Hook SecurityHook Docs

Authorize recipient domains for phishing simulations

Approve the email domains your synced users receive mail on so Hook can deliver phishing simulations to them.

Before Hook sends a simulation to anyone, the email domain they receive mail on has to be approved. Hook reads those domains out of your synced directory and lists them for review, so approving one is what unblocks the people waiting behind it.

You need to be an org admin with a connected directory, either Microsoft Entra or Google Workspace, and at least one group in scope. Hook never approves a domain for you. Every approval is a click you make.

Where the review appears

The same domain review card shows up in three places, and it behaves the same way in all of them:

  • The connect preview. When you first pick groups and preview their members, the domains those members use are listed under Recipient domains. Approve them there and those people are ready as soon as the first sync finishes.
  • The scope-change confirm step. When you change your selection through Manage groups, the confirm screen lists the domains your new selection brings in.
  • The connection's Domains tab. Go to Settings, then Integrations, expand your directory row, and open Domains. This is where you come back when a new domain turns up later. A search box filters the list by name.

When people are held behind a domain nobody has decided on yet, the connection header also carries a banner naming how many, with a button that takes you straight to the Domains tab.

How the list is grouped

Rows arrive in two sections. Both headings describe where a domain came from, not whether you have approved it, so an approved domain keeps sitting under the heading it arrived in.

Verified in your tenant holds the domains your provider confirms belong to your organization: the domains you added and proved ownership of in Microsoft Entra or Google Workspace. They are usually safe to approve together, so when more than one is waiting the section offers a control that marks all of them for approval in one click. You still apply that decision yourself.

Outside your tenant covers everything else. Outside collaborators sitting in a synced group, contractors on their own company domain, and domains you do own but never verified with your provider all land here. Hook cannot confirm these, so read them one at a time. If your provider's verified list is unavailable, every domain arrives in a single Domains found list instead and gets the same row-by-row treatment. That heading describes where the list came from, not the standing of any domain in it, so approved domains sit under it too.

Each row carries the evidence you need: the domain, how many synced users are on it, which synced group they came from, and a sample of member addresses. A short line under each heading says what that grouping means.

Approve the domains you send to

Choose an answer per row

Click Approve on a row and it switches to a chosen state with an undo link next to it, so you can see the whole batch before you commit it. Decline sits beside Approve as the quieter second choice, for a domain you do not want simulations going to.

A domain you leave alone stays pending, and the people on it stay held. That is a reasonable answer when you are not sure who a domain belongs to. It waits for you on the Domains tab.

Read the summary line

Next to the Apply button, one line states what you have chosen: how many domains you are approving and how many users start syncing because of it, how many you are declining, and how many you skipped.

Apply

Click Apply. That commits the batch. Up to that point every choice is still undoable on the row it belongs to.

Certify, the first time

If any domain you approved has never been certified under the current terms, one dialog opens before the batch commits. It names those domains, repeats your summary, and carries the certification sentence you are agreeing to. Its confirm button certifies and applies in the same click, and cancelling it leaves your choices sitting on the card, unapplied.

Hook records who accepted, when, the address they accepted from, and which version of the terms they agreed to. Domains your organization certified earlier go through with no dialog, which is why you see it the first time and not the second.

Only approve domains you actually control

Approving a domain states that your organization owns it or is permitted to use it for simulated phishing, and it is recorded against your name. Do not approve a domain you have no authority over.

When nothing is left to decide

Once every domain has an answer, the card collapses to a summary: how many domains are approved and how many are declined, with the list of them below it, read-only. There is no Apply button on it, because there is nothing left to apply. Hide tucks the list away, and View brings it back.

If an approved domain still has people held behind it, that line says how many are waiting for a sync and offers Sync now. Approving records the decision; a sync is what actually makes those users sendable. Applying a decision on the Domains tab starts that sync for you, and in the connect preview and the scope-change step your Save starts it. Sync now is there for the case where the run did not happen, so an approval that never promoted anyone cannot go quiet on you.

Each domain in that list shows its current status, and declined domains keep a Reinstate button beside them.

Decline and reinstate

Declining a domain does not deactivate anybody. Those people keep syncing from your directory and stay in your user list, they simply never receive a simulation.

To reverse a decline, expand the collapsed card, click Reinstate on the row, and click Apply. The Apply bar comes back for the reinstatement, because it is a change like any other. Reinstating returns the domain to waiting for a decision rather than straight to approved, so approve it in the next round if that is what you want.

Domains you will never see

Consumer and ISP mailboxes (Gmail, Outlook.com, Yahoo, iCloud, Comcast, and the like), disposable address services, and Microsoft tenant defaults (anything ending in .onmicrosoft.com, including guest addresses) are permanently blocked. Hook filters them out before the card renders, so they never appear as rows and there is nothing to click. If your user count and your domain list do not reconcile, this is usually why: somebody whose only address is one of these cannot be tested until they have a company domain.

When a domain cannot be approved

Occasionally a domain comes back Not approved instead of approved. That means the service that delivers the mail rejected it, and the row tells you the reason it gave. Unsupported top-level domains and domains on a sending blocklist are the usual causes. The people on that domain stay held. If the reason is not something you can fix, contact Hook support rather than retrying.

Common pitfalls

  • A sync in progress holds your decisions. Only one operation runs per connection at a time, so the rows stay visible but Apply waits until the running sync finishes.
  • A search can hide a pending domain. On the Domains tab the summary line counts every domain, not only the ones matching your search. If it reports a skipped domain you cannot see on screen, clear the search box.
  • Approved is not the same as synced. If the collapsed card says people are waiting for a sync, the decision landed and only the sync is outstanding. Use Sync now.
  • You do not have to wait for the Domains tab. Hook lists new domains during the connect preview and the scope-change confirm step too, using the same card.

On this page