Hook SecurityHook Docs

Set up Google Direct Send

Place simulations in synced Google Workspace users’ Gmail inboxes.

Google Direct Send places simulations directly into Gmail inboxes as unread messages in the Primary category. It bypasses spam filtering. Standard delivery is coming soon. Training and account emails still arrive as regular email. Keep your safelisting rules in place.

Before you start

Connect Google Workspace directory sync and complete a sync. You need a Google Workspace super administrator to authorize mailbox access. Directory access alone does not grant Gmail access.

Open Settings → Email delivery → Google Direct Send. If the card is unavailable, contact Hook support.

Authorize mailbox access

  1. Copy the Client ID shown for your organization. Use this value, not the account email address.

  2. In Google Admin console, open Security → Access and data control → API controls → Manage Domain Wide Delegation, then select Add new.

  3. Add the Client ID and both scopes shown in Hook:

    https://www.googleapis.com/auth/gmail.insert,https://www.googleapis.com/auth/gmail.readonly
  4. Save the entry. If your Workspace requires another administrator’s approval, complete that approval too.

  5. Return to Hook and enter the primary email address of a person already synced from this Google directory. Guests, aliases and manually imported learners are not eligible.

  6. Select Check access. Hook requests temporary access as that user and checks their inbox. Verification does not insert a message.

  7. After verification succeeds, Google Direct Send becomes your delivery method if none is selected. If another method is already selected, choose Google Direct Send to switch.

Waiting and the first campaign

Google can take up to 24 hours to apply the delegation entry. “Waiting for delegation” means the check has not succeeded yet. Confirm the Client ID and both scopes, then retry in a few minutes. The separate retry countdown prevents repeated checks within one minute.

After a new grant, follow the wait-before-launch guidance shown in Hook before launching your first campaign. Different Google servers can receive the permission change at different times, so one successful check does not prove every recipient is ready. The initial sandbox guidance is at least 60 minutes; this is provisional and must be validated before general release.

If Google refuses delegation during delivery, Hook stops new deliveries for the affected connection. Messages already delivered remain delivered. Restore the entry if necessary and verify again. Stopped campaigns are not restarted; send a new campaign to learners who did not receive the earlier one.

What access you grant

The insert permission allows Hook to add messages to Gmail. The read-only permission authorizes reading messages across the Workspace when acting as a user. Hook uses it to check the seed inbox and search for its own simulation message IDs before retrying an uncertain delivery. It does not store inbox contents or expose an inbox-browsing feature. These permissions are broader than the searches Hook normally performs.

The Gmail scopes do not authorize deleting messages or changing account settings. Disconnecting in Hook stops its delivery workflow; it does not remove the permission you granted in Google Admin console.

Disconnect or replace the account

Before disconnecting, Hook shows the number of Google campaigns in progress. If Google Direct Send is your selected delivery method, disconnecting it leaves no method selected, and simulations cannot launch until you set up direct delivery again. Disconnecting the Google directory also disconnects Google Direct Send. Replacing Hook’s service account clears the previous verification, and the replacement has a new Client ID. Set up and verify Direct Send again in Settings → Email delivery.

To revoke Google access, remove the old Client ID’s domain-wide delegation entry in Google Admin console. Directory access uses a separate administrator role assignment; remove that role too if you no longer want directory sync.

Re-verifying while campaigns are in progress asks for confirmation. A mailbox-specific problem asks you to choose another synced mailbox; an account problem on Hook’s side requires support.

On this page