Docs

Understand your score and results

How your phishing-awareness score works, and how to review a specific simulation.

How your score changes

Every simulation you are part of can move your score, based on how you responded:

  • Not opening it, or opening it without clicking or typing anything, counts as resisted. Nothing is held against you.
  • Clicking a link, scanning a QR code, or opening an attachment moves you toward the simulation having worked. No real credentials or data are ever collected; it all runs on Phishtime's own systems.
  • Typing anything into a fake login page, even a made-up password, counts as fully caught.

Your rank and percentile are worked out the same way for everyone in your company, so they stay comparable over time. Reviewing more simulations and getting better at spotting them is what improves your position.

Reviewing a simulation you were part of

Open a past campaign from your dashboard to see what happened and why the message was a simulation: the details that gave it away, such as the sender address, the link destination, and urgency language. If you missed something, this is the quickest way to learn what to look for next time.

If a campaign included awareness training

Some campaigns show a short awareness page after you interact with the simulation, or send a follow-up email about what the exercise tested. These are educational only. Nothing you enter there is stored, and there is nothing else to do beyond reading it.