GuideInformationCybersecurityIT

Review phishing-simulation domains and sending addresses as matching sets

Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?

Potentially affected

Non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline.

DSE recommendation

Assess the complete domain and IP sets together; do not substitute relay addresses for an unidentified original sender.

Source facts

Advanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. Microsoft Learn.

Microsoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. Microsoft Learn.

Applicability

Review non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.

DSE recommendation

DSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.

Verification

Use authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.

Official references

Microsoft Learn: Configure advanced delivery.

Primary reference

Review the official source

Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes - Microsoft Defender for Office 365 | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE