Authorized phishing simulation

Phish your own
people. Safely.
On purpose.

ImmunePhish runs authorized phishing and smishing simulations against your team, then shows you exactly who clicked, who reported, and who needs training - with a complete audit trail behind every send.

B2B only · sales-led onboarding · no public sign-up

Simulation
Inbox - 1 new3 tells found

IT Helpdesk

it-support@microsoft-secure-login.com

[Action Required] Your password expires in 24 hours

We detected unusual sign-in activity on your account. Verify your credentials now to avoid suspension.

Verify my account

↳ resolves to hxxps://microsoft-secure-login.com/auth

ImmunePhish flags the tells. Your people learn to.

Authorizedconsent-gated
Audit trail100% of sends
Isolationper tenant
Access4 RBAC roles

The loop

Simulate, measure, train - then again.

continuous - risk trends down each round

01 / 03

Simulate

Launch authorized phishing and smishing campaigns from realistic templates against your own people.

02 / 03

Measure

See who clicked, who reported, and how fast - by department, with a risk score per person.

03 / 03

Train

Auto-assign awareness courses to the people who need them. Next round, the numbers move.

The platform

One platform, the whole programme.

Campaign authoring, multi-domain tracking, behavioural analytics, and training assignments - built for the way security teams actually work.

Campaign builder

Realistic phishing emails with tracking pixels, click-thru links, and per-recipient personalization.

Custom tracking domains

Tenant-owned domains with on-demand Let's Encrypt TLS. Recipients see your brand, not ours.

Behavioural analytics

Per-department breakdown, time-to-click distribution, repeat-offender lists, per-user risk scores.

one engine · six capabilities

Templates & landing pages

Ready-made templates plus a builder for bespoke phishing pages with credential-capture controls.

Roles & multi-org

Tenant admin, campaign manager, analyst, viewer. Invite teammates; every action is audited.

Authorized by design

Recipient-domain consent gates, do-not-phish lists, and per-tenant isolation keep you compliant.

Measurement

The number that has to fall.

Every send feeds the metrics your dashboard trends round over round - so you can prove the programme is working, not just that it's running.

  • Phish-Prone Percentage

    The share of targeted people who clicked or submitted - the industry-standard exposure metric, benchmarked and trended round over round.

  • Time-to-click

    How fast people fall, from under a minute to a day out, so you learn which pretexts land hardest.

  • Per-user & per-department risk

    A weighted risk score for every person and team, with repeat offenders surfaced automatically.

Phish-Prone %sample view
18.4%6.2 pts · improving

Time to click

<1 min
8%
1–5 min
34%
5–30 min
26%
30 min–2 h
20%
>2 h
12%

Department risk

FinanceHigh
SupportMedium
EngineeringLow

Course · Spotting credential harvesting

Module 01

  • Lookalike domains video
  • Urgency & pretext article

Module 02

  • Reporting the right way video
  • Knowledge check · pass 80% quiz
Auto-assigned to everyone who clicked this round

Training

Close the loop - automatically.

The people who fall for a simulation are exactly the ones who need training. ImmunePhish assigns it for them and tracks it through to done.

Course builder
Modules, lessons, and blocks - video, article, PDF, and quiz - assembled in an ordered outline.
Server-graded quizzes
Multi-select answers, CSV import, one attempt, and a per-question review revealed only after submitting.
Auto-assignment
Trigger a course the moment someone clicks or submits - the people who need it get it, hands-off.
Built-in motivation
Points, ranks, badges, and a team leaderboard turn one-off awareness into an ongoing habit.

Built for authorized use only

Phishing simulations require written authorization from the recipient organization. ImmunePhish enforces it - recipient-domain consent gates, do-not-phish lists, per-tenant isolation, and an immutable audit trail keep every campaign inside the lines.

FAQ

Questions security teams ask.

Yes. Phishing simulations require written authorization from the recipient organization, and ImmunePhish enforces it - recipient-domain consent gates, do-not-phish lists, per-tenant isolation, and an immutable audit trail on every send.

No. ImmunePhish is sold B2B and sales-led - we scope the engagement with you and provision your tenant. No public sign-up, no credit card.

No. Campaigns send from your own tracking domains with automatic TLS, so recipients see your brand and infrastructure - not ours.

Every tenant is isolated, access is scoped to four RBAC roles, and every action is written to an audit trail you can review at any time.

Yes. Alongside email phishing, ImmunePhish runs smishing (SMS) campaigns from the same console.

You can auto-assign an awareness course to anyone who clicks or submits, then track completion through to done - so the next round’s numbers move.

Request a quote

ImmunePhish is sold B2B and priced per engagement. Tell us your team size and the capabilities you need - phishing simulation, awareness training, custom domains, SSO - and we'll put together a tailored quote and provision your organization. No self-serve signup, no credit card.

or email sales@immunephish.com