> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/allow-block-email-logins.md).

# Allow/Block Email Logins

Detects accounts using email domains that are on your block list, not on your allow list, or that appear across fewer than 5 (configurable) accounts in the last 30 days. You can toggle between using a block list or an allow list, and enable auto-discovery of rare domains to flag uncommon email providers without manual list maintenance. An ignore list is available to suppress alerts for known-good domains.<br>

**Recommended Actions**

Depending on your security posture, consider deleting users using emails with those domains and exploring why you have them in the system.<br>

**Default Check Settings**

Auto-Discovery of Rare Domains: enabled

Rare Domain Occurrence Threshold (Past 30 Days): 5

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[GitHub](/integrations/github.md)

[AWS](/integrations/aws.md)

[Duo](/integrations/duo-security-integration.md)

[Slack](/integrations/slack-notification-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

[Salesforce](/integrations/salesforce-integration.md)

[Auth0](/integrations/auth0.md)
