Deliverability
The reason most programmes quietly fail
A simulation that lands in quarantine produces a flattering number and teaches nobody anything. Deliverability is treated here as a first-class capability rather than a support article: dedicated infrastructure, generated allow-list configuration, and a placement test before every send.
- 100%
- campaigns placement-tested
- 4
- gateway vendors supported
- 0
- changes to your SPF or DKIM
Infrastructure
Simulations do not send from a transactional provider
The acceptable-use policies of shared transactional email services prohibit simulated phishing, so anything built on one is a suspension waiting to happen. SafeLoop runs dedicated mail infrastructure with per-tenant sending domains and reputation managed separately from system notifications.
- Dedicated MTA, isolated from transactional mail
- Per-tenant sending domains and IP reputation
- Your own look-alike domain supported if you prefer
- 1SafeLoop MTADedicated, per-tenant domain
- 2Your gatewayBypass policy applied
- 3Mail platformAdvanced Delivery entry
- 4InboxVerified by seed test
Configuration
Rules you paste, not advice you interpret
The wizard produces the exact configuration for your stack — Microsoft 365 Advanced Delivery entries, Google Workspace bypass rules, and the equivalent policy on your gateway — then verifies it landed by sending to a seed group and reading the result.
- Microsoft 365 Advanced Delivery and Google Workspace
- Mimecast, Proofpoint and two other gateways
- Seed-group placement test before every campaign
Platform detail
What gets configured where
| Platform | Mechanism | Who has to do it |
|---|---|---|
| Microsoft 365 | Advanced Delivery phishing-simulation entry (domains, IPs, URLs) | Your Defender admin, once |
| Google Workspace | Inbound gateway and spam-bypass rule scoped to our sending domains | Your Workspace admin, once |
| Mimecast | Permitted-sender and URL-protection bypass policy | Your gateway admin, once |
| Proofpoint | Safe-sender list plus URL-defence exclusion | Your gateway admin, once |
| Everything else | Generated generic rule set plus a placement test to confirm | Us, with your admin on the call |
Your own SPF, DKIM and DMARC records stay untouched — simulations send from SafeLoop-owned domains that you allow-list.
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
Do we have to change our SPF, DKIM or DMARC records?
No. Simulations send from SafeLoop-owned domains that you allow-list, so your authentication records are unaffected. If you would rather send from a look-alike domain you control, that is supported and we walk your mail team through it during onboarding.
What if our gateway still quarantines a campaign?
The pre-send placement test catches that before the campaign goes out, not after. If a message is held, you see which control held it and the generated rule to fix it — the campaign does not launch against a blocked path.
Why can't you just use SES or SendGrid?
Their acceptable-use policies prohibit simulated phishing. Providers built on them are one abuse report from suspension, which is why SafeLoop runs separate infrastructure for simulations and uses transactional providers only for account notifications.
Keep reading
Related
Have your mail admin on the demo
We generate your exact allow-list configuration live and prove placement with a seed send.