Authorized use
Phishtime is for authorized security-awareness simulations and training.
Phishtime is for authorized security-awareness simulations and training.
You must have authorization
Before you create a campaign, make sure you have authorization from the organization that owns the recipients and the target domains. Follow the employment, privacy, consumer-protection, and telecommunications law that applies in your jurisdiction and the recipients' jurisdiction. It varies by country and by whether the recipients are employees, contractors, or members of the public.
What's checked technically
Phishtime enforces part of this. A campaign can only target employees whose email address is on a domain your company has verified (Settings → Domains & network → Verified domains), and simulation email can only be sent from a domain verified the same way. Each Company Admin must also accept the Phishtime Terms of Service, the prompt shown on sign-in, with the accepted version recorded under Settings → Branding → Legal & policies. The terms set out what the platform may be used for and where responsibility for each simulation sits.
What Phishtime does not do
Landing pages imitate real sign-in, MFA-approval, and OAuth-consent flows to measure behavior. They do not perform any real authentication and do not grant any real permissions. When a recipient submits a fake form, Phishtime records that a submission happened and which fields were filled in, not what was typed. It does not store the passwords, codes, or other data entered.
See Pre-launch authorization checklist before your first send.

