Abnormal Security Integration for Sendmarc
The integration for Sendmarc into Abnormal Security surfaces vendor risk data so users can identify and monitor third-party email threats directly within the Sendmarc platform.
Prerequisites
- You must at the very least be an account-administrator to configure the integration
- You need an active Abnormal Security account with VendorBase access.
Step 1 - Add Sendmarc IP Addresses to Abnormal IP safelist
Before connecting to the Abnormal API, your Abnormal account must allow inbound API requests from the Sendmarc application servers. Please refer to Abnormal documentation here on how to set this up on your access token.
You will need to add the following IPs to the Abnormal IP safelist
- 20.101.184.175
- 20.101.186.244
- 20.126.184.33
Permissions
We require at a minimum the read access to the following abnormal API routes:
GET/v1/vendors
GET/v1/vendors/:id/details
GET/v1/vendor-cases/:id
GET/v1/vendors/:id/activity
GET/v1/vendor-cases
Step 2 - Configure the integration in Sendmarc
The integration can be set up under the account - integrations tab

- Select the correct region for you Abnormal account. This is the region your Abnormal account is hosted on.
- Paste the Abnormal access token into the API key field
-
Click Save. Sendmarc will immediately validate the key against the Abnormal API.
- If validation fails, an error is shown beneath the API key field. Double-check the key and that IP whitelisting is complete.
- If validation succeeds, the integration is saved. The Vendors menu item should become available in the sidebar upon refresh.