Docs

Read results and take action

Open Campaigns, select a campaign, and review its Sent, Opened, Clicked, Submitted, Reported, and Failed counts.

Open Campaigns, select a campaign, and review its Sent, Opened, Clicked, Submitted, Reported, and Failed counts.

  1. Look at Failed sends first. These usually point to sender authentication, address quality, or filtering, not to employee behavior.
  2. Compare Sent against your intended target count, shown at the top of the page, to confirm the right group was reached.
  3. Open the Event log tab to see who clicked, when, and from where. Each row has the action, the target, and a timestamp.
  4. Open the Landing page tab to see what people who clicked were shown. Open the Sending template tab to see the message that was sent.
  5. Export the full result set as CSV from the campaign's export option, to report to people outside Phishtime.

Internal vs. external network

Under Settings → Domains & network, add your office, VPN, or data-centre IP ranges in CIDR notation. Once you have at least one range, every tracked event (opens, clicks, submissions) is tagged internal or external in the Event log and in CSV exports, based on the recipient's IP address at the time. This tells you whether a risky click came from inside the building on a managed device or from a personal device off the network. With no ranges set, events are left unclassified.

Following up with employees

Anyone who submits the fake landing page can be shown an awareness page about the simulation. The text is set under Settings → Branding; whether a campaign shows it is set on the campaign. Use campaign results to decide who needs a follow-up conversation or extra training, and to track click and submission rates across repeated campaigns. Compare periods with the 30 days / 1 quarter / 1 year toggle on the Dashboard.