Skip to content
  • There are no suggestions because the search field is empty.

How to identify if a suspicious email is a Nimblr simulation?

How can you verify whether a suspicious email is a Nimblr simulation?

To verify whether a suspicious email is a Nimblr simulation, log in to the Nimblr portal and follow these steps:

  1. Go to Reports > Users.
  2. Find the user who received the suspicious email and click on their name.
  3. Click the View button next to any sent simulation to review its full details.

How can you verify a Nimblr simulation using email headers or technical signals?

If the complete email (including headers) is available, look for the header X-NIMBLR-PHISHING: yes. Note that email headers can be inserted by anyone, so the presence of this header alone does not guarantee the email is a Nimblr simulation.

For stronger confirmation, check that the email is signed with the Nimblr DKIM signature (sasender.net) and originates from one of the following IP addresses:

  • 78.47.225.98
  • 116.203.167.208
  • 95.216.176.28

Note: These IP addresses and the DKIM signing domain reflect current Nimblr infrastructure and may change over time. Verify the latest details in the Nimblr portal or by contacting Nimblr support.

How does the Microsoft built-in Report button work with Nimblr simulations?

If you use Microsoft 365, you may also implement the Microsoft built-in Report button for Outlook. This allows users to report suspicious emails and administrators to review them in the Microsoft 365 Admin Portal. Reported Nimblr simulations are automatically marked as simulations in the Microsoft 365 Admin Portal.