Sender and delivery
Which domain the exercises come from, how they reach the mailbox, and what you need to allow at your mailbox provider so they do not end up in junk.
An exercise only measures your staff if it reaches the inbox. If it lands in junk, the results measure the spam filter instead. This chapter covers the three things that have to be right: the sender domain, the delivery path and the exception at your mailbox provider.
The sender domain
The domain provided by Conbool is recommended. An exercise should look like an attack from outside. Sent from your own company domain, it teaches staff to distrust their own domain. Conbool maintains SPF and DKIM for the provided domain; there is nothing for you to enter.
Your own domain is possible. The domain's card under Settings, Protection and sender then shows which SPF record and which DKIM key must be in place. Copy both values rather than typing them.
Every night the check runs to confirm SPF and DKIM are still correct. If a domain fails, the programme stops scheduling anyone through it, and the change log records a line with the reason. If it is a domain provided by Conbool, the card says so explicitly: Conbool has been notified and there is nothing for you to do.
The delivery path
How an exercise reaches the mailbox depends on how your domain is set up. In neither case do you need to change anything.
- With mail routing through Conbool, the exercise goes directly to your mail server behind the gateway, bypassing the Conbool filter that would otherwise recognise it as phishing.
- Without mail routing, the exercise goes to the mail server listed in your domain's MX record, usually Microsoft 365. The only requirement is that the domain is verified, by TXT record or through Microsoft 365.
The exception at your mailbox provider
A good exercise looks like real phishing to the spam filter, because that is what it imitates. Without an exception, Microsoft Defender correctly recognises it as an attack. The values for the exception are under Settings, Protection and sender, section Delivery.
Microsoft 365. In the Defender portal under Policies and rules, Threat policies, Advanced delivery, open the Phishing simulation tab and enter the sender domains and the sending IP addresses.
Google Workspace. In the Admin console under Apps, Google Workspace, Gmail, add the sending IP addresses to the email allowlist.
The exception applies only to exercises from these domains and addresses. Real attacks from other sources are still filtered.
Afterwards, confirm in Conbool that the exception is in place. No programme starts without this confirmation. If domains or sending addresses change, the confirmation counts as outdated and has to be renewed, as it does after six months.
Checking that it works
The confirmation is a self-declaration. Only a real exercise proves the exception: create a campaign with a test mailbox as the only audience and check whether the message lands in the inbox or in junk.
If it lands in junk, the most common reasons are:
- a value was entered differently, such as a missing IP address,
- the sender is on the mailbox's personal junk list,
- a custom transport rule applies before the exception.