See who clicks on a fake phishing email
before a real attacker sends one.
Phishtime runs realistic, authorised phishing simulations against your own employees and turns every click into a training moment. Email, QR codes, attachments, MFA-fatigue prompts, SMS and Viber, measured by name, with timestamps.
Awareness training people actually remember
Three reasons a yearly e-learning module is not a security control.
A video in January proves nothing in June
Completion rates measure attendance, not behaviour. A simulation tells you who approved the push prompt, who scanned the code, who typed their password this month, by name, with timestamps.
Attackers moved on. Most simulators didn't.
Credential forms are the easy case. Real intrusions run through MFA approval fatigue, OAuth consent screens, device-code flows, and QR codes on a phone your endpoint agent never sees, "just paste this into the Run box" included.
A click without a follow-up is wasted
The teachable second is the second after someone clicks. Phishtime shows them, right then, exactly which signals they missed in their own language instead of adding a row to a spreadsheet nobody reads.
Even trained eyes slip under pressure
A bad week, a tight deadline, a full inbox. The signals someone learned last quarter get forgotten. Phishtime runs campaigns on your schedule, so your people get a reminder when it matters, not a certificate from six months ago.
Four steps, first campaign in under an hour
Load your people
Import a CSV, or sync straight from Microsoft Entra ID. However you bring them in, group employees by department, office or risk, then scope a campaign to one group without touching the rest.
Pick a lure
30+ ready-made templates with matching landing pages covering Microsoft 365, Google, DHL, DocuSign, Teams, Zoom, Dropbox and more, in every attack style we support. Clone one and edit it, or write your own.
Send it
From our managed mail, or from your own domain with your own DKIM. All at once, dripped across a window, or scheduled for a date. Preview and test-send before a single employee is touched.
Measure and train
Clicks, submissions, opens and reports land in real time. Anyone who falls for it gets the awareness page explaining exactly what they missed, and the numbers roll up into reports you can hand to a board.
Eight ways to be phished. Simulate all of them.
Every one of these is a shipped campaign type you can launch today - not a roadmap item.
Tracked link
The classic. Click through to a realistic sign-in page and see who hands over credentials under time pressure.
QR code - quishing
The code sits in the mail body; the victim scans it with a personal phone, stepping clean past the firewall, the endpoint agent and every other control that only watches the corporate laptop. The oldest bypass of the newest controls.
Tracked attachment
HTML, TXT, DOCX or XLSX, generated by us, beaconing on open, or carrying the tracked link inside. Tests who opens files from strangers.
MFA push approval
An "Approve this sign-in?" prompt, the way a real MFA-fatigue attack looks. See who waves a push through and who denies it.
OAuth consent
A mimicked app-consent screen. Consent is how a token gets stolen without a password ever being typed, and no password reset fixes it.
Device code
A lure that mimics a shared-document notification, "Finance shared a file with you", which leads to a real-looking device code and sign-in flow instead of a document. A favourite of real intrusion sets, and almost nobody trains for it.
ClickFix / fake CAPTCHA
"Prove you're human: run this command." The instructions adapt to the device: Win+R on Windows, Terminal via Spotlight on a Mac, a terminal shortcut on Linux, so it measures who will run a command a web page told them to, on whatever they're actually using.
SMS & Viber
The same campaign machinery, delivered over messaging channels from your own registered sender. Smishing lands where email filters aren't.
Numbers you can put in front of a board
Every number means the same thing wherever you see it, with the same definition on screen, in a PDF report, and in a CSV export, so nothing you show a board has to be double-checked first.
The teachable second is the second after the click
Awareness at the moment of failure
Anyone who clicks or submits is shown a page walking through the exact indicators in the mail they just fell for; the sender domain, the urgency, the mismatched link, plus a follow-up email carrying the same content.
In their own language
Training is delivered in each employee's own training language, not the campaign's. Enable the languages your organisation actually uses and set a default per person, by import or by directory sync.
An employee portal, not a shame list
Employees sign in to see their own score, points and history: Resisted, Opened, Clicked, Submitted. The leaderboard shows full names, initials only, or nothing at all: your call, because a public wall of shame trains people to hide clicks.
A simulator is only useful if it can't become the real thing
No credentials, ever
A submitted form records that a field was filled and what it was called. The value is dropped before it reaches the database. There is no plaintext password to leak, because none is stored.
Verified recipients only
Campaigns can only reach email domains your organisation has verified. The same check applies to test sends, so Phishtime cannot be pointed at anyone outside your workforce.
Content that can't exfiltrate
Every template and landing page is scanned before it is saved: off-platform form targets, <base>, meta-refresh and formaction tricks are rejected, and landing pages run under a script-restricting CSP.
Isolation in the database
The database itself, not just the application, scopes every query to your company under a restricted role with no bypass privileges. An application bug cannot reach another company's rows. The database refuses, before the bug ever gets the chance.
Secrets encrypted at rest
SMTP passwords, SSO client secrets, API keys and MFA seeds are AES-256-GCM encrypted, with a documented key-rotation path.
Everything on the record
An append-only audit log of every administrative action, tenant-scoped and exportable to CSV and to your SIEM over the API on Enterprise.
Fits the IT you already have
Identity & directory
Mail & infrastructure
Priced per employee. Free under 25.
You buy seats, not a bracket. The per-seat rate falls as you add people, and every plan includes the full simulate → land → measure → train loop.
- Email simulations
- Landing pages & tracking
- Awareness training pages
- Employee portal
- Own sending domain & SMTP
- Advanced lures (MFA / OAuth)
- Scheduled campaigns
- REST API & CSV export
- Everything in Starter
- SMS & Viber campaigns
- Custom landing domains
- SOC mailbox ingest
- Drip sends, branding, PDF reports
- Everything in Pro
- Entra ID SSO & directory sync
- Audit log API for your SIEM
- Cross-campaign executive reporting
The ones everybody asks first
Is this legal?
Yes - when you run it against your own workforce, on domains your organisation has verified. Phishtime enforces both: a campaign cannot reach an address outside your verified domains, and every administrator accepts terms stating plainly what the platform may be used for. Speak to HR or your works council before the first campaign; the docs include a pre-launch authorisation checklist.
Do you see our employees' passwords?
No. When someone submits a simulated login form, Phishtime records that a field was filled and what the field was called. The value never reaches storage, and no setting changes that.
Will this get our domain blacklisted?
Send through our managed mail and your own domain is not involved at all. If you send from your own domain, the built-in deliverability guide gives you the exact SPF, DKIM and DMARC records for it, plus a test-send path to verify before you launch.
Won't our mail filter click every link and ruin the data?
No. Automated mail-security scanning follows links to inspect them before your employees ever see the message, which would otherwise look like a click that never happened. Known scanner traffic is recognised and left out of the numbers, so what you see is people, not filters.
Can employees see each other's scores?
Only if you want them to. The leaderboard can show full names, initials only, or be switched off entirely - each employee always sees their own score either way.
What happens when the trial ends?
Nothing is deleted, and the workspace doesn't go read-only - it settles onto the free Hello World plan. Email simulations, landing pages, awareness training and the employee portal keep working, capped at 25 employees and one campaign every 30 days. Paid-only features - your own sending domain, advanced lures, the API - switch off automatically and come straight back the moment you pick a plan. The one thing that pauses: if you're carrying more employees than your plan allows (common right after a downgrade), launching a new campaign is blocked until you archive people down to the cap or add seats.
Run one simulation.
Sign up free, add a few test email addresses, and send your first campaign today - no card, no sales call. In a week you'll know more about your real risk than a whole year of e-learning completion certificates ever showed you.