---
title: Restricting Delivered Messages with Recipient Whitelisting
description: "Applies to HMS Version: 2.1+ It is often useful to separate different types of outbound messages between multiple accounts on a Hurricane MTA Server. Some accounts may only deliver to specific address"
---

[Skip to content](https://help.socketlabs.com/docs/restricting-delivered-messages-with-recipient-whitelisting#main-content)

English

Show submenu for translations

[Contact us](https://help.socketlabs.com/docs/kb-tickets/new?hsLang=en)

[![SocketLabs logo](https://help.socketlabs.com/hs-fs/hubfs/Logos/SocketLabs%20logo.png?width=243&height=70&name=SocketLabs%20logo.png)](https://www.socketlabs.com/)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact us](https://help.socketlabs.com/docs/kb-tickets/new)

 SocketLabs is here to help!

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.socketlabs.com/docs?hsLang=en)
2. [Hurricane MTA](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en)
3. [Basic Hurricane Usage](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#basic-hurricane-usage)

# Restricting Delivered Messages with Recipient Whitelisting

 

Applies to HMS Version: 2.1+

It is often useful to separate different types of outbound messages between multiple accounts on a Hurricane MTA Server. Some accounts may only deliver to specific addresses or domains, depending on their purpose. For example, an account may be configured to specifically handle messages for internal consumption within a company. Accounts such as these can take advantage of the Recipient Whitelisting feature to prevent the processing of messages to unintended recipients, either inadvertently or through malicious intent. This feature can be particularly useful for preventing compromised machines that are generating spam messages from using an MTA account to deliver messages to random addresses, greatly restricting the amount of damage done before such activity is detected and stopped.

#### CONSIDERATIONS

The following should be considered before using this feature:

- Messages rejected by Recipient Whitelisting are rejected during the initial SMTP protocol exchange, so the messages are not even received by the HMS before being rejected.
- If a message specifies multiple recipients via RCPT TO commands, the message is accepted and processed for any recipient that was not rejected by whitelisting.
- RCPT TO addresses are not authenticated, and thus can be easily spoofed. Do not rely on Recipient Whitelisting as the sole method of restricting what messages are delivered by any MTA account!

#### CONFIGURATION

This feature is enabled and configured by adding a single line to the \[RESTRICTIONS\] section of the GENERAL.CONFIG file found in an individual account's config directory. Please remember to reload the target account's configuration after making these changes in order for these changes to take effect.

**FIELD**: AllowedRcptToList

**DESCRIPTION**: A comma-delimited list of email addresses. If set to anything other than an empty string, this account will only accept email with a RCPT TO address that is on this list. The comparison is a case insensitive string match.  At this time wildcards are not supported.

**EXAMPLE**: The following example shows how to create a Recipient Whitelist.

```
AllowedRcptToList=user2@example.com,ceo@example.org
```

Using the above configuration, only messages that identify themselves as being delivered to any address at @example.com or ceo@example.org via the RCPT TO component of the SMTP protocol are accepted by the MTA.

### RELATED ARTICLES

For more information about writing regular expressions, we recommend third-party resources such as the following:

- [http://www.regular-expressions.info/quickstart.html](http://www.regular-expressions.info/quickstart.html) - An introduction to regular expressions
- [http://www.regular-expressions.info/reference.html](http://www.regular-expressions.info/reference.html) - A quick reference to core regular expression syntax
- [http://regexpal.com/](http://regexpal.com/) - An online regular expression tester, which highlights test data that matches a regular expression

The following Knowledge Base article may also be of interest:

[Restricting Received Messages with Mail From Whitelisting](https://help.socketlabs.com/docs/restricting-received-messages-with-mail-from-whitelisting?hsLang=en)

 

- [Fundamentals](https://help.socketlabs.com/docs/fundamentals?hsLang=en#main-content)

    - [StreamScore](https://help.socketlabs.com/docs/fundamentals?hsLang=en#streamscore)
    - [Reports](https://help.socketlabs.com/docs/fundamentals?hsLang=en#reports)
    - [Frequently Asked Questions](https://help.socketlabs.com/docs/fundamentals?hsLang=en#frequently-asked-questions)
- [Advanced](https://help.socketlabs.com/docs/advanced?hsLang=en#main-content)

    - [Security](https://help.socketlabs.com/docs/advanced?hsLang=en#security)
- [DNS Authentication](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#main-content)

    - [DKIM](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#dkim)
    - [SPF and Custom Bounce Domain](https://help.socketlabs.com/docs/dns-authentication?hsLang=en#spf-and-custom-bounce-domain)
- [Deliverability](https://help.socketlabs.com/docs/deliverability?hsLang=en)
- [For Developers](https://help.socketlabs.com/docs/for-developers?hsLang=en#main-content)

    - [Event Webhooks](https://help.socketlabs.com/docs/for-developers?hsLang=en#event-webhooks)
- [Integrations](https://help.socketlabs.com/docs/integrations?hsLang=en#main-content)

    - [Languages and Frameworks](https://help.socketlabs.com/docs/integrations?hsLang=en#languages-and-frameworks)
    - [Mail Servers](https://help.socketlabs.com/docs/integrations?hsLang=en#mail-servers)
    - [Web Clients and Plug-ins](https://help.socketlabs.com/docs/integrations?hsLang=en#web-clients-and-plug-ins)
    - [Mail Clients](https://help.socketlabs.com/docs/integrations?hsLang=en#mail-clients)
- [Marketing Tools](https://help.socketlabs.com/docs/marketing-tools?hsLang=en#main-content)

    - [Tips and Tricks](https://help.socketlabs.com/docs/marketing-tools?hsLang=en#tips-and-tricks)
- [Troubleshooting](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#main-content)

    - [SocketLabs Inbound SMTP Gateway Errors](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#socketlabs-inbound-smtp-gateway-errors)
    - [SocketLabs Outbound SMTP Errors](https://help.socketlabs.com/docs/troubleshooting?hsLang=en#socketlabs-outbound-smtp-errors)
- [Spotlight Email Analytics](https://help.socketlabs.com/docs/spotlight-email-analytics?hsLang=en)
- [Hurricane MTA](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#main-content)

    - [Advanced Hurricane Usage](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#advanced-hurricane-usage)
    - [Upgrading Hurricane](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#upgrading-hurricane)
    - [Troubleshooting](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#troubleshooting)
    - [Hurricane Maintenance](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#hurricane-maintenance)
    - [Getting Started with Hurricane](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#getting-started-with-hurricane)
    - [Basic Hurricane Usage](https://help.socketlabs.com/docs/hurricane-mta?hsLang=en#basic-hurricane-usage)
- [Complex Sender](https://help.socketlabs.com/docs/complex-sender?hsLang=en)

[![Chill listening crop-3](https://help.socketlabs.com/hs-fs/hubfs/Logos/Logo_Favicon%20-%20large%20-%20cropped.png?width=24&height=24&name=Logo_Favicon%20-%20large%20-%20cropped.png "Chill listening crop-3")](https://www.socketlabs.com)

<https://www.facebook.com/socketlabs/> <https://twitter.com/socketlabs> <https://www.linkedin.com/company/socketlabs-inc./>

Copyright © 2026, SocketLabs LLC