To ensure Arsen phishing simulations land directly in employees’ inboxes, you must authorize their delivery using a rule based on a specific header in Google Workspace.
1 – Objectives
Ensure simulation emails are delivered directly to the inbox
Identify Arsen emails using a dedicated header
Use a method suited to organizations with an upstream security filter
Verify that simulations are correctly received after configuration
2 – Prerequisites
Have administrator access to Google Workspace / Google Apps
Have already allowed Arsen IPs in your upstream filter (if applicable)
3 – Access Gmail compliance settings
To begin:
Go to https://admin.google.com to open the Admin console
Click
Apps
Select
Google Workspace
Click
Gmail
Scroll down to the Compliance section
4 – Add a Gmail compliance rule
4.1 – Create a new rule
Go to Content compliance
Click
ConfigureorAdd another rule
Enter a clear name, for example:
Arsen – Phishing simulation allow ruleSelect email types: Inbound and Internal – Receiving
4.2 – Add the Arsen header condition
Under Add expressions…, select
If ANY of the following match the messageClick
Add
Choose
Advanced content matchIn Location, select
Full headersIn Match type, choose
Contains textIn Content, enter your unique Arsen header (specific to your account)
📚 Note
To find your header in Arsen:
Go to Settings in Arsen
Click the Campaigns Settings tab
Click the Phishing Simulation Whitelisting link and copy the header value
Click Save
4.3 – Define the behavior when the header matches
In If the above expressions match, do the following:
Keep Modify message
Check
Bypass spam filter for this message
Click
Save
5 – Test phishing simulation delivery
Changes can take up to one hour to propagate.
To validate the configuration:
Launch a test campaign to a small set of controlled addresses
Confirm that Arsen simulations are delivered to the inbox (not spam)
Run this test at least one hour after configuration to ensure the rule is active









