Dedicated Sending and Tracking Domains for Phishing Tests

You can write the most convincing simulated phishing email in the world, but if the mail filter quarantines it before anyone sees it, your campaign measures the filter - not your people. Deliverability is the invisible half of realistic phishing simulation, and it is where most in-house testing efforts quietly fail. empowsec solves it with dedicated per-company sending domains, fully automated email authentication, and a clear allow-listing guide, all managed from a single settings page.
One Click to a Dedicated, Authenticated Sending Domain
Under Settings and Phishing Configuration, a company admin provisions the entire sending setup with one button. empowsec generates a unique subdomain for the company - a slug of the company name plus four random characters under the platform's sending zone - so every organization sends its simulations from its own isolated domain. A campaign for Acme Corp never shares a sending identity with any other customer, which keeps reputation, results and troubleshooting cleanly separated.
Behind that one click, the platform creates the mail domain and a dedicated security@ mailbox on empowsec's managed mail infrastructure, retrieves the domain's DKIM signing key, and configures all required DNS records through the platform's DNS service. There is nothing for the customer to install and no DNS changes to make in their own zone for sending - the domain lives entirely inside managed infrastructure. Each company has exactly one phishing mail configuration, and the platform guards against creating a second one.
Provisioning is also engineered to fail safely. If any step in the chain does not complete - for example, the DNS update cannot be applied - the platform rolls the whole operation back and removes the partially created mail domain. You either get a fully working configuration or a clean slate to retry from, never a half-provisioned domain that sends unauthenticated mail.
DNS Done Right: SPF, DKIM and a Strict DMARC Policy
Modern mail providers increasingly reject or junk email that fails authentication, so a simulation platform that skips SPF and DKIM is testing its own luck. When empowsec provisions a sending domain, its DNS service automatically writes the full record set: the address and MX records for the mail host, an SPF record listing exactly the platform's sending IP ranges, the DKIM public key retrieved from the mail server, and a strict DMARC policy set to reject with strict alignment. Every simulation email is therefore signed, aligned and verifiable - just like legitimate corporate mail.
This matters for more than inbox placement. Well-authenticated simulations behave like the phishing that actually gets through to your users in the real world: modern attackers register their own domains and configure authentication too. Testing with unauthenticated mail would train people against a threat model that mail filters already handle. The settings page keeps this visible with a DNS health card showing the SPF record, DKIM signature and return path as verified.
The Tracking Domain: Where Simulation Links Live
Sending is only half the journey - the links inside a simulation need somewhere to go. The Phishing Configuration page also displays the platform's tracking domain along with its wildcard subdomain, which together host the click and open tracking links used inside simulated emails. Because link scanning and URL rewriting in corporate mail filters can block or prefetch these URLs, both the tracking domain and its wildcard belong on your filter's allow list alongside your dedicated sending domain. The page lists all of them with one-click copy buttons.
Allow-Listing: Bypassing Your Filter on Purpose
Allow-listing a phishing simulation platform feels counterintuitive at first: is that not weakening the mail filter? In practice it is the opposite of sloppy - it is scoping. Your secure email gateway will catch most bulk phishing regardless; the simulation program exists to measure and train the human layer that sits behind the filter. If simulations are randomly swallowed by the gateway, your click rates become noise, departments receive unequal test coverage, and your reporting dashboards understate risk. Deliberately allow-listing the platform's known, published ranges keeps the experiment controlled while your filter keeps doing its normal job against real attackers.
empowsec publishes exactly four IP ranges to allow-list, shown on the configuration page with copy-to-clipboard actions and a copy-all shortcut:
Because most customers run Microsoft 365 or Google Workspace, the page does not stop at a raw list. Dedicated tabs walk admins step by step through applying the domains and IP ranges in each ecosystem, so the allow-listing work that usually consumes a support ticket becomes a ten-minute copy-and-paste exercise.
What This Means for Your Team
- Deliverability is measurable realism - if simulations do not arrive, your phishing simulation program measures the mail filter instead of employee behavior.
- One click provisions everything - a unique per-company sending domain, a security@ mailbox and the DKIM key, created on managed infrastructure with no customer DNS edits for sending.
- Authentication is automatic and strict - SPF, DKIM and a reject-policy DMARC record are written by the platform's DNS service the moment the domain is provisioned.
- Failures roll back cleanly - a provisioning error removes the partial setup, so there is never a half-configured domain, and each company has exactly one configuration.
- Allow-list four ranges deliberately - 206.168.56.0/22, 207.167.112.0/22, 216.238.56.0/22 and 45.91.95.92/32, plus the tracking domain and its wildcard, with guided steps for Microsoft 365 and Google Workspace.


