What you need to know
Does advanced delivery remember a particular sending IP as belonging to only one configured simulation domain?
Potentially affected
Non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline.
DSE recommendation
Assess the complete domain and IP sets together; do not substitute relay addresses for an unidentified original sender.
Source facts
Advanced delivery requires a matching simulation domain and sending IP, but does not retain a pairing between individual values. The domain is the vendor’s MAIL FROM or DKIM domain. A domain list and IP list therefore are not a set of vendor-specific pairs. Microsoft Learn.
Microsoft warns that Enhanced Filtering cannot recover the true origin for the documented internet-to-Microsoft-365-to-external-service-and-back route. Adding that intermediary’s addresses as a workaround can bypass spam filtering for internet senders impersonating a configured domain. Direct injection also falls outside advanced delivery because it bypasses transport. Microsoft Learn.
Applicability
Review non-Microsoft phishing simulations using Microsoft 365 advanced delivery through the transport pipeline. Keep the simulation’s delivery method and observed sender identity in scope; a vendor’s presence in one list is not the complete match decision.
DSE recommendation
DSE recommends evaluating every allowed domain against the complete permitted IP set before adding another simulation provider. Ask the provider for the authentication identity and delivery path, then compare those with representative message headers. If the documented unsupported round trip applies, stop the proposed address workaround and redesign the approved test route. Do not widen the list merely to make a failed simulation arrive.
Verification
Use authorized, harmless simulation messages to compare the expected domain and original sending address with the observed match. Include an intentionally nonmatching case under controlled conditions. Record whether the message traversed transport and which identity was evaluated; successful delivery alone is not the acceptance criterion.
Official references
Review the official source
Configure the advanced delivery policy for non-Microsoft phishing simulations and email delivery to SecOps mailboxes - Microsoft Defender for Office 365 | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE