# Known automated-scanner sources, shipped with Warmbly and applied by the
# tracking service. Set TRACKING_SCANNER_BUILTINS=false to ignore this file,
# TRACKING_SCANNER_NETWORKS / TRACKING_SCANNER_CLICK_NETWORKS to add your own.
#
# Format, one entry per line:   <source> <scope> <certainty> <label>
#   source     a CIDR (v4 or v6), or asn:<number>
#   scope      all    the source never carries a person's own request
#              clicks the source also carries a mail client's own image
#                     fetches, so only its click tickets may be judged
#   certainty  certain  (the default) a match is the whole verdict: the source
#                       only ever filters mail
#              probable a match corroborates the timing rule instead of
#                       replacing it, because the source can also carry a
#                       person. The consumer then treats the event as
#                       automated only inside its wider machine window
#                       (tracking.machine_window_probable_seconds), so a
#                       delivery-time scan is caught and a click hours later
#                       is still a person's
#   label      what is recorded on the event
#
# An ASN entry needs the source ASN, from either TRACKING_SCANNER_ASN_DB (a
# MaxMind GeoLite2-ASN database, which needs no ASN header and no transform
# rule) or TRACKING_SCANNER_ASN_HEADER (a header your edge writes; Cloudflare:
# ip.src.asnum). With neither, every asn: entry below is inert.
#
# Neither removes the need for TRACKING_TRUSTED_PROXIES behind a reverse proxy.
# The header is read only from a peer listed there; the database reads the
# client address, which without that variable is the proxy's, so it would
# resolve the proxy's network instead of the requester's.
#
# A match never changes the response. The pixel is still served and the click
# is still redirected; only the analytics event is labelled as automated.

# Microsoft 365 Defender / Exchange Online Protection. This is the mail
# filtering layer: Safe Links rewriting and delivery-time URL detonation run
# here, and no mailbox is ever read from it, so both its pixel fetches and its
# click tickets are machines. Published by Microsoft as endpoint sets 9 and 10
# of the Microsoft 365 worldwide endpoint list (*.protection.outlook.com).
# The Exchange Online ranges are deliberately NOT here: Outlook on the web is
# served from those, and it fetches external images through Microsoft's own
# proxy, so a genuine open by an Outlook.com recipient comes from them.
40.92.0.0/15        all     microsoft-365-protection
40.107.0.0/16       all     microsoft-365-protection
52.100.0.0/14       all     microsoft-365-protection
52.238.78.88/32     all     microsoft-365-protection
104.47.0.0/17       all     microsoft-365-protection
2a01:111:f400::/48  all     microsoft-365-protection
2a01:111:f403::/48  all     microsoft-365-protection

# The rest of Microsoft's and Google's networks, by ASN. Defender detonation is
# not confined to the ranges above, so these catch a scan that runs from Azure
# instead. Clicks only, never opens: both companies proxy external images for
# their web mail, so counting their pixel fetches as machines would zero the
# open rate of every Outlook.com, Microsoft 365 and Gmail recipient.
#
# These stay OFF by default even as `probable`, because they are whole cloud
# allocations rather than mail-security networks. A recipient whose browser
# egresses through Azure (Windows 365, Azure Virtual Desktop, a NAT gateway) or
# Google Cloud sits inside them all day, so a match here says almost nothing
# about who is asking, and inside the probable window their real click would
# still be recorded as automated. Uncomment them, or set them through
# TRACKING_SCANNER_CLICK_NETWORKS, when your recipients' scanner noise costs
# you more than the clicks it will take with it.
#
# asn:8075          clicks  probable  microsoft
# asn:8074          clicks  probable  microsoft
# asn:12076         clicks  probable  microsoft
# asn:15169         clicks  probable  google

# Barracuda Email Gateway Defense. Published by Barracuda as the ranges its
# filtering layer connects to a customer's mail server from, one narrow block
# per region. Enabled for the same reason the EOP ranges are: these are the
# mail filtering tier itself, not the cloud it happens to sit in, and no
# recipient reads their mail from them.
3.24.133.128/25     all     barracuda-egd
15.222.16.128/25    all     barracuda-egd
35.157.190.224/27   all     barracuda-egd
18.185.115.192/26   all     barracuda-egd
18.184.203.224/27   all     barracuda-egd
13.200.136.128/25   all     barracuda-egd
35.176.92.96/27     all     barracuda-egd
18.133.136.128/26   all     barracuda-egd
18.133.136.96/27    all     barracuda-egd
209.222.82.0/24     all     barracuda-egd

# Proofpoint, Mimecast and Cisco Secure Email, by ASN. Each of these is a pure
# mail security network with no consumer eyeball traffic, which is what makes
# them worth naming at all. They ship enabled and marked `probable`, and the
# reason for the mark is browser isolation:
#
#   Proofpoint Isolation and Mimecast Browser Isolation render a clicked page
#   in the vendor's own cloud and stream it to the recipient. When a policy
#   sends a link to isolation, the GET on the click ticket comes from the
#   vendor's network and a PERSON is on the other end of it. Isolation is
#   usually scoped to uncategorised or suspicious URLs, which is precisely what
#   a new cold-outreach domain looks like, so for this product it is not a
#   rare edge case.
#
# A whole-ASN entry therefore cannot settle it alone; marked `certain` it would
# trade inflated click counts for lost automations. `probable` is what makes
# them safe to ship on: the network match widens the machine window rather than
# deciding, so a request from one of these networks is CLASSIFIED as the
# delivery-time scan only while it is inside that window, and the isolated
# click an hour later is still the person's.
#
# This is a trade, not a free win. It moves events in one direction only, from
# counted-as-human to counted-as-automated, so it can never let a scan count as
# engagement. What it costs is the recipient behind one of these vendors who
# genuinely clicks inside the probable window: that click is now recorded as
# automated and fires nothing. Shorten tracking.machine_window_probable_seconds
# if your recipients are that fast, or drop the entry.
#
# A second cost, independent of the window: a click from ANY recognised network
# is redirected without the identification ticket, because the edge does not
# know when the send was dispatched and cannot tell the two apart there. So an
# isolated click the consumer later counts as a person's still leaves no
# website-visit attribution for that contact.
asn:22843           all     probable  proofpoint
asn:26211           all     probable  proofpoint
asn:52129           all     probable  proofpoint
asn:30031           all     probable  mimecast
asn:39588           all     probable  mimecast
asn:42427           all     probable  mimecast
asn:60492           all     probable  mimecast
asn:16417           all     probable  cisco-ironport
