Skip to content

Deliverability is the hard part nobody advertises

A simulation sitting in quarantine produces a flattering number and teaches nobody. What actually has to be configured, and why.

By SafeLoop

If you have ever run a campaign that reported a 2% click rate and felt pleased, it is worth checking whether the mail arrived. Quarantined simulations are the most common cause of implausibly good results in this category.

Why you cannot send simulations from a normal provider

The acceptable-use policies of the major transactional email services explicitly prohibit simulated phishing. Any platform built on one is a single abuse report away from suspension, which is why simulation traffic needs separate infrastructure from system notifications.

  1. 1SafeLoop MTADedicated, per-tenant domain
  2. 2Your gatewayBypass policy applied
  3. 3Mail platformAdvanced Delivery entry
  4. 4InboxVerified by seed test
Four hops, each one a place a simulation normally dies. The placement test walks the whole path before a campaign launches.

The four places a simulation dies

  1. Reputation — a shared sending IP with poor history never reaches the gateway.
  2. The gateway — Mimecast, Proofpoint and peers will detonate URLs and strip the lure unless a bypass policy exists.
  3. The mail platform — Microsoft 365 needs an Advanced Delivery entry; Google needs a scoped bypass rule.
  4. The client — link rewriting and safe-attachment handling can neutralise a lure that otherwise arrived.

Configuration you paste, not advice you interpret

The difference between a support article and a working configuration is specificity. Your admin should receive the exact domains, IPs and URL patterns to enter for your stack, and then a test that proves the entry took effect.

What not to do

Do not disable link protection globally to make simulations work. Scope every bypass to the simulation sending domains, keep it documented, and review it when you change vendors. A permanently weakened gateway is a worse outcome than an unmeasured workforce.

And do not change your own SPF, DKIM or DMARC records to accommodate a simulation vendor. Simulations should send from vendor-owned domains you allow-list, leaving your authentication posture untouched.

See these numbers on your own people

A twenty-minute demo runs a live campaign against a test group and produces your own provisional grade.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.