Deliverability is the hard part nobody advertises
A simulation sitting in quarantine produces a flattering number and teaches nobody. What actually has to be configured, and why.
By SafeLoop
If you have ever run a campaign that reported a 2% click rate and felt pleased, it is worth checking whether the mail arrived. Quarantined simulations are the most common cause of implausibly good results in this category.
Why you cannot send simulations from a normal provider
The acceptable-use policies of the major transactional email services explicitly prohibit simulated phishing. Any platform built on one is a single abuse report away from suspension, which is why simulation traffic needs separate infrastructure from system notifications.
- 1SafeLoop MTADedicated, per-tenant domain
- 2Your gatewayBypass policy applied
- 3Mail platformAdvanced Delivery entry
- 4InboxVerified by seed test
The four places a simulation dies
- Reputation — a shared sending IP with poor history never reaches the gateway.
- The gateway — Mimecast, Proofpoint and peers will detonate URLs and strip the lure unless a bypass policy exists.
- The mail platform — Microsoft 365 needs an Advanced Delivery entry; Google needs a scoped bypass rule.
- The client — link rewriting and safe-attachment handling can neutralise a lure that otherwise arrived.
Configuration you paste, not advice you interpret
The difference between a support article and a working configuration is specificity. Your admin should receive the exact domains, IPs and URL patterns to enter for your stack, and then a test that proves the entry took effect.
What not to do
Do not disable link protection globally to make simulations work. Scope every bypass to the simulation sending domains, keep it documented, and review it when you change vendors. A permanently weakened gateway is a worse outcome than an unmeasured workforce.
And do not change your own SPF, DKIM or DMARC records to accommodate a simulation vendor. Simulations should send from vendor-owned domains you allow-list, leaving your authentication posture untouched.
Keep reading
Related articles
The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
Read article →Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
Read article →Beyond email: why smishing, vishing and quishing belong in every programme
Attackers moved channels years ago. An email-only programme measures your office workers and calls it an organisation.
Read article →