Overview
The phishing module sends simulated bait to employees and measures who opens, who clicks and who reports, all with no real risk. The results feed the Human Risk Score and trigger targeted training for the people who need it most.
Every campaign picks a vector (delivery channel):
| Vector | Channel | Tracking | Doc |
|---|---|---|---|
| Email with link/attachment | Per target | this page | |
| QR in email | QR Code embedded in the email | Per target | Quishing |
| QR poster | Printed physical poster | Anonymous (collective) | Quishing |
| SMS | Text message | Per target | Smishing |
Anatomy of a campaign
The campaign editor walks you through four steps:
- Bait: the email subject and body, or the composer for the channel you chose. Use the placeholders below.
- Landing is the page the target sees after clicking, for example a fake login or an immediate educational page.
- Audience — who receives it: everyone, groups, departments or specific users.
- Schedule: when to send, plus the campaign window.
Placeholders
In the bait body you have tokens that the platform substitutes per target:
{{link}}— the recipient’s individual trackable link.{{qrcode}}— a trackable QR Code (for quishing campaigns).
Each target gets a unique token, so open, click and report tracking is individual.
What gets measured
For each target, over the course of the campaign:
- Sent → Opened (tracking pixel in the email) → Clicked (the link/QR) → Reported (if the person flagged the bait).
flowchart LR
S[Sent] --> A[Opened]
A --> C[Clicked]
A --> R[Reported]
C --> L[Educational page]
classDef good fill:#3ddc97,stroke:#3ddc97,color:#070a0e;
classDef bad fill:#ff3d71,stroke:#ff3d71,color:#ffffff;
class R good
class C bad
Reporting is the desired behavior (green); clicking is what you want to reduce (red).
Reporting is the desired behavior, and it connects to PhishER, which handles the emails employees actually report.
SMS and posters have leaner tracking: SMS has no open pixel and no report; the poster is anonymous by nature. Each channel doc covers this in detail.
Sender profiles
You configure reusable sender profiles (like SMTP profiles): domain, sender and provider. The campaign chooses which profile to use. SMS has its own profiles with provider selection; see Smishing.