
You can now build a custom phishing scenario that sends from your organization domain instead of a lookalike spoofing domain. The result is a simulation that reproduces the exact condition that makes business email compromise effective in the real world: a request that arrives from a sender address employees have no technical reason to doubt.
What is business email compromise?
Business email compromise (BEC) is a social engineering technique in which an attacker impersonates or takes over a trusted business identity, usually an executive, a finance colleague, or a supplier, to trigger a payment, a data disclosure, or a process exception. It carries no malware, no attachment, and often no link. The payload is the employee's decision. Because the message passes authentication and matches an expected business workflow, technical email controls have limited visibility, which makes verification behavior the actual control surface.
How it works
When crafting a custom phishing scenario, select
Organization domain instead of Spoofing domain as the sender. Arsen delivers the simulation through your Microsoft or Google integration using API-only delivery, so the email originates from a domain you own and use, with no gateway relay and no external sending infrastructure.
Every standard Arsen phishing builder feature remains available from there: sender identity, subject, body, landing page, attachment, and reporting. The scenario behaves as a one-way phishing hook.
Organization domain and spoofing domain compared
| Spoofing domain | Organization domain | |
|---|---|---|
| Sender address | Lookalike domain registered by Arsen | A verified domain your organization owns |
| Delivery | Standard email delivery | Microsoft or Google API-only delivery |
| Threat modeled | External impersonation and lookalike detection | Business email compromise and internal identity trust |
| What it tests | Whether employees inspect the sender domain and other clues | Whether employees verify the request itself |
| Conversational scenarios | Supported | Not supported |
| Setup required | None | Microsoft or Google email-delivery integration |
- A spoofing domain campaign measures whether people catch a technical tell.
- An organization domain campaign removes that tell entirely and measures whether people apply an out-of-band verification step when the request is financially or operationally sensitive. That’s what predicts real BEC exposure.
Requirements
- An enabled Microsoft or Google email-delivery integration.
- A verified domain your organization owns and uses.
- Custom phishing scenario. Conversational simulations are not supported for BEC.

Which BEC scenarios can you simulate?
Because the sender is a domain your organization owns, every scenario below impersonates an internal identity rather than an external party.
| Scenario | Impersonated sender | Typical target | What the request asks for |
|---|---|---|---|
| Executive impersonation | CEO, CFO, or managing director | Finance staff, executive assistants | An urgent transfer, an off-process approval, or a confidential task |
| Invoice and payment change | Finance or accounts payable colleague | Accounts payable, controllers | Approval of a new invoice or updated beneficiary details |
| Payroll diversion | HR or payroll administrator | Payroll and HR staff | A direct-deposit or bank-detail change |
| IT and helpdesk pretext | Internal IT or service desk | All employees | Credential re-entry, MFA re-enrollment, or device validation |
| Legal and M&A confidentiality | General counsel or an executive sponsor | Finance, legal, deal teams | Access to a confidential document, with a discretion instruction |
| HR announcement | People operations | All employees | Confirmation of personal data or acknowledgment of a policy document |
Run these against the populations that actually hold the authority: finance, payroll, procurement, executive support, and anyone who can change a payment record. Company-wide BEC campaigns dilute the signal you are trying to read.
-
A BEC simulation is a controlled phishing exercise that reproduces a business email compromise attempt, in which a trusted internal identity requests a payment, a data disclosure, or a process exception. Unlike a standard phishing simulation, it does not rely on a suspicious sender domain, so it measures whether employees verify the request rather than whether they spot a technical tell.
-
No. That is the point of the feature. A BEC simulation sends from a verified domain your organization already owns and uses, delivered through your Microsoft or Google integration. Spoofing domains remain available for scenarios where external impersonation is the threat you want to test.
-
No. BEC scenarios support one-way phishing hooks only. Conversational phishing scenarios are not available when the sender is set to an organization domain.
-
An active Microsoft or Google email-delivery integration and a verified organization domain. Once both are in place, the Organization domain option appears in the sender step of the custom phishing scenario builder.