Authorize recipient domains for phishing simulations
Approve the email domains your synced users receive mail on so Hook can deliver phishing simulations to them.
Before Hook can send a simulation to someone, the email domain they receive mail on has to be authorized with the service that delivers the mail. Hook spots those domains automatically from your synced directory and lists them in the Authorized domains pane on your Microsoft Entra connection. You'll come here whenever a new domain turns up unapproved, because approving it is what unblocks the people waiting behind it.
You need to be an org admin with an active Entra connection and at least one group synced. Your organization also needs its sending integration set up, since authorization is keyed to that account. Your Hook contact sets those up; without them the Authorize button returns a configuration error and nothing can be approved.
Where the pane lives
Open Settings, then Integrations, and click your Microsoft Entra row to expand its workspace. Authorized domains is the right-hand column, beside your synced groups and the members of the group you have selected. Its subtitle notes that these are the recipient domains detected from your synced users. The Authorized domains metric in the header counts only fully approved domains, so it's a quick read on how much of your directory can actually be sent to.

Read the domain statuses
Each row shows a domain, how many synced users are on it, and one of four statuses:
- Authorized: approved, those users can receive simulations, nothing to do.
- Pending review: Hook knows about it but nobody has approved it yet.
- Unauthorized: the domain was explicitly rejected, or an attempt failed.
- Awaiting sync: no result has come back yet, which is the normal resting state for a domain Hook has only just detected.
The two middle states carry an Authorize domain button. The footer tallies all four, and a search box filters by domain name.
Anyone whose domain isn't Authorized can't be sent a simulation and simply waits. Unapproved rows tell you how many people that is, which is usually the fastest way to explain why a campaign reached fewer people than you expected.
Authorize a domain
Click Authorize domain
Find the row and click its Authorize domain button. Unless you've already accepted the current terms for that domain, a certification dialog opens. Domains you certified earlier, during the first-sync preview for example, go through without the dialog unless the terms have changed.
Certify the domain
The dialog names the domains you're approving and asks you to confirm your organization owns them or is authorized to use them for simulated phishing. Hook records who accepted, when, the address they accepted from, and which version of the terms they agreed to.
Only authorize domains you actually control
Approving a domain is a formal statement that your organization owns it or is permitted to use it for simulated phishing, and it's recorded against your name. Don't approve a domain you don't have authority over.
Wait for the result
On success the row turns Authorized and Hook starts making the waiting users eligible, telling you how many are being processed. If the domain is rejected, for an unsupported top-level domain or one on a sending blocklist, the row lands on Unauthorized and those users stay blocked.

Domains you'll never see in the pane
Consumer and disposable mail providers (Gmail, Outlook.com, Yahoo, Proton,
Mailinator, and the like) and Microsoft tenant defaults (anything ending in
.onmicrosoft.com, including guest addresses) are permanently blocklisted.
They're filtered out before the pane renders, so they never appear as rows and
there's nothing to click. Worth knowing if your user count and your domain list
don't reconcile: anyone whose only address is one of these can't be tested
until they have a real company domain.
The retry cap
Every failed attempt on a domain is counted. After 3 failures the Authorize domain button is disabled and the row tells you how many users are blocked behind it. Contact Hook support at that point, because the answer won't change on the fourth try.
Common pitfalls
- A sync in progress blocks authorization. Only one operation runs per connection at a time, so Hook asks you to try again once the sync finishes.
- A network hiccup isn't a rejection. If the call fails rather than being refused, the status doesn't move and the button stays enabled. Try again.
- You don't have to wait for this pane. Hook surfaces new domains during the first-sync preview too, using the same dialog.