Skip to content

Simulation Delivery Engine: Direct Message Injection (DMI) vs SMTP Relay

1. Executive Summary & Value Proposition

The foundation of any successful phishing simulation program is guaranteed deliverability. If simulated training emails are blocked by spam filters, quarantined by Secure Email Gateways (SEGs), or routed to junk folders, employees cannot be trained and security metrics become meaningless. SimuPhish provides dual delivery mechanisms through its Simulation Delivery Engine (Main Navigation > Settings > Simulation Engine and Settings > Platform > SMTP Configuration). Organizations can choose between Direct Message Injection (DMI) via Microsoft Graph API—which deposits simulated emails directly into user inboxes without traversing external mail gateways—or Managed / Custom SMTP Relay with end-to-end deliverability verification.


2. The Threat Landscape & The Real-World Problem Solved

  • The Whitelisting Headache: Configuring IP whitelisting, header bypasses, and transport rules across Microsoft Defender, Proofpoint, or Mimecast requires hours of complex IT effort and often breaks during gateway software updates.
  • Email Gateway Quarantine: Up to 30% of simulated phishing emails sent via standard SMTP are inadvertently quarantined or marked as spam by email security gateways.
  • Altered Email Headers: Modern security gateways rewrite URLs and modify email headers (e.g., prepending [EXTERNAL] tags), alerting employees that an email is external and distorting simulation realism.

3. How It Works (The User Journey)

graph TD
    A[Simulation Campaign Scheduled] --> B{Delivery Engine Selection Settings > Simulation Engine}
    B -->|Direct Message Injection DMI| C[Connect to Microsoft Graph API / M365]
    C --> D[Directly Inject Email into Employee Inbox]
    D --> E[100% Guaranteed Inbox Placement: Zero Gateway Interception]
    B -->|SMTP Relay Engine| F{SMTP Choice: Managed vs Custom}
    F -->|Managed SMTP| G[SimuPhish Dedicated High-Reputation Sender IPs]
    F -->|Custom SMTP| H[Customer Corporate SMTP Server: Host, Port, Auth, TLS]
    G & H --> I[Standard Mail Routing with Deliverability Test Verification]

The Administrator Experience

  1. Navigating to the Simulation Engine: Open Main Navigation > Settings and click the Simulation Engine tab.
  2. Selecting Delivery Technology:
  3. Direct Message Injection (DMI - Recommended for Microsoft 365):
    • Connects directly to your Microsoft 365 tenant via authorized Microsoft Graph API integration.
    • Injects simulated emails directly into employee inboxes via internal API calls.
    • Bypasses External Gateways: Completely bypasses Microsoft Defender Safe Links, Proofpoint, Mimecast, and SpamTitan.
    • Eliminates Whitelisting: Requires zero complex mail flow rules, IP allow-listing, or transport rules.
    • 100% Deliverability: Guaranteed delivery directly into the primary inbox with original, unaltered email headers.
  4. SMTP Relay Engine:
    • Ideal for organizations utilizing Google Workspace, on-premise Exchange, or non-Microsoft mail servers.
  5. Custom SMTP Configuration (Settings > Platform > SMTP Configuration):
  6. Managed SMTP: Use SimuPhish’s out-of-the-box managed email relay with high-reputation dedicated IP addresses.
  7. Custom SMTP Setup:
    • SMTP Host & Port: Configure mail server hostname (e.g., smtp.office365.com, mail.company.com) and port (25, 465, 587).
    • Authentication: Enter SMTP Username and secure Password.
    • Encryption: Select TLS, SSL, or STARTTLS.
    • From Address & From Name: Define default sender identity (e.g., security@company.com).
    • Test Email Address: Enter a test email address and click Send Test Email to verify configuration and firewall connectivity instantly.
  8. Active Status & Monitoring: View configuration status (Active/Inactive), manage multiple SMTP profiles, and switch between delivery engines as operational needs evolve.

4. Key Business Benefits & Measurable ROI

  • Eliminate IT Whitelisting Overhead: DMI saves dozens of hours of network engineering setup by bypassing mail gateway configuration entirely.
  • 100% Inbox Placement: Guarantee that simulated drills reach employee inboxes every time, avoiding junk folder drop-offs.
  • Preserve Perfect Simulation Realism: Deliver simulated attacks with original headers, spoofed sender domains, and realistic formatting without gateway tampering.
  • Flexible Multi-Engine Architecture: Choose DMI for Microsoft 365 environments while maintaining robust SMTP capabilities for hybrid or Google Workspace environments.

5. Real-World Attack Scenario & Case Study

Scenario: The Broken Mail Gateway Whitelist

  • The Situation: A global consulting firm updated its enterprise email security gateway over a weekend. On Monday morning, a scheduled phishing simulation failed because the gateway quarantined all 6,000 test emails.
  • SimuPhish Action: The security team switched the delivery engine from SMTP to Direct Message Injection (DMI) via Microsoft Graph API integration.
  • Outcome: With DMI activated, the simulation was re-launched. Emails were injected directly into mailboxes without traversing the gateway, achieving 100% deliverability with zero IT intervention or firewall rule edits.