365 Defender / Exchange Online Protection. This is the mail
# filtering layer: Safe Links rewriting and delivery-time URL detonation run
# here, and no mailbox is ever read from it, so both its pixel fetches and its
# click tickets are machines. Published by Microsoft as endpoint sets 9 and 10
# of the Microsoft 365 worldwide endpoint list (*.protection.outlook.com).
# The Exchange Online ranges are deliberately NOT here: Outlook on the web is
# served from those, and it fetches external images through Microsoft's own
# proxy, so a genuine open by an Outlook.com recipient comes from them.
40.92.0.0/15        all     microsoft-365-protection
40.107.0.0/16       all     microsoft-365-protection
52.100.0.0/14       all     microsoft-365-protection
52.238.78.88/32     all     microsoft-365-protection
104.47.0.0/17       all     microsoft-365-protection
2a01:111:f400::/48  all     microsoft-365-protection
2a01:111:f403::/48  all     microsoft-365-protection

# The rest of Microsoft's and Google's networks, by ASN. Defender detonation is
# not confined to the ranges above, so these catch a scan that runs from Azure
# instead. They are NOT enabled by default and are here to be uncommented, or
# set through TRACKING_SCANNER_CLICK_NETWORKS, as a deliberate trade-off:
#
#   - clicks only, never opens. Both companies proxy external images for their
#     web mail, so counting their pixel fetches as machines would zero the open
#     rate of every Outlook.com, Microsoft 365 and Gmail recipient.
#   - even on clicks these are whole cloud allocations, not scanner ranges.
#     A recipient whose browser egresses through Azure (Windows 365, Azure
#     Virtual Desktop, a NAT gateway) or Google Cloud is inside them, and their
#     real click would be recorded as automated and fire nothing. Turn these on
#     when your recipients' scanner noise costs you more than that.
#
# asn:8075          clicks  microsoft
# asn:8074          clicks  microsoft
# asn:12076         clicks  microsoft
# asn:15169         clicks  google

# Barracuda Email Gateway Defense. Published by Barracuda as the ranges its
# filtering layer connects to a customer's mail server from, one narrow block
# per region. Enabled for the same reason the EOP ranges are: these are the
# mail filtering tier itself, not the cloud it happens to sit in, and no
# recipient reads their mail from them.
3.24.133.128/25     all     barracuda-egd
15.222.16.128/25    all     barracuda-egd
35.157.190.224/27   all     barracuda-egd
18.185.115.192/26   all     barracuda-egd
18.184.203.224/27   all     barracuda-egd
13.200.136.128/25   all     barracuda-egd
35.176.92.96/27     all     barracuda-egd
18.133.136.128/26   all     barracuda-egd
18.133.136.96/27    all     barracuda-egd
209.222.82.0/24     all     barracuda-egd

# Proofpoint, Mimecast and Cisco Secure Email, by ASN. Each of these is a pure
# mail security network with no consumer eyeball traffic, which is what makes
# them worth naming at all, and they are still NOT enabled by default. The
# reason is browser isolation, and it is worth understanding before turning
# one on:
#
#   Proofpoint Isolation and Mimecast Browser Isolation render a clicked page
#   in the vendor's own cloud and stream it to the recipient. When a policy
#   sends a link to isolation, the GET on the click ticket comes from the
#   vendor's network and a PERSON is on the other end of it. Isolation is
#   usually scoped to uncategorised or suspicious URLs, which is precisely what
#   a new cold-outreach domain looks like, so for this product it is not a
#   rare edge case.
#
# So a whole-ASN entry here cannot distinguish the delivery-time scan from the
# isolated human click, and enabling one trades inflated click counts for lost
# automations. Turn them on when your recipients' scanner noise costs you more
# than that, and prefer leaving the machine-window rule to catch the
# delivery-time half: a scan runs seconds after the send, an isolated click
# runs whenever the person got to it.
#
# asn:22843         all     proofpoint
# asn:26211         all     proofpoint
# asn:52129         all     proofpoint
# asn:30031         all     mimecast
# asn:39588         all     mimecast
# asn:42427         all     mimecast
# asn:60492         all     mimecast
# asn:16417         all     cisco-ironport
