{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
        "slug": "dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/"
        },
        "title": "Review phishing-simulation domains and sending addresses as matching sets",
        "summary": "Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:14+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 249,
        "potentially_affected": "Non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline.",
        "dse_recommendation": "Assess the complete domain and IP sets together; do not substitute relay addresses for an unidentified original sender.",
        "primary_source": {
            "name": "Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Advanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor&#8217;s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Microsoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary&#8217;s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation&#8217;s delivery method and observed sender identity in scope; a vendor&#8217;s presence in one list is not the complete match decision.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.</p>\n<h2>Verification</h2>\n<p>Use authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure advanced delivery</a>.</p>",
        "content_text": "Source facts\nAdvanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. Microsoft Learn.\nMicrosoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. Microsoft Learn.\nApplicability\nReview non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.\nDSE recommendation\nDSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.\nVerification\nUse authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.\nOfficial references\nMicrosoft Learn: Configure advanced delivery.",
        "content_markdown": "## Source facts\n\nAdvanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure).\n\nMicrosoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure).\n\n## Applicability\n\nReview non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.\n\n## DSE recommendation\n\nDSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.\n\n## Verification\n\nUse authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.\n\n## Official references\n\n[Microsoft Learn: Configure advanced delivery](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review phishing-simulation domains and sending addresses as matching sets",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/",
                "headline": "Review phishing-simulation domains and sending addresses as matching sets",
                "description": "Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?",
                "abstract": "Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?",
                "articleBody": "Source facts\nAdvanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. Microsoft Learn.\nMicrosoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. Microsoft Learn.\nApplicability\nReview non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.\nDSE recommendation\nDSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.\nVerification\nUse authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.\nOfficial references\nMicrosoft Learn: Configure advanced delivery.",
                "datePublished": "2026-09-10T00:24:14+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review phishing-simulation domains and sending addresses as matching sets"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 249,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure"
                }
            }
        ]
    }
}