To allow Phishing Simulation to send your organization emails, configure Microsoft
365 Defender and Microsoft Exchange allow list settings.
-
Configure your Microsoft 365 Defender phishing simulation settings to allow
Phishing Simulation to send your organization emails.
-
On the Trend Micro Vision One console, locate and copy the Phishing
Simulation sending domains, sending IPs, and simulation URLs by going to .
-
In the Microsoft 365 Defender portal,
go to in the Rules section.
-
On the Advanced delivery page, click the
Phishing simulation tab and then click
Add.
-
In the Edit third-party phishing simulation panel
that opens, configure the following settings.
Your organization should now be able to receive emails from Phishing
Simulation. To verify email delivery, run a test phishing campaign.
Important:
Step 1 outlines Microsoft's new method for configuring phishing
simulation allow lists, replacing Microsoft's historical methods. If
your organization is still unable to receive Phishing Simulation emails
after you complete Step 1, complete the historical methods outlined in
Steps 2-4 and then run another test phishing campaign.
-
(Optional) Configure your IP allow list.
-
On the Trend Micro Vision One console, locate and copy the Phishing
Simulation sending IP address by going to .
-
In the Microsoft 365 Defender portal,
go to .
-
Click .
-
Under Always allow messages from the following IP addresses
or address range add the Phishing Simulation sending IP
address, and then click Save.
-
(Optional) Bypass spam filtering in Microsoft Exchange Online Protection
(EOP).
-
On the Trend Micro Vision One console, locate and copy the Phishing
Simulation sending IP address by going to .
-
In the Microsoft Exchange admin center, go to .
-
Click .
-
Specify a name for the rule.
-
Click More options.
-
Under the condition Apply this rule if... select
The sender.
-
Click More options and select IP
address is in any of these ranges or exactly
matches.
-
Specify the Phishing Simulation sending IP address and click
OK.
-
Under Do the following... select .
-
Specify the message header
X-MS-Exchange-Organization-BypassClutter and
specify the header value true.
Important:
Both the message header
("X-MS-Exchange-Organization-BypassClutter") and value ("true")
are case-sensitive.
-
Click add action to add an additional action
under Do the following...
-
Select and click Save.
-
(Optional) Bypass junk mail filtering for Office 365 mail servers.
-
On the Trend Micro Vision One console, locate and copy the Phishing
Simulation header key and header value by going to .
-
In the Microsoft Exchange admin center, go to .
-
Click and specify a name for the rule.
-
Click More options.
-
Under the condition Apply this rule if... select .
-
Under Enter text specify the Phishing Simulation
header key and then click Enter words.
-
Specify the Phishing Simulation header value and then click
+.
-
Under Do the following select .
-
Specify the message header
X-Forefront-Antispam-Report and specify the
header value SFV:SKI;
-
Click add action to add an additional action
under Do the following...
-
Select and click Save.