Do I need to setup SPF, DKIM or DMARC to accept Phishing Simulations in Exchange Online?
If you use Advanced Delivery Policy as described in Microsoft’s documentation, you do not need to manage SPF or DMARC for phishing simulations—the policy ensures they are delivered regardless.
Do I need to configure SPF, DKIM, and DMARC for Nimblr phishing simulations in Microsoft Defender?
When allowlisting Nimblr phishing simulations using Advanced Delivery Policy in Microsoft Defender for Office 365, you do not need to consider SPF, DKIM and DMARC.Why?
Advanced Delivery Policy is designed to ensure Nimblr phishing simulations reach your users’ inboxes without being blocked by Microsoft’s security filters. When you configure this policy:
- Emails matching the specified sender address (or domain) are treated as simulated attacks.
- They bypass security features such as Safe Links, Safe Attachments, and Microsoft’s anti-phishing filters.
- SPF, DKIM, and DMARC checks are not affected, as the Advanced Delivery Policy explicitly exempts them from filtering.
What does this mean in practice?
- You do not need to configure SPF, DKIM or DMARC records to ensure delivery.
- Simulations will be delivered correctly even if they would otherwise fail SPF or DMARC policies.
- However, maintaining correct SPF, DKIM, and DMARC configuration is still recommended for all other email sending scenarios. For step-by-step instructions on configuring Advanced Delivery Policy, see Microsoft's official documentation.