Email & reporting

Claro + Microsoft 365

Turn every Outlook inbox into a reporting sensor, and deliver realistic phishing simulations without fighting your own mail filters.

Overview

Claro ships an Outlook add-in that puts a Report Phishing button directly in the ribbon, so employees can flag a suspicious email the moment they see it. Reports flow straight into Claro's phish-reporting review workflow, where your security team can confirm whether the email was a Claro simulation or a real threat and respond accordingly. This closes the loop between training and action: employees practice the behavior you want, and every report becomes a data point in your risk analytics.

On the sending side, Claro simulations are delivered directly to Microsoft 365 mailboxes. Because simulated phishing emails are, by design, built to test filtering and human judgment, most tenants allowlist Claro's sending domain in Exchange Online so simulations land in the inbox rather than quarantine. This is a standard, low-effort step your Microsoft 365 admin can complete once and reuse for every future campaign.

The add-in is built on Office JS, so a single deployment covers Outlook on Windows, Mac, and the web without asking employees to install anything themselves. Your Microsoft 365 admin pushes it centrally through the admin center, which means the Report Phishing button simply appears for everyone. For a workforce with mixed technical confidence, that consistency matters: the reporting action looks and behaves the same on every device, so the habit you are trying to build is never blocked by an unfamiliar interface.

Because reporting and sending share one platform, Claro can automatically tell the difference between a reported simulation and a reported real email. Simulation reports feed straight into your behavior and risk scoring, rewarding the employees who spot your tests, while suspected real threats are surfaced to your security team for review. That distinction turns Microsoft 365 from a passive mail system into an active early-warning channel, and it gives you defensible reporting-rate metrics for OJK, ISO 27001, and internal board reviews.

How it works

  • Install the Outlook add-in

    Deploy the Claro add-in to your Microsoft 365 tenant so the Report Phishing button appears in every employee's Outlook ribbon, on desktop and web, from a single centralized push.

  • Allowlist the sending domain

    Your admin adds Claro's sending domain to your Exchange Online allowlist so simulation emails reach the inbox instead of being filtered or quarantined. This is a one-time step reused by every campaign.

  • Launch simulations to real mailboxes

    Run Claro phishing campaigns that deliver straight to Microsoft 365 inboxes, testing filtering and human judgment under realistic conditions your employees actually experience.

  • Reports reach your review queue

    When an employee clicks Report Phishing, the message details are sent to Claro's phish-reporting workflow for your team to review, match against active simulations, and close out.

  • Signals feed analytics and rewards

    Confirmed simulation reports flow into risk scoring and gamification, so reporting employees earn recognition and your team gets a defensible, measurable reporting rate over time.

Frequently asked questions

  • Yes, the add-in is built on Office JS, so it runs in Outlook desktop and Outlook on the web from the same deployment, giving employees a consistent report button everywhere.

Not sure how Claro fits your stack?

Tell us what you run today and we will walk you through the integration path.

Request a demo