Skip to main content
Microsoft 365 + Google Workspace

Phishing simulations, delivered straight to the inbox

Direct Delivery places Hook phishing simulations straight into Microsoft 365 and Google Workspace mailboxes instead of sending them across the public mail path, where spam filters and link scanners usually get the first look. Your results show what people do, not what your filters caught. Setup takes three steps, with no mail-flow rules for simulations.

Your mail filter shouldn't take the test

Sent the usual way, a phishing simulation has to get past spam filters and link scanners before it reaches anyone. If a filter quarantines it, nobody practices. If a scanner follows the link first, the click lands in your report as if a person made it. Either way, the report is measuring the filter.

The usual fix is a stack of allowlists and mail-flow rules that someone has to build, test and keep current. See what safe-listing involves.

Microsoft 365: straight into Outlook

Microsoft Direct Delivery places each simulation in the person's mailbox through Microsoft Graph. It uses its own app, separate from directory sync, and a Microsoft 365 admin approves it once per tenant. The simulation arrives in Outlook like any other message, without passing through the filters that would normally inspect it.

Google Workspace: unread, in the Primary tab

Google Direct Send lands simulations as unread mail in the Gmail Primary tab for everyone synced from Google Workspace. It's authorized through domain-wide delegation with two scopes: one to insert messages and one to read them. It can't delete mail or change mailbox settings.

Three steps, no mail-flow rules

Set it up once in Hook's email delivery settings:

  1. Connect your directory.
  2. Approve mailbox access.
  3. Let Hook check one synced mailbox to confirm delivery works.

Every send accounted for

Each person gets a delivery record: sent, pending, failed or excluded, with the reason. A duplicate check stops a retry from sending the same simulation twice, so nobody gets two copies after a hiccup. Training and account emails still arrive as regular email, so keep the safelisting you have for those.

Mailbox access is its own approval

Directory sync never includes mailbox access; it's a separate approval you grant on purpose. Disconnect it in Settings and Hook stops delivering through that method and cancels its scheduled simulations.

How it fits with the rest of Hook

Delivery is the first link in the chain. Once a simulation reaches the inbox, Hook counts only human activity in the results, so a scanner that still touches a message can't inflate your click rate. When someone does click, they land on a teaching page built from the exact email they received.

Each step depends on the one before it: a simulation that never arrives teaches nothing, and a click a scanner made teaches nothing either. Direct Delivery makes sure the practice actually happens, in the inbox people use every day, so the numbers you report afterward describe your people. It also works alongside the directory and SSO integrations you already run.

Direct Delivery questions

Not for simulations sent through Direct Delivery. Training and account emails still travel as regular email, so keep those safelisting rules.

A Microsoft 365 admin approves Hook's delivery app once per tenant. It's separate from the app used for directory sync.

Insert simulation messages and read them to confirm delivery. It can't delete mail or change settings.

Every person has a delivery record showing sent, pending, failed or excluded, with the reason.

Hook stops delivering through that method and cancels that method's scheduled simulations.

Test your people, not your filters.

See Direct Delivery set up on a live account in thirty minutes.