Skip to main content
Cimento places email simulations directly in each employee’s inbox through the Gmail API or Microsoft Graph. They never cross your mail gateway, so there’s nothing to allowlist, and they look exactly like a real attack would. Connect the platform your employees’ mailboxes are on. Your organization can have one email provider active at a time.

Google Workspace

A Super Admin authorizes Cimento’s service account with domain-wide delegation.

Microsoft 365

A Global Administrator grants consent, then an Exchange admin limits Cimento to your simulation targets.
Both setups are one-time, and Cimento never receives or stores your administrators’ credentials. For every permission they grant and exactly what Cimento does with it, see Mailbox permissions.

Let employees report phishing

To give Outlook users a one-click way to report suspicious email to your security team, deploy the Phish Alert Button for Outlook.