These screens are tabs of the Phishing module and feed the simulation campaigns. For all of them: view = Administrator or Manager; create/edit = Administrator.
Email senders
Under Phishing → Senders (/phishing/senders) you register your own SMTP profiles, the “sending profiles”. With the customer’s SMTP, the “From:” field can be a real address, not just a name.
Main fields: the profile name, the display name and email of the “From:”, the SMTP host and port (default 587), TLS, username/password and extra headers (e.g. Reply-To). The password is encrypted and never returned; if left blank when editing, the current one is kept. Use Test to send a validation email. In the campaign, the sender field points to the profile (or uses the system sender).
SMS senders
Under Smishing → Senders (/smishing/senders) live the SMS profiles, with provider selection (AWS SNS, Twilio or generic HTTP for Zenvia/Comtele/Infobip). Secrets are encrypted and never returned. Usage details are in the Smishing doc.
Landing pages
Under Phishing → Landing pages (/phishing/landings) you create the educational page the person sees after clicking: “this was a test”.
Landings do NOT capture passwords or any data; they only educate. This is a deliberate difference from offensive phishing tools.
When you create one, the page comes with a default HTML (“This was a phishing test 🎣” + the signs of the scam). Edit the HTML, preview it and save. There are 8 ready-made templates (You fell for the test, How to spot it next time, How to report phishing, Phishing in numbers…). The campaign points to the landing from the library, or uses an inline page.
Templates (email bait)
Under Phishing → Templates (/phishing/templates) live the reusable baits — ready-made (from the catalog) and your own. The ready-made ones can’t be edited: you clone them to create your own version.
Fields: name, category, suggested “From:”, the bait’s subject and HTML. A panel shows the available personalization variables, substituted per target:
| Variable | Becomes |
|---|---|
{{.FirstName}} / {{.LastName}} / {{.Name}} |
Target’s name |
{{.Email}} |
Target’s email |
{{.Position}} / {{.Department}} |
Position / department |
{{link}} |
The tracked link (injected separately) |
{{qrcode}} |
The tracked QR (quishing) |
The ready-made templates cover the classic scams: Microsoft 365 (password expiring), Google (new sign-in), DocuSign, IT support, HR (pay stub), Finance (invoice), Delivery (held package).