Direct Message Injection (DMI) delivers SoSafe phishing simulations directly into user inboxes via secure provider APIs. It reduces whitelisting complexity, improves delivery reliability, and avoids mail gateway interference while maintaining strong security controls.
Am I eligible for DMI?
Microsoft 365 (Entra)
✅ You can use Microsoft DMI if your organization meets these conditions:
-
Your mailboxes are hosted entirely on Microsoft 365 Exchange Online.
-
All users receiving the simulation emails are in a single Microsoft 365 tenant.
-
All email domains are owned and managed by your organization.
🛑 DMI is not supported if:
-
You use an on-premise or hybrid Exchange server.
-
Users are spread across multiple Microsoft 365 tenants.
-
You use non-company domains (e.g.,
@hotmail.com).
Google Workspace
✅ You can use Google DMI if:
-
You are on any SoSafe plan.
-
You are a Google Workspace customer.
-
You have an account with the Super Admin role.
Limitations
-
The DMI connection does not support sending to alias email addresses.
If you meet the criteria above for your platform, you are eligible to use DMI for faster, more reliable simulation delivery.
Quick benefits
-
Higher deliverability: Messages are inserted directly to inboxes via secure APIs.
-
Lower IT overhead: No complex IP/domain whitelisting maintenance.
-
Consistent behavior: Avoids mail gateway rewriting, quarantines, and false positives.
Before you begin
-
Involve your IT/email admins early; elevated permissions are required for initial authorization.
-
Plan a brief test window to send a test email from SoSafe Manager after enabling DMI.
-
If your organization uses additional email security tools, confirm they won’t hide or alter injected messages post-delivery.
DMI checklists and setup links
Microsoft 365 DMI
Start here: Direct Message Injection (DMI) setup guide for Microsoft 365/Entra
Recommended follow-up actions (Microsoft)
-
After connecting DMI: send test mails from SoSafe Manager and confirm ‘Delivered’ in Emails / Email log
-
Whitelisting domains with Safe Links (Microsoft Defender) to avoid URL warnings
-
Reloading images for certain senders (Microsoft 365) to ensure visuals render
-
If DMI cannot be used, follow the traditional whitelisting path in the same article
Google Workspace DMI
Start here: Direct Message Injection (DMI) setup guide for Google Workspace
Recommended follow-up actions (Google)
-
After enabling DMI: send a test email and confirm ‘Delivered’ in Emails → Email log
-
Note: delivery method changes can take up to two days to apply for running campaigns
-
Alias recipient addresses are not supported by the DMI connection
-
If messages land under Promotions or are altered by scanners, adjust security configurations as needed
-
You can disconnect DMI in SoSafe Manager and remove delegated authorization in the Admin console
Security and compliance
For a comprehensive view of API permissions, safeguards, and data handling, read the full Statement on the Security of DMI on our Trust Center.