Welcome to Phishtime
Phishtime lets you run phishing simulations against your own staff, see how they respond, and follow up with training.
Phishtime lets you run phishing simulations against your own staff, see how they respond, and follow up with training.
What you can do in Phishtime
- Simulate. Send a phishing email (with a tracked link, a QR code, or an attachment) or a Viber/SMS message to your employees. Use a built-in template or write your own.
- Land. A recipient who clicks lands on a fake page: a sign-in form, an MFA approval screen, or an OAuth consent screen. The page records what they did. It never stores a real password or code.
- Measure. The dashboard and each campaign report show sent, opened, clicked, submitted, and reported counts, down to the individual employee.
- Follow up. When a campaign has awareness content enabled, anyone who submits the fake page is shown a short page explaining the test.
Getting started
Sign up with your work email. This creates your company workspace and makes your account its first Company Admin, on a free 30-day trial.
Who this is for
Two kinds of people use Phishtime:
- Company admins set up employees, templates, campaigns, and security settings for their organization. Most of this documentation is for them.
- Employees receive the simulations. They can sign in to the employee portal to see their score and review past simulations. See Employee portal.
Before you start
You may only run campaigns against people who work for your organization and whom you are authorized to test. Read Authorized use before your first campaign.
Next: Set up your workspace.

