# Review phishing-simulation domains and sending addresses as matching sets

> Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:14+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?

## Potentially affected

Non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline.

## DSE recommendation

Assess the complete domain and IP sets together; do not substitute relay addresses for an unidentified original sender.

## Article

## Source facts

Advanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure).

Microsoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure).

## Applicability

Review non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.

## DSE recommendation

DSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.

## Verification

Use authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.

## Official references

[Microsoft Learn: Configure advanced delivery](https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure).

## Primary reference

- Name: Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/advanced-delivery-policy-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review phishing-simulation domains and sending addresses as matching sets,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-462-review-phishing-simulation-domains-and-sending-addresses-as-matching-sets/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
