Docs

Review campaign results

Open a campaign from Campaigns to see its delivery and interaction results. The numbers refresh on their own every few seconds while a campaign is running. Turn Auto-refresh off if you prefer.

Open a campaign from Campaigns to see its delivery and interaction results. The numbers refresh on their own every few seconds while a campaign is running. Turn Auto-refresh off if you prefer.

Top-line counters

  • Total / Sent: how many recipients were targeted, and how many messages went out.
  • Opened: an email tracking signal was recorded. Automated mail-security scanning is detected and left out. See Mail scanner activity.
  • Clicked: the recipient opened the tracked link, scanned the QR code, or opened the attachment.
  • Submitted: the recipient interacted with the fake landing page, for example typed something into the sign-in form.
  • Reported: the recipient reported the message, through the built-in report flow or a connected SOC mailbox.
  • Failed: the message could not be delivered.

Below these are Click rate, Submission rate, Open rate, and Time to click (median, P90, fastest).

Common outcomes

  • Sent: the message was accepted for delivery.
  • Opened: a tracking signal came from the recipient, not their mail filter.
  • Clicked: the recipient opened a tracked link, QR code, or attachment.
  • Submitted: the recipient interacted with the fake landing page.

Tabs on the campaign page

  • Overview: the timeline chart (clicked, opened, submitted over time) and the funnel donut.
  • Sending template: the exact email or message that was sent.
  • Landing page: the exact landing page recipients saw.
  • Event log: a row per send, open, click, and submission, with timestamps. It also shows scanner activity, tagged scanner, which the counters leave out.
  • Queue: recipients still waiting to be sent.

Mail scanner activity

Corporate mail-security products, such as Microsoft Defender for Office 365, Proofpoint, and Mimecast, open messages and follow their links automatically to check them, usually within seconds of delivery. To a tracking pixel, that looks the same as a person opening the email.

Phishtime recognizes this and marks it as scanner traffic. These hits:

  • do not count toward Opened, Clicked, Submitted, or any rate;
  • do not change a recipient's status. Someone whose gateway scanned the mail still shows as Sent until they open it themselves;
  • do not affect that employee's score, and are never shown to them in the portal.

So your results reflect what your people did, not what their mail filter did.

The activity is still recorded and stays in the Event log, tagged scanner. A Hide scanner traffic toggle hides those rows. Because of them, the Event log can show more opens or clicks than the counters at the top. The CSV export has the same information in a scannerHits column per recipient.

If you think real recipient activity is being marked as scanner traffic, or a scanner is not being recognized, contact support with the campaign name and date. The source address of every hit is recorded, so it can be checked.

See Read results and take action for what to do with what you find.