Deliverability & domains
Land in the inbox, not the spam folder
A simulation creates value only when it reaches its audience. PhishSpot provisions and monitors sending domains end to end — DNS, authentication, TLS, and mail-filter allowlists.
Add a domain, and we handle the plumbing
Bring your own domain or lease one from us. PhishSpot provisions the full mail stack through Cloudflare and Postal — no DNS ticket, no waiting on IT.
- SPF, DKIM, MX and return-path generated and published automatically.
- TLS certificates issued and renewed for landing pages and tracking.
- Delegation and verification run in the background and report status as they complete.
- One place to see every domain, its role, and whether it is ready to send.

Everything that keeps you out of the spam folder
Domains, authentication, monitoring, and mail-filter allowlists managed as one system.
Three kinds of domain
Platform domains host your landing pages, Secured domains are ones you verify and control, and Custom (BYOD) sending domains are fully managed on your behalf.
BYOD sending domains
Bring a domain you already own. We provision it for sending and keep it warm, so campaigns come from an address your people trust.
Authentication, automatic
SPF, DKIM, MX and return-path records are created and published through Cloudflare and Postal — correctly, every time.
Hourly health checks
Every domain is re-checked each hour: delegation, DNS records, mail flow, SSL, and expiry via RDAP. Problems surface before a campaign does.
Mail-filter allowlists
Export ready-made allowlist rules in ten formats — Microsoft 365, Google Workspace, Mimecast, Proofpoint, Postfix, SpamAssassin, plus TXT, JSON, CSV, and Markdown.
Automatically updated allowlist
A webhook updates the allowlist as sending IPs and domains change. Configure it once and PhishSpot keeps it current.
Delegate once, we handle the records
Point your domain’s nameservers at us a single time. From then on, every record a simulation needs is created, verified and kept healthy automatically.
- Copy two nameservers into your registrar — that’s the whole manual step.
- We watch delegation propagate and confirm the domain the moment it is live.
- DNS, mail and TLS records are managed for you and re-verified every hour.
- Expiry and RDAP checks warn you well before a domain lapses.

Deliverability, explained
How do you keep simulations out of the spam folder?
Two ways. First, we provision each sending domain with correct SPF, DKIM, MX, and return-path records plus valid TLS. Second, we generate ready-to-apply allowlist rules for Microsoft 365, Google Workspace, Mimecast, Proofpoint, and other mail-security systems. A webhook keeps those rules current.
Do I have to touch DNS myself?
Only once. You delegate the domain by copying two nameservers into your registrar. After that PhishSpot creates and maintains every record for you and re-checks them hourly.
What’s the difference between Platform, Secured and Custom domains?
Platform domains are ours and host landing pages out of the box. Secured domains are ones you own and verify so we can use them safely. Custom (BYOD) sending domains are your own domains, provisioned end to end for sending and fully managed.
How will I know if a domain breaks?
Every domain is health-checked every hour across delegation, DNS, mail flow, SSL and expiry (via RDAP). If something drifts, it’s flagged in the dashboard before it can affect a live campaign.
Managed deliverability, from setup to monitoring
Connect a domain and let PhishSpot handle DNS, authentication, TLS, and allowlists so simulations reach their intended audience reliably.

