How to set up mail injection for Gmail
Direct Inject for Gmail allows CultureAI to directly create phishing simulations in your employees inboxes, rather than sending the emails via regular mail flow conventions.
This feature allows us to bypass Gmails' spam filtering, which can often cause many of our phishing simulations to be blocked or moved to spam.
NOTE - The CultureAI Gmail phishing report button must be used in conjunction with this to ensure accurate click reporting. Deploy Gmail reporting button
Permissions and requirements
Permissions are installed at the domain level (domain-wide). Per-user permission's are not required. To be installed, the application will need to be marked as trusted.
We require the following permissions to allow Direct Inject to function;
- https://www.googleapis.com/auth/admin.directory.user.readonly - This allows CultureAI to view your employee list and use that to generate the emails into the correct inboxes. This is a Read Only permission.
- https://www.googleapis.com/auth/gmail.insert This allows CultureAI to directly insert emails into employees inboxes.
Setup Steps
The CultureAI Google Gmail Integration service account must be granted permission to open chats with your users, to do this, follow the steps below;
- Login to your CultureAI admin account
- Click the settings cog at the top of your dashboard
- Scroll and locate the "Gmail" integration tile
- Click "Enable" 
- Follow the steps in the on screen set-up wizard, or follow the steps below;
- Visit Domain Wide Delegation under Security >> API Controls within your Google Console
- Click "Add New" 
- Enter the Client ID from step 2 of the set-up wizard
- Enter the OAuth Scopes from step 3 of the set-up wizard 
- Click "Authorise" 
- Click "Continue" in the CultureAI set-up wizard
Next the CultureAI Google Gmail application must be marked as trusted so that it can be installed to your Google Gmail Workplace.
- Visit App access control under Security >> API Controls within your Google Console
- Click "Add App" then "OAuth App Name"  
- Enter the Client ID from step 2 of the set-up wizard
- Select the Client ID from the found app  
- Continue with the default scope  
- Mark the app as trusted and click continue  
- Click "Finish" to save  
- Click "Continue" in the CultureAI set-up wizard
You now need to give the application it's final approval
If you are the owner or admin of your Google Gmail Workplace, we recommend you click "Open now" to install the CultureAI Google Gmail application immediately.
If you need someone else to install the application, or you're planning on installing it at a later date, use "Copy link" to get a shareable link which will install the application CultureAI when used by an admin.

Once approved, refresh your page and you should see the integration enabled

Now you need to switch on Direct Inject in CultureAI to finish your set-up
- Click the settings cog at the top of your dashboard
- Click the "Attack Simulations" tab along your side bar
- Click into "Email Phishing"
- Click the "More" tab
- Scroll and locate the "Direct Send and Injection" option 
- Switch on the "Gmail Direct Inject" toggle
- A new window will pop up, click "Yes, enable" 
- You're done! Your simulated phishing emails will now start sending via Direct Inject