Troubleshooting Guide: Enable Images in Emails
In Microsoft Outlook, automatic image downloads are often disabled by default for security reasons. This can affect how simulated phishing emails display and may also impact tracking accuracy.
To ensure emails display correctly, you may need to adjust Outlook settings and trust specific simulation domains.
Enable Automatic Image Downloading
- Open Trust Center Settings
In Outlook Desktop:
- Go to File > Options
- Select Trust Centre
- Click Trust Centre Settings
- Allow Image Downloads
- Go to Automatic Download
- Untick: “Don’t download pictures automatically in HTML e-mail messages or RSS items”
If available, ensure this is ticked:
✔ Permit downloads from websites in this security zone: Trusted Zone
Note: Menu options may vary slightly depending on your Outlook version (Microsoft 365 vs older desktop versions). Some options may also be managed by your IT administrator.
Add Simulation Domains to Trusted Sites (Windows)
- Open Internet Options
- Open Internet Options in Windows.
- Go to the Security tab.
- Select Trusted Sites, then click Sites.
- Add Trusted Domains
Add the following domains:
- mail.goldphish.com
- mail.emailsupport.me
- app.goldphish.com
- Click Add, then Close
Note: This ensures both simulation emails and training landing pages load correctly without filtering, rewriting, or security inspection by email and web security tools.
Verify Advanced Security Settings
- Check Encrypted Page Settings
In the same Internet Options window:
- Go to the Advanced tab.
- Scroll down to the Security section.
- Ensure the following is unchecked: ❌ Do not save encrypted pages to disk
- Click Apply, then OK
Note: This is a legacy setting and may not be available or applicable in all environments.
Organisation-Wide Configuration (Recommended)
If your organisation manages Outlook centrally, these settings may be controlled via policy. In that case, changes will need to be made by your IT team using:
- Group Policy (GPO)
- Microsoft Intune policies for Outlook
- Safe Senders / Trusted Domains configuration
Microsoft Resource: Deploy Safe Senders settings using Group Policy in Outlook
Notes:
- Changes may require a restart of Outlook to take effect
- Some settings may be restricted by your IT administrator
- In modern Microsoft 365 environments, certain options may not be visible or may be controlled centrally
- These steps are intended for testing and simulation environments only