Genesys Cloud – Enable secure replies outside the domain allow list
| Announced on (YYYY-MM-DD) | Effective date (YYYY-MM-DD) | Aha! idea |
|---|---|---|
| 2026-08-17 | - | - |
In a future release, Genesys Cloud will extend the domain allow list feature to give administrators more flexibility when managing email conversations. Administrators will be able to allow agents to reply to recipients from existing inbound conversations, even when those recipients’ domains are not included in the domain allow list. This change helps organizations respond to customers who use common consumer or third-party email domains without requiring administrators to continually expand and maintain large allow lists, while preserving the security controls of the original feature.
What’s changing
Administrators will be able to configure additional domain allow list options for each email address:
- Allow agents to reply to or forward emails to recipients from the most recent email in an existing conversation, even if those recipients’ domains are not included in the domain allow list.
- Allow agents to start new outbound email conversations to any email address from ACD queues, regardless of whether the recipient’s domain is included in the domain allow list.
- Use wildcard domains, such as
*.example.com, to allow all matching subdomains without adding each one individually. The wildcard does not match the root domain, which must be added separately if needed. - Validate email addresses and domain allow list entries by using a new validation service that supports wildcard domains and provides consistent validation for administrators and agents.
Both new domain allow list options are disabled by default and can be enabled independently for each domain allow list. Reply and forward exceptions apply only to recipients that participated in the existing conversation and do not allow agents to add arbitrary recipients outside the allow list.
Why this matters
Many organizations receive email from consumer and third-party domains such as Gmail or Outlook.com. Without this enhancement, agents can be prevented from replying unless administrators explicitly add every domain to the domain allow list. This feature reduces ongoing administration while maintaining control over outbound email policies by limiting exceptions to verified participants in existing conversations. It also helps organizations use the domain allow list in more business scenarios without relying on workarounds.
[NEXT] Was this article helpful?
Get user feedback about articles.